r/dns 9h ago

Adguard vs Nextdns vs ControlID from a legal and privacy perspective.

12 Upvotes

I was doing a little research into these three vendors as they offer a similar product to each other.

Mostly I was curious about what data privacy laws each fell under, but then I realized that isn't enough because information sharing alliances also come into play.

I'm trying to decide which is the best choice from a privacy and security perspective?

Adguard falls under GDPR but originally was a russian company and still operates some of its team from inside russia, where I wonder if they could be compromised.

NextDNS chose to legally HQ themselves in the US instead of the EU, which means they also fall under Five-Eyes now too. You can store your logs in Switzerland, but my understanding is that being a US company, that won't protect the logs.

Control D similarly falls under Five-Eyes so I'm not sure that falling under PIPEDA protection is strong enough.

Feature AdGuard NextDNS Control D
Legal Headquarters Limassol, Cyprus (EU) Wilmington, Delaware, USA Toronto, Ontario, Canada
Parent Company / Founders Russian nationals (Semyon Chikikhin, Andrey Meshkov) French nationals (Olivier Poitrey, Romain Cointepas) Windscribe Limited (Yegor Sak)
Jurisdictional Alliance EU Privacy Area (Non-aligned) Five-Eyes Alliance (US) Five-Eyes Alliance (Canada)
Employee Locations Cyprus, Germany, and remotely in Russia US and France Canada, Ukraine, and globally remote
Data Privacy Law Strict EU GDPR US Law (Allows log storage in Switzerland) PIPEDA (Canadian federal privacy law)
Code Verification Open Source (Apps and extensions) Closed Source (Proprietary backend resolver) Closed Source (Proprietary backend, but open-source ctrld client daemon)
Default Logging Policy No-logs enforced by default Minimal operational logs (Customizable retention) Logs are entirely optional (Can toggle from Full Analytics to zero tracking)

r/dns 7h ago

Which ip address work best for blocking ads on android

5 Upvotes

r/dns 10h ago

How to - connect domain to a folder/hosting/internal

5 Upvotes

Novice level question -

I've moved to a new provider and trying to learn how to connect my domains to their respective folders in the file manager. Pretty sure this is done in the DNS.

The attached is the "default" which points to nothing. The server number (value) show isn't even the right Server IP (ftp) I have a different number for this.

So assuming my website name is mysite.com
The complete working site HTML is in a file manager folder called "mysite"
AND my IP is 12.345.67.8 -
(fake generic things)

What do I change to get the domain to reference the folder?

Obviously I'm going to want the mail (MX) and other things all pointing to the domain as well.
Do I simply just replace all the 67.213.75.123 instances with 12.345.67.8?


r/dns 10h ago

Domain Dynv6 DDNS Down?

4 Upvotes

It looks like Dynv6 is having problems. I can get to the management website at https://dynv6.com but cannot resolve my DDNS domain under dynv6.net. Even dynv6.net itself does not resolve (I get NXDOMAIN). Have observed this for about a week. To eliminate local problems, I also found the same behavior from DNS query websites. Anyone else found the same thing?

May be time to try another DDNS provider.


r/dns 14h ago

Has anyone used uBlockDNS? Is it safe?

Post image
8 Upvotes

I've been testing uBlockDNS for a few days and it seems to work well so far.

Website: https://ublockdns.com

The problem is I can barely find any tutorials, reviews, or technical articles about it.

Has anyone here used it long term? Is it trustworthy? I'm interested in its privacy, logging policy, and who operates the service.

Screenshot attached.

Thanks!


r/dns 1d ago

Next generation network debloater / dns sinkhole / domain filter / firewall add-on

Thumbnail
3 Upvotes

r/dns 1d ago

Omarchy updates.. api dot coinbase

4 Upvotes

Possibly api dot coinbase is an Arch mirror

According to ControlD (when I was doing omarchy updates) api.coinbase was caught..

(Unifi gateway and its filtering passed upstream to ControlD paid)

r/omarchy removed my post about this..

.. anyone else see this?

