The original post: /r/pihole by /u/l86rj on 2025-01-20 05:39:13.

I’ve noticed that my iPhone queries are not being filtered by pihole, and searching for an explanation I found about private relay. However, all the docs I found mention only two addresses:

mask.icloud.com

mask-h2.icloud.com.

Accordingly, the pihole seems to be blocking those domains. I see it in query log: “Blocked (special domain)”, which, considering the docs, is the expected behavior in later pihole versions.

But in my query logs there are also at least two other suspicious domains that are not getting blocked:

mask-api.fe2.apple-dns.net

mask-api.icloud.com

Could they be responsible for my pihole not filtering the iPhone’s queries? Why aren’t they also blocked by default? Is Apple adding new domains for the private relay service or are these domains used for different purposes?