Windows 11 DNS Over TLS "This system does not support required TLS version(s)"

  • DNS Benchmark v2 Release 5 with Consultant License
    Guest:
    If you own any earlier release of our DNS Benchmark you may immediately download its release #5 replacement. Running an earlier release will detect the new release and help you upgrade.

    Although this release is cosmetic, appearance matters and affects ease of use. The biggest change, as seen in the image above, is that the DNS Benchmark now has a traditional Windows application menu to more fully expose its many features. This release is also "Consultant License Aware" and GRC will now issue a Consultant version when owners have previously purchased four "Personal Use" licenses. If you have previously purchased four DNSB licenses, or if you wish to upgrade your "Personal Use" license to Consultant, GRC's purchase process will direct you through that process.
    /Steve.
  • Be sure to checkout “Tips & Tricks”
    Dear Guest Visitor → Once you register and log-in please checkout the “Tips & Tricks” page for some very handy tips!

    /Steve.
  • BootAble – FreeDOS boot testing freeware

    To obtain direct, low-level access to a system's mass storage drives, SpinRite runs under a GRC-customized version of FreeDOS which has been modified to add compatibility with all file systems. In order to run SpinRite it must first be possible to boot FreeDOS.

    GRC's “BootAble” freeware allows anyone to easily create BIOS-bootable media in order to workout and confirm the details of getting a machine to boot FreeDOS through a BIOS. Once the means of doing that has been determined, the media created by SpinRite can be booted and run in the same way.

    The participants here, who have taken the time to share their knowledge and experience, their successes and some frustrations with booting their computers into FreeDOS, have created a valuable knowledgebase which will benefit everyone who follows.

    You may click on the image to the right to obtain your own copy of BootAble. Then use the knowledge and experience documented here to boot your computer(s) into FreeDOS. And please do not hesitate to ask questions – nowhere else can better answers be found.

    (You may permanently close this reminder with the 'X' in the upper right.)

wigzoe

Member
Mar 12, 2026
9
0
Hi I just downloaded DNSB v2 and I received the below error on Windows 11. I went into internet options to check my TLS settings. Is there something I am missing to enable the TLS tests?

Thank you!
Screenshot 2026-03-12 194049.jpg
\


Screenshot 2026-03-12 194238.jpg
 
Last edited:
What does this page show for you?
 
What does this page show for you?
I can run it. But, does it matter that this is testing in the browser and DNSB v2 is running on my Desktop?
 
Regardless of the options set on my Windows, I want to test if they
actually work and are 'seen' in the real world of browsing,
So, at https://browserleaks.com/tls for example, I get:

Protocol Support
TLS 1.3 ✔Enabled
TLS 1.2 ✔Enabled
TLS 1.1 ✖Disabled (Good)
TLS 1.0 ✖Disabled (Good)

If I had TLS1.2 set, but it wasn't 'seen' out there, then I'd need to
troubleshoot.
 
Regardless of the options set on my Windows, I want to test if they
actually work and are 'seen' in the real world of browsing,
So, at https://browserleaks.com/tls for example, I get:

Protocol Support
TLS 1.3 ✔Enabled
TLS 1.2 ✔Enabled
TLS 1.1 ✖Disabled (Good)
TLS 1.0 ✖Disabled (Good)

If I had TLS1.2 set, but it wasn't 'seen' out there, then I'd need to
troubleshoot.
Gotcha, Mine looks exactly like yours.

browserleaks-tls-2026_03_13_06_56_47.png
 
Ah, so after a power-cycle reboot of everything, including our
modem/router and all switches ;-) . . . DNSBench 2 then says ... ?

And in Safe Mode with Networking?
 
Are you using the latest commercial release 4?

2.0.9486.1

See https://www.grc.com/dns/version-history.htm

Redownload DNSBench 2 and test the new download.

Resolved = you win.
'Problem' still there = keep troubleshooting.

- - - - -

Everyone has personal troubleshooting preferences, especially if they
have seen the problem before ( which for me was resolved by
updating TLS protocols that were missing ).

I suggest two troubleshooting schemes:

duplicate and document
divide and conquer

So if you start from scratch, power-cycle everything, and try again,
even try another computer, does the problem stay, or is it resolved?

Resolved = you win.
'Problem' still there = keep troubleshooting.

Then change something, such as rebooting into Safe Mode with
Networking *.

Resolved = something in real mode is inserting itself, thus starts
the hunt.
'Problem' still there = keep troubleshooting.