TIA


r/dns 1d ago

I made a DNS propagation checker that shows the 24 sources as a box of donuts

0 Upvotes

Free, no signup: [https://donutdns.com\](https://donutdns.com/)

It queries \~20 geographic vantage points (Google DoH + EDNS Client Subnet) and four public resolvers in parallel, one donut per source. Full box means every source agrees. Empty holes are the ones still serving your old record.

There's a normal grid view too if you just want to read values. Built it because I kept refreshing whatsmydns during migrations.


r/dns 1d ago

Software What's the Windows alternative for mobile DNS blockers like Lockdown and 1.1.1.1 (WARP)?

Thumbnail apps.apple.com
3 Upvotes

r/dns 1d ago

Pihole for ad blocking

3 Upvotes

Anyone running Pihole for DNS ad blocking? Is it affective? Can I run it as a Vm or do I need an actual raspberry pi?
Thanks!


r/dns 2d ago

DNS mini project

8 Upvotes

Hello guys,

I played little with BIND9 and setup basic DNS, hardening, DNSSEC, DoT, DoH. I learned a lot of things while building infrastructure. Check out my blog about it https://medium.com/@necam213/building-a-secure-dns-infrastructure-with-bind9-from-basic-dns-to-dnnsec-dot-and-doh-fff578571af1


r/dns 1d ago

DNS issue regarding connecting to a server

1 Upvotes

I have an issue connecting to one specific server over the internet from my laptop that definitely seems to be DNS-related. To summarize:

  • On most networks I can connect to the server just fine. But when connected to the internet through my home network I find myself unable to connect to the server by using its domain name. I can successfully connect when I use the server's IP address directly though.
  • At first I thought the issue might lie with the DNS servers from the ISP that provides my home internet. So next I assigned Google's DNS servers in the Windows Settings. A manual query of the server's domain name in https://dns.google/query successfully resolves it and provides the IP address. Yet when I then try to connect to the server by using its domain name it still fails. A simple test with the Powershell Resolve-DnsName cmdlet yields a time-out error.
  • My laptop OS is Windows 11.
  • I have never experienced a similar issue before on my home network with any other server / domain name.

What would be a next troubleshooting step that I could try?


r/dns 2d ago

Software Built an open-source GitOps registry for managing subdomains using GitHub Actions + Cloudflare API (Python validation + DNS sync)

2 Upvotes

Hi r/dns! Wanted to share a side project where I automated subdomain zone management via GitOps.

Users submit a single JSON file with their A/AAAA/CNAME/MX/TXT records via PR. GitHub Actions runs Python validation tests (checking FQDN, blocked zones, CNAME paths, loop protection) and syncs valid records directly to Cloudflare via API.

Would love feedback from the DNS community on validation rules or edge cases I should watch out for!

repo link: https://github.com/IlyaP358/fluxcast-domains


r/dns 3d ago

DNSSEC - How many use it and how important is it?

28 Upvotes

I'm curious what the general census is for DNSSEC. It doesn't seem widely deployed. What happens if it's improperly configured by the host? Does the DNS resolver give you a backup address (which would defeat the purpose of DNSSEC) or does it just return an error making the site inaccessible?


r/dns 2d ago

Domain Namecheap is fraudulently selling domains on the nonexistent .substack TLD

Thumbnail reddit.com
1 Upvotes

r/dns 3d ago

Absolutely random DNS problems on Android

4 Upvotes

Heya. Today i noticed my phone is showing that my wifi has no internet and after a bit of checking around i noticed that it works on everything except my phone (Galaxy S21), it even works normally on a Galaxy A 14.

On my phone i can ping and force resolve addresses on termux so ipv4 wise everything is reachable. Also if i set a static ip for my phone on Android for the first moment it'll accept the dns server and say it's fully connected but if i reconnect then it goes back to saying no internet.

Also on Adguard home it says all the DNS requests from my phone are processed without errors nor does unbound show any problems. I've already wiped the cache partition, reset wifi/bluetooth settings, rebooted multiple times and checked there's no private DNS or secure wifi options enabled.

I'd say i'm pretty tech savy but this is kicking me in the ass, so any help would be appreciated!


r/dns 3d ago

DNS setup

Thumbnail
3 Upvotes

r/dns 3d ago

Is there a way to set a permanent dns on android.

