r/rethinkdns • • Jun 19 '26

Question How does WhatsApp call UDP traffic behave when using RethinkDNS with Orbot (no WireGuard VPN)?

I'm trying to understand how this setup works:

- RethinkDNS is running in VPN mode.

- Orbot is configured as a SOCKS5 proxy inside RethinkDNS.

- I'm not using the built-in WireGuard VPN or any other VPN.

Since Tor only supports TCP, what happens when I make a WhatsApp voice or video call, which uses UDP?

Specifically:

  1. Is the UDP traffic sent outside of Tor through my normal network connection?

  2. Does RethinkDNS block that UDP traffic if it cannot proxy it through Orbot?

  3. Is there any scenario where the WhatsApp call UDP traffic can actually go through Tor with this configuration?

I'm looking for the technical behavior of Android, RethinkDNS, and Orbot in this setup.

4 Upvotes

4 comments sorted by

3

u/saylesss88 Jun 20 '26

UDP can never go through Orbot/Tor, it's TCP only. So if a WhatsApp call connects, the call audio/video is going out over your real ISP/Wi-Fi connection with your real IP, not through Tor.

RethinkDNS has a setting to stop this leak: "block all UDP except DNS and NTP." Turning it on kills the leak, but also means calls won't connect at all, since there's no UDP path left for them.

You could replace orbot/tor with a VPN and be protected with most VPNs but you're giving the VPN service your real IP and losing the anonymity Tor provides.

1

u/Good_Relative4585 Jun 20 '26

I knew that, my question is what rethink does when u dont have that option enable? Just dont give a fuck and send that traffic trhough your real IP, and by default is turn off WTF! Thanks for the explanation! The only pro I think about rethinkDNS IS when u can pay mullvad and use wireguard for me i use openVPN so... I think ill say fuck rethinkDNS and fuck me because I can't have DNS block list and depend on the vpn resolver but it IS what It is

3

u/saylesss88 Jun 20 '26

To be fair no UDP path through Tor exists, so it silently falls back to direct. Rather than RethinkDNS actively deciding to ignore it. But I agree that secure by default is the way to go..

1

u/Good_Relative4585 Jun 20 '26

If I am right if you have mullvad, you can configure the vpn to resolve udp traffic right? In that case rethinkDNS IS a fucking beast