Skip to main content

How to use NextDNS to block apple's servers to check certificate status if my certificate is revoked?

Updated over 2 weeks ago

1. Signup to NextDNS and follow the video instructions.

The URLS for denylist:

ocsp2.apple.com

valid.apple.com

crl.apple.com

certs.apple.com

appattest.apple.com

vpp.itunes.apple.com

ocsp2-lb.apple.com

ocsp2.g.aaplimg.com

crl3.digicert.com

crl4.digicert.com

ocsp.digicert.cn

ocsp.digicert.com

ocsp2-lb.apple.com.akadns.net

gsas.apple.com

gsas.idms-apple.com.akadns.net

ma-gsa-hb-prod.apple.com

aidc.apple.com

init.ess.apple.com

iphone-ld.origin-apple.com

crl5.digicert.com

crl2.digicert.com

crl.digicert.com

crl2.apple.com

crl3.apple.com

guzzoni-apple-com.v.aapling.com

axm-app.apple.com

comm-cohort.ess.apple.com

comm-main.ess.apple.com

mesu.apple.com

xp.apple.com

ppq.apple.com

ocsp.apple.com

PPQ.apple.com

The URLS for allowlist:

app.localhost.direct

api.palera.in

api.development.push.apple.com

register.appattest.apple.com

mask-h2.icloud.com

mask-canary.icloud.com

mask-api.icloud.com

api.push.apple.com

push.apple.com

Blocks Updates:

gdmf.apple.com

You can also use any DNS of your choice.

Important Note: When installing or opening applications for the first time, it is important to disable either complete DNS or just disable the URL โ€œppq.apple.com.โ€ This is necessary for the successful installation of applications.

Did this answer your question?