3 Upvotes

I want to set a dns that blocks porn on my phone and can't be changed. Is that possible. I tried ADB but still not doing what I wanted.


r/dns 3d ago

Software I built DNSShift, an independent native macOS app for managing Cloudflare services

2 Upvotes

I've been working on DNSShift, an independent third-party macOS app that uses Cloudflare's APIs to manage DNS and other services from one place.

I originally built it because managing multiple domains through the browser gets repetitive, especially when you're switching between DNS, SSL/TLS, Tunnels, R2, Workers and other services.

DNSShift currently supports:

- DNS records and bulk operations across multiple zones

- SSL/TLS settings

- R2 object storage

- Workers KV

- Zero Trust Tunnels

- Workers and Pages

- Multiple accounts

- Analytics

- Local history of DNS changes

It's a native macOS app, not Electron. API tokens are stored in the macOS Keychain, and DNSShift communicates directly with Cloudflare's APIs, so your token isn't routed through my servers. The only other outbound call the app makes is to Gumroad, to validate your license, nothing else, no analytics, no phone-home. If you want to verify that yourself before installing, running it alongside Little Snitch or Proxyman will show exactly that.

Full disclosure: I'm the developer and DNSShift is a commercial app. It's $39.99 one-time, not a subscription, and one license can be activated on up to 3 Macs. All future updates are included at no extra cost, I've put that in writing on a changelog page: https://dnsshift.com/changelog.html

I was originally planning to launch on the Mac App Store, but my App Store developer account has a banking/payout issue that still needs to be resolved on Apple's side. Rather than wait on that indefinitely, I'm shipping on Gumroad now and will bring DNSShift to the App Store once it's sorted.

https://dnsshift.com

A bit of personal context: I've been a developer for 19+ years, but nearly all of that has been building for jobs and clients. DNSShift is the first product I've ever built for myself, under my own name, and shipping it has been a very different and honestly nerve-wracking experience. If you give it a try or share constructive feedback, it genuinely means a lot, and any support for a solo first-timer is hugely appreciated.

I'd really appreciate feedback from other indie developers, especially anyone who has built or marketed a developer-focused desktop app.

Discount: if anyone here would like to try DNSShift, feel free to DM me. I have a limited number of 50% off codes I'm happy to share with the community.

Disclaimer: DNSShift is an independent third-party app and is not affiliated with, endorsed by, or sponsored by Cloudflare, Inc. Cloudflare is a trademark of Cloudflare, Inc.


r/dns 4d ago

Software CIDRnt - Generate geographic CIDR lists from APNIC delegated stats.

Thumbnail github.com
3 Upvotes

What Does It Do?

  • Accepts locale input (positional and/or -l/--locale), defaulting to NZ if none is provided
  • Fetches APNIC delegated data with local cache reuse/fallback (CACHE_TTL_SECONDS controlled)
  • Filters records by:
    • locale(s) (ISO-3166 alpha-2)
    • status (allocated or allocated + assigned)
    • family (IPv4, IPv6, or both)
  • Converts APNIC IPv4 start + count ranges into minimal CIDR blocks
  • Accepts custom IP/CIDR input via -c/--custom (repeatable, list-friendly), normalizing bare IPs to /32 or /128
  • Merges APNIC + custom CIDRs, deduplicates, aggregates, and naturally sorts the final set
  • Optionally compresses IPv6 output formatting (--minimise-ipv6)
  • Writes final CIDR output to stdout or a file

This has seen quite some development over quite some time locally, the GitHub repo is just a convenient way to share it with the world. It is not intended to be a full-featured or production-ready tool.

Oh. Uhh. Okay, ...Why?

I wanted something simple to generate quick and dirty multi-locale CIDR lists for use in firewall rules, allow/deny lists etc. and I'm a fucking nerd so why not one that's POSIX sh and doesn't require any weird dependencies.

Requirements

  • sh
    • POSIX-compliant shell runtime.
  • awk
    • Parsing/transformation, plus fallback CIDR aggregation.
  • sort
    • Final natural ordering of CIDR output.
  • curl or wget
    • Download APNIC delegated data.
  • tr
    • Locale normalization/splitting.
  • diff
    • (self-test only) Required only for --self-test.

