You overlooked this one in my post: ... (assuming, all traffic from users is routed via squid box) Which is easy to be done in a local squid, serving as/in gateway to the internet. Whether personal or for a large LAN. My "iptables rules to redirect port 53" are not so easy to be implemented/achieved in large scale setup, like for an ISP, I have to agree on. Anyway, I think the opener of this thread now has a possible path to go (research first) :-) -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/Force-DNS-queries-over-TCP-tp4678324p4678356.html Sent from the Squid - Users mailing list archive at Nabble.com. _______________________________________________ squid-users mailing list squid-users@xxxxxxxxxxxxxxxxxxxxx http://lists.squid-cache.org/listinfo/squid-users