I feel kinda bad about feeding google with data. Is there some name server I can point my servers to that upholds my privacy and does not run analytics on the requests it gets?
Cloudflare at work, quad9 at home.
Honestly at work I mostly use the upstream dns
I use the DNS resolver in pfSense which connects directly to the DNS root servers.
I do the same in opnsense. According to dnsperfbench, running my own resolver benchmarked as slightly faster or at minimum about the same performance as using any of the big public resolvers. I think the only concern is to make sure you’re not using your local resolver if you’re trying to use a VPN.
You can do that?
Yes, as long as you don’t have a crappy ISP that interferes with your DNS traffic.
My ISP is crappy in other ways
How about dnscrypt-proxy?
Randomized dns servers and you can use your own blocklists
OpenNIC is my favourite, community run, lots of servers have no logs
OpenNIC is quite a hit or miss for me. How does it work for you?
What do you mean?
Uptime? DNS resolution speed?
I’ve been using them for a good 10 years, occasionally a server goes down but then you just swap them in your config.
I set them on my router which acts as the cache server as well. So after a client resolves it, no other clients have issues.
It’s just that some servers I’ve chosen in the past had either gone down in speed or vanished completely.
Fwiw the AU ones are working like a treat
Quad9, a Swiss public benefit, not-for-profit foundation. Main address is 9.9.9.9.
TIL, danke!
NextDNS is good. OpenDNS used to be, but you know… Cisco.
My own.
This is the correct answer if you trust that your ISP isn’t snooping on your traffic. Your DNS server will send unencrypted queries to the root name servers and the nameservers of the domains you search for. This traffic is easy to detect and parse, so you do need to trust your ISP, or the provider of wherever you host your DNS server.
If you don’t trust your ISP to that level you’ll need to trust whichever server you connect to. It’s a trade off to decide which is best for your use case.
Been using dnsforge.de to block ads, pretty sure they respect privacy
@Sibbo if you don’t classify cloudflare as evil, you can give their DNS at 1.1.1.1 a try
OpenDNS, anyone?
Open DNS is run by Cisco now. And is directly used for their proprietary anti malware systems
Thanks for the info, I’ve started using Quad9 ever since I got fiber recently and tried a DNS benchmark tool and saw it’s even faster than Cloudflare at my network
Quad9
9.9.9.9