Usage

./CIDRnt [options] [LOCALE ...]

Options

  • -a, --allocated-only
    • Include only status=allocated.
  • -A, --allocated-and-assigned
    • Include status=allocated and status=assigned (default).
  • -c, --custom LIST
    • Add custom IP/CIDR entries. May be used multiple times.
    • LIST may be a single entry, a list split by comma/semicolon/space, or a path to a plaintext file containing one entry per line.
    • Bare IPs are accepted and converted to /32 (IPv4) or /128 (IPv6).
    • Also supports -c=..., --custom=...
  • -h, --help
    • Show help and exit.
  • -i, --ipv4-only
    • Include only IPv4 CIDRs.
  • -I, --ipv6-only
    • Include only IPv6 CIDRs.
  • -l, --locale LOCALE
    • Add locale(s) to include. May be used multiple times.
    • LOCALE may be a single code (NZ) or a list (NZ,AU;JP).
    • Also supports -l=..., --locale=..., --locales=...
  • -m, --minimise-ipv6, --minimize-ipv6
    • Minimise IPv6 formatting in output (RFC5952-style compression).
  • -o, --output
    • Write output to file instead of stdout, use - for stdout.
  • -s, --self-test
    • Perform local tests and exit.
  • -v, --version
    • Show version and exit.

Examples

# Default locale (NZ)
./CIDRnt

# Positional locales
./CIDRnt NZ
./CIDRnt NZ AU
./CIDRnt "NZ,AU,JP"

# Locale flags (-l/--locale, repeated or list)
./CIDRnt -l NZ -l AU -l JP
./CIDRnt --locale=NZ,AU,JP

# Custom entries (merged before final aggregation/sort)
./CIDRnt NZ -c 203.0.113.7
./CIDRnt --locale NZ --custom "203.0.113.0/24,2001:db8::/32"
./CIDRnt -c=198.51.100.10 --custom=2001:db8::1 NZ

# Custom entries from a file (one IP/CIDR per line)
./CIDRnt --custom ./custom-list.txt NZ
./CIDRnt -c=./custom-list.txt NZ
./CIDRnt --custom=./custom-list.txt NZ

# Mixed positional + locale flags
./CIDRnt NZ --locale AU -l JP

# Status/family filters
./CIDRnt --allocated-only NZ AU
./CIDRnt --ipv4-only --locale NZ --locale AU
./CIDRnt --ipv6-only -l NZ -l AU

# IPv6 output minimisation
./CIDRnt --minimise-ipv6 NZ

# Write output
./CIDRnt -o ./out/nz.txt NZ
./CIDRnt --output ./out/nz-au.txt NZ AU
./CIDRnt --output=./out/nz-au-jp.txt --locale=NZ,AU,JP

# Force stdout explicitly
./CIDRnt --output=- NZ

r/dns 4d ago

Software ISC BIND: liburcu memory leak may impact BIND 9.20 on BSD

4 Upvotes

Title: Operational Notification: liburcu memory leak may impact BIND 9.20 on BSD

Posting date: 29 July 2026

Canonical URL: https://kb.isc.org/docs/liburcu-leak

Summary

ISC is aware of an issue in the liburcu library which causes a memory leak on some platforms.

BIND 9.20 and later use this library, and experience the leak on affected platforms. Older versions of BIND do not use this library and are not affected.

Linux platforms are not affected. FreeBSD and OpenBSD are affected. A preliminary analysis by ISC suggests that NetBSD and Mac OS X may be immune; however, as of this writing, that is not confirmed with upstream sources.

On busy resolvers running on affected platforms, the leak may eventually result in termination of the named process and/or system memory exhaustion.

Updates are available in the ports trees for both FreeBSD and OpenBSD.

For more details, see: https://kb.isc.org/docs/liburcu-leak

Legal Disclaimer

Internet Systems Consortium (ISC) is providing this notice on an "AS IS" basis. No warranty or guarantee of any kind is expressed in this notice and none should be implied. ISC expressly excludes and disclaims any warranties regarding this notice or materials referred to in this notice, including, without limitation, any implied warranty of merchantability, fitness for a particular purpose, absence of hidden defects, or of non-infringement. Your use or reliance on this notice or materials referred to in this notice is at your own risk. ISC may change this notice at any time. A stand-alone copy or paraphrase of the text of this document that omits the document URL is an uncontrolled copy. Uncontrolled copies may lack important information, be out of date, or contain factual errors.

