Recommend:
To the knowledge base

Local DNSSEC cannot be used via the FRITZ!Box

Since updating FRITZ!OS, DNS queries are no longer resolved via the FRITZ!Box if the devices use a DNSSEC validation (i.e. an authenticity validation of DNS entries for a domain).

The problem affects both their own local DNS servers in the home network (for example Pi-hole, Bind9), which are announced via the FRITZ!Box DHCP server, and connector in doctors' offices and pharmacies (for example Gematik, secunet).

Local DNSSEC is not supported

DNSSEC validation for DNS queries is not supported by your FRITZ!Box Cable.

Workaround

  1. Enter the DNS servers of your internet service provider or a different public DNS server (for example from Cloudflare 217.0.43.146 und 217.0.43.162) in your local DNS server or the connector. If you are running a local DNS server, you can also deactivate DNSSEC in the DNS server instead.

    Important:Changes to connectors in doctors' offices or pharmacies should only be made after consulting the service provider on the premises.