- - - - -

* Google suggests: To reboot Windows 11 into Safe Mode with​
Networking, hold down the Shift key while selecting​
Start > Power > Restart.​
Once the PC restarts to a blue menu, navigate to​
Troubleshoot > Advanced options > Startup Settings > Restart,​
then press 5 or F5. [1, 2, 3]​
This video demonstrates how to restart your computer in Safe Mode​
with networking:

Alternative Methods:​
  • System Configuration (msconfig): Press , type , go to the Boot tab,
    select Safe boot with Network, and restart.
  • Command Prompt: Open Command Prompt as administrator, run ,
    then restart. [1, 4, 5]
Exiting Safe Mode:Restart your computer normally. If you used , you​
must go back and uncheck "Safe boot" to prevent booting into Safe​
Mode again. [2, 5, 6]​
[2]
[3]
[5]
[6]
 
Are you using the latest commercial release 4?

2.0.9486.1

See https://www.grc.com/dns/version-history.htm

Redownload DNSBench 2 and test the new download.

Resolved = you win.
'Problem' still there = keep troubleshooting.

- - - - -

Everyone has personal troubleshooting preferences, especially if they
have seen the problem before ( which for me was resolved by
updating TLS protocols that were missing ).

I suggest two troubleshooting schemes:

duplicate and document
divide and conquer

So if you start from scratch, power-cycle everything, and try again,
even try another computer, does the problem stay, or is it resolved?

Resolved = you win.
'Problem' still there = keep troubleshooting.

Then change something, such as rebooting into Safe Mode with
Networking *.

Resolved = something in real mode is inserting itself, thus starts
the hunt.
'Problem' still there = keep troubleshooting.

- - - - -

* Google suggests: To reboot Windows 11 into Safe Mode with​
Networking, hold down the Shift key while selecting​
Start > Power > Restart.​
Once the PC restarts to a blue menu, navigate to​
Troubleshoot > Advanced options > Startup Settings > Restart,​
then press 5 or F5. [1, 2, 3]​
This video demonstrates how to restart your computer in Safe Mode​
with networking:

Alternative Methods:​
  • System Configuration (msconfig): Press , type , go to the Boot tab,
    select Safe boot with Network, and restart.
  • Command Prompt: Open Command Prompt as administrator, run ,
    then restart. [1, 4, 5]
Exiting Safe Mode:Restart your computer normally. If you used , you​
must go back and uncheck "Safe boot" to prevent booting into Safe​
Mode again. [2, 5, 6]​
[2]
[3]
[5]
[6]
I can confirm:
  1. I am on the latest commercial release 4
  2. Even in Safe Mode with Networking I still get the TLS error I showed before
 
I'll grant you it would be nice to get to the bottom of things wrt DoT but Steve did run into difficulties getting it working on some machines anyway, and I believe that is because it is sort of a black sheep. DoH seems to have mostly supplanted it, near as I can tell, so unless you're really set on getting DoT working for a specific reason, I think I'd choose DoH anyway.
 
I'll grant you it would be nice to get to the bottom of things wrt DoT but Steve did run into difficulties getting it working on some machines anyway, and I believe that is because it is sort of a black sheep. DoH seems to have mostly supplanted it, near as I can tell, so unless you're really set on getting DoT working for a specific reason, I think I'd choose DoH anyway.
That's understandable, I'd just like to be able to test DoH and DoT, so having it working would be nice. Thanks!
 
Try slowing DNSBench 2 R4 down:

Via menus:

Alt Spacebar​
Change Benchmark Speed: 20 msec​
[ 9999 ] msec per resolver​
Accept​

1773440994916.png


9999 milliseconds = 9.999 seconds delay between queries

- - - - -

Or via command line:

DNSBENCH.EXE /PAUSE 123456

... where 123456 is any number of ms / msec / miliseconds to delay
between queries.

123456 milliseconds = 2.0576 minutes delay between queries

I've run 5 minutes and longer delays to empower getting results
through some systems.

- - - - -

If either of those gives joy, then whatever is responding to TLS in
your system is really ... burdened and not very responsive.

- - - - -

Alternatively, maybe it's a particular DoT getting caught, so try:

delete all,​
toggle off IPv4, IPv6, and DoH,​
load System to get DoT only,​
try a Benchmark​

also

delete all but one DoT,​
try a Benchmark​
- - - - -

Anything?
 
Last edited:
Try slowing DNSBench 2 R4 down:

Via menus:

Alt Spacebar​
Change Benchmark Speed: 20 msec​
[ 9999 ] msec per resolver​
Accept​

View attachment 1981

9999 milliseconds = 9.999 seconds delay between queries

- - - - -

Or via command line:

DNSBENCH.EXE /PAUSE 123456

... where 123456 is any number of ms / msec / miliseconds to delay
between queries.

123456 milliseconds = 2.0576 minutes delay between queries

I've run 5 minutes and longer delays to empower getting results
through some systems.