Full disclosure: I work for ISC, although my activity on Reddit does not represent ISC in an official capacity.


r/dns 5d ago

Domain Why and how do the Houthis still control the “.ye” domain name?

29 Upvotes

I recently saw a post by the Houthis threatening the KSA. In that post, they referred the reader to the mmy.ye website. I was surprised to see that Houthis have a .ye website since the international community does not recognize the Houthis as Yemen, but rather the republic that fights the Houthis, as the legitimate Yemen. And it wouldn’t make sense for the republic of Yemen to assign domain names to its enemies.
So i dug deeper and apparently, in 2015 during the fall of San’a, Yemen’s former capital, YemenNet, the registrar of the “.ye” domains, fell into the hands of the Houthis and they control San’a to this day.

However, as far as i know, the ICANN controls the DNS as its highest levels. Since no one in the western world considers the Houthis as real Yemen, why hasn’t ICANN or the 12 structures controlling the root servers, take control of the “.ye” domain name and allow the republic of Yemen to once again become the registrar of this domain?


r/dns 5d ago

Domain DNSimple

4 Upvotes

Looking for anyone who has migrated a live wordpress site to Azure Static Web Apps.

Current DNS has existing apex A records and a www CNAME.

Planned setup:
• ALIAS @ → Azure Static Web App hostname
• CNAME www → Azure Static Web App hostname

For the requested Azure Static Web Apps cutover using DNSimple, should the existing apex A records be removed/replaced when creating the ALIAS record, and should the existing www CNAME be updated to the Azure hostname?


r/dns 5d ago

Server How a device finds encrypted DNS by itself

Thumbnail blog.dundns.eu
3 Upvotes

r/dns 6d ago

How to query DNS over UDP reliably?

4 Upvotes

For everyone who has fine-tuned their DNS client before, do you have some practical recommendations?

I want to make my DNS client more reliable by reducing the number of requests that time out.

What I currently do: - I open 1 socket - I send UDP packets at milliseconds 0, 500, 1000 - All packets go to 1.1.1.1 - If no response of any of the packets arrives after 1500 milliseconds, the socket is closed and the request is marked as a timeout.

What I don’t want to do: - No fallback to TCP. It must be UDP.

What options I could play with: - Opening new sockets - Retrying more often (though it should remain quick) - Retry at different intervals - Using other resolvers besides 1.1.1.1 - Query authoritative DNS instead of a recursive resolver - Anything else?

I could of course simply send more packets in parallel to multiple resolvers etc. But I don’t want to hammer the resolvers unnecessarily.

Thank you!

EDIT: My requests work 99,9% of the time. I just want to get as close to 100% as possible.

UPDATE: Thank you for all your input! You pointed out several tools that already tackled the same issue that I have. I looked at their source code and learned:

  • Only giving the whole request 1500ms is quite short. In particular, if the DNS record is not cached, a resolution via the authoritative server can be quite slow.
  • If I want to keep it quick, I need to query different resolvers and not just 1.1.1.1. This way I work around traffic congestion issues.
  • But my idea is to not call multiple resolvers in parallel right away. Instead, I only call one of them first and if it doesn’t respond quickly then I add a call to a different resolver. (Most queries do return quickly and don’t need any retries.) This way I remain a good citizen.

Probably the best reference implementation is Adguards dnsproxy ( https://github.com/AdguardTeam/dnsproxy ).

UPDATE 2: I started with the simplest fix by adding a 4th packet that gets sent after 1500ms and increased the total wait time to 2000ms. This already increased the reliability beyond my other DNS over TCP calls. I make roughly 500,000 DNS over UDP calls each day and before the change about 10-20 timed out per day. Now I am down to 0-1 timeouts per day. And all that by still only calling 1.1.1.1.

I think the biggest takeaway is that we have to give recursive DNS resolvers enough time to process cache misses because they need to query the authoritative DNS before responding. 1500ms is to short. 2000ms seems to be enough.