- - - - -

If either of those gives joy, then whatever is responding to TLS in
your system is really ... burdened and not very responsive.

- - - - -

Alternatively, maybe it's a particular DoT getting caught, so try:

delete all,​
toggle off IPv4, IPv6, and DoH,​
load System to get DoT only,​
try a Benchmark​

also

delete all but one DoT,​
try a Benchmark​
- - - - -

Anything?
I did try changing the benchmark speed to 9999 and 123456, and they did get rid of the TLS warning. But, all of the TLS severs show as unable to test.
Screenshot 2026-03-15 090349.jpg
 
I did try changing the benchmark speed to 9999 and 123456, and
they did get rid of the TLS warning. But, all of the TLS servers show
as unable to test

Wow.

Movement, but no resolution.

Any ideas, anybody?


Do you have any other computers, even a loaner from a friend, that
you can test through your modem/router?

Can you test your OC through someone else's ISP?

We're trying to isolate the source of the block:
  • your PC
  • your modem/router
  • your ISP.

What if . . . you change your DNS servers in your PC and or in your
modem/router
to known TLS-compatible DNS servers?

So, what are your DNS servers now?

Try changing them to, as Google AI-assisted search suggests today 2026-03-15:

The public DNS servers with the best reputation for robust, secure,
and fast DNS-over-TLS DoT support are Cloudflare, Google,
Quad9, and CleanBrowsing.

These providers specialize in DNS privacy, supporting TLS 1.3 and
offering high uptime to prevent eavesdropping and hijacking.

Top Public DNS Servers for TLS (DoT/DoH)
Cloudflare
1.1.1.1
1.0.0.1

Highly regarded for speed and strict privacy policies, encrypting all
queries via DoT and DoH.

Google Public DNS
8.8.8.8
8.8.4.4

Offers very fast, reliable, and secure resolution, supporting TLS 1.3
and extensive DNSSEC validation.

Quad9
9.9.9.9
Focuses heavily on security, blocking known malicious sites while
providing DoT for privacy.

• CleanBrowsing: Popular for its focus on security and privacy,
including specialized family filtering options.

• AdGuard DNS: Specializes in blocking ads, trackers, and malicious
websites using secure, encrypted DNS.
These providers allow you to use strict or opportunistic DoT to
authenticate the server, preventing tampering.


 
I did try changing the benchmark speed to 9999 and 123456, and
they did get rid of the TLS warning. But, all of the TLS servers show
as unable to test

Wow.

Movement, but no resolution.

Any ideas, anybody?


Do you have any other computers, even a loaner from a friend, that
you can test through your modem/router?

Can you test your OC through someone else's ISP?

We're trying to isolate the source of the block:
  • your PC
  • your modem/router
  • your ISP.

What if . . . you change your DNS servers in your PC and or in your
modem/router
to known TLS-compatible DNS servers?

So, what are your DNS servers now?

Try changing them to, as Google AI-assisted search suggests today 2026-03-15:

The public DNS servers with the best reputation for robust, secure,
and fast DNS-over-TLS DoT support are Cloudflare, Google,
Quad9, and CleanBrowsing.
These providers specialize in DNS privacy, supporting TLS 1.3 and
offering high uptime to prevent eavesdropping and hijacking.

Top Public DNS Servers for TLS (DoT/DoH)
Cloudflare
1.1.1.1
1.0.0.1
Highly regarded for speed and strict privacy policies, encrypting all
queries via DoT and DoH.

Google Public DNS
8.8.8.8
8.8.4.4
Offers very fast, reliable, and secure resolution, supporting TLS 1.3
and extensive DNSSEC validation.

Quad9
9.9.9.9
Focuses heavily on security, blocking known malicious sites while
providing DoT for privacy.

• CleanBrowsing: Popular for its focus on security and privacy,
including specialized family filtering options.

• AdGuard DNS: Specializes in blocking ads, trackers, and malicious
websites using secure, encrypted DNS.
These providers allow you to use strict or opportunistic DoT to
authenticate the server, preventing tampering.
So I just tested on a Ubuntu 24.04 VM I have setup, and I got the same result with all TLS servers unable to test. I even tried changing the DNS in my router from just using unbound resolver mode to using it in forwarding mode to Quad 9 TLS, and I still could not get the TLS servers to show up as available to test. Thanks!
Screenshot 2026-03-15 160231.jpg
 
Yeah, Wine has trouble supplying the necessary crypto. Newer Wine versions may work better, but it's still better to go for DoH for better/working support in any version of Windows.
I think the default version of Wine with Ubuntu 24.04 is Wine 8 which does not support the necessary crypto. It has been noted before that you need at least Wine 9.0 for DNS over TLS and this is not in the Ubuntu repositories yet. You should be able to install Wine 9.0+ manually.