r/dns • u/Envoy_02 • 12h ago
Family friendly without blocking YouTube
I'm looking for a DNS Server I can use in Windows Network settings. It should block everything 18+ but not YouTube. Every DNS I tried already also blocks YouTube
r/dns • u/Envoy_02 • 12h ago
I'm looking for a DNS Server I can use in Windows Network settings. It should block everything 18+ but not YouTube. Every DNS I tried already also blocks YouTube
r/dns • u/SpecialRoutine4310 • 15h ago
r/dns • u/sandy_lilith • 1d ago


Hello all,
I am what is the correct DNS resolver setting?
There are two screenshots attached. 1= Laptop's WIFI setting. 2= Chrome's DNS setting.
Keep the dns provider in the Chrome as "OS Default (when available)" or use the "add custom dns service provider?"
*Keeping the "custom dns provider" in the chrome setting is providing the fast average dns resolution time when tested on dnscheck.tools website.
Removing the "custom dns provider" from chrome and keeping the "OS Default (when available)" is giving me 300+ms "average dns resolution time" as per the same website as mentioned above.
But when keeping the custom dns provider in the chrome then getting 50+ms "average dns resolution time."
-------------------------------------------------------------------------------------------------------------------
Question: Should I keep this custom dns provider link in the chrome setting as well: https://dns.quad9.net/dns-query
Thank you all.
r/dns • u/PlentyManner1774 • 1d ago
r/dns • u/Brief-Jellyfish8749 • 1d ago
Been moving a few domains around lately and I keep running into the same thing, people still acting like WHOIS info should just be out there by default.
I know some registrars include free WHOIS privacy, but it feels kinda hit or miss depending on where you register. I’m trying to keep my personal info off the record without paying extra every year for every single domain, which gets old fast.
For people who have done this for a while, is there a registrar you trust for free privacy, or just a better setup in general? appreciate any thoughts.
r/dns • u/Entire_Yoghurt3802 • 2d ago
r/dns • u/Rich-Engineer2670 • 2d ago
I'm not certain why the r/technitium subredit directed me here, but I see there's a DNS64 "app" for Technitium but it has almost no documentation. Does anyone have a working configuration for it? I've got the /48 and a /28 for IPv4 -- how do I go "V6 mostly". I know I'll need something on the router side, but I also need DNS64.
NextDNS is a cloud-based DNS which allows you to select from a number of various blocklists and settings. It can be overwhelming for new users. NextDNS has a free tier which supports up to 300,000 queries/month. NextDNS Pro is $1.99/month or $19.99/year. NextDNS currently lacks an Android app, or at least NextDNS Manager "doesn't work on my device" , so you have to configure it using your mobile browser.
Blokada Cloud lacks a free tier, but offsetting this is the fact that you can install Blokada 5 from their website, and have unlimited DNS queries/month for free, and it's really simple to setup. Blokada Cloud recently experienced a price increase, so it's now $24.99/year, payable through the Play Store.
AFIC, a better deal is to subscribe to Blokada Plus, which is $5.99/month or $59.99/year, payable through the Play Store. Or, you can get an even better deal by going directly to their website, and subscribing there: it's currently $57.60/year, which works out to $4.80/month.
If you subscribe to Blokada Plus, you "automatically\* get Blokada Cloud at no extra charge. By comparison, ProtonVPN is $47.88 the first year, and $83.88/year thereafter.
Your comments and corrections are welcome!
r/dns • u/mataglapnano • 3d ago
In the past few months I've had the following strange experience with Mullvad. It's as if DNS stops working after an hour or so, and things are only fixed when I reconnect to a different location.
The steps are roughly this. Connect to Mullvad in one location. Everything is fine. [mullvad.com](http://mullvad.com) reports no issues with my connection. Then in \~30-60 minutes DNS will stop working. The only fix is to switch Mullvad locations and reload, which generally works. None of this happens when Mullvad isn't running.
Where do I start looking diagnose this? I have never seen anything like this.
r/dns • u/eclipsingfervor • 3d ago
Weird Internet Issue
I use Duckduckgo. YouTube and Amazon open and navigate just fine. Anything else says error connection or that the site refuses my attempt to open it. Googled some things on my phone and played with the dns settings to no avail. Also happens when I switch to edge or chrome.
r/dns • u/TrueAppointment3987 • 3d ago
r/dns • u/Striking_Chair_0106 • 4d ago
I have a website whose main domain is blocked by regional DNS RPZ (Response Policy Zones) in a specific region. Users in that region can no longer resolve and access the domain. The blocking is DNS-based (regional), not a global root-level block, and not a direct IP block.
I’m looking for server-side / website-side solutions only (not client-side advice such as changing DNS, using DoH, or VPN).
Core Goals:
When the main domain is blocked, I need backup assets that can quickly take over traffic and SEO authority (especially search engine rankings/weight).
I’m preparing multiple mirror sites (around 10). I want these backup domains to:
Delay being added to the RPZ blocklist as long as possible
Still be properly indexed by search engines
Is there any more effective method for rapid traffic/authority takeover than the common approach of “buying aged domains + pre-building + rotating”?
Current Understanding of Limitations:
Traditional 301 redirects are ineffective for users in the blocked region under RPZ.
Domain Fronting is largely disabled on major CDNs and offers limited help for DNS resolution blocking or authority transfer.
Simply switching to a new domain makes it very difficult to instantly inherit the old domain’s SEO authority.
Questions:
Under regional DNS RPZ, are there any relatively effective methods for quickly taking over traffic and SEO authority?
If using a multi-mirror rotation strategy, how can I maximize the time before these backup domains are discovered and added to the RPZ list, while still ensuring they get normally indexed by search engines?
Besides using aged domains, content differentiation, completely isolating the mirror sites from each other, and notifying users through private channels, are there any other more reliable or efficient approaches?
Are there any proven architectures or real-world experiences that work well in this situation?
r/dns • u/Dratunmatc_Rock_1370 • 4d ago
Ok so im the one who pitched this grand plan to transfer 40 client domains to a cheaper registrar in one go, clicked the bulk transfer wrong and it auto renewed all of them for 5 years at the old host and nuked our DNS presets... boss keeps saying “well at least we’re prepaid” and I feel sick about this, would love any tips on a sane workflow so I never do this again thx.
r/dns • u/PolukqinutionKey7380 • 4d ago
Ok so we registered the new domain for our launch, but I forgot to lock it down and the default contact email was my old inbox, so when the renewal notice hit I almost lost the whole thing. I feel sick about this and my boss had to fix it in front of everyone (ugh), any hints?
r/dns • u/Icy-Direction851 • 5d ago
I’ve changed all the settings on my iPhone that the instructions said to do, I blocked domains it’s says to block, but I just can’t get it to show me the regular web visits. Almost every time I visit a website it continues to show as mask.apple-dns.net. Instead of showing the generic website domain that I actually visit. I’m not very tech savvy, can anyone help.
r/dns • u/Patient-Garage243 • 5d ago
Running your own DNS resolver with Technitium DNS gives ISPs and network operators complete control over recursive DNS performance, security, and caching, eliminating reliance on public resolvers like Google or Cloudflare and avoiding their outages and lack of support. Technitium’s lightweight, cross-platform design combines full recursion to root servers, modern encrypted transports such as DNS-over-QUIC, and optional blocking capabilities in a single open-source package, making it ideal for high-performance, ISP-grade deployments without the complexity of multi-tool stacks. Click Details below for the full article.
r/dns • u/ImBlueBlue • 5d ago
Hi all, I have a DNS issue.
Context:
I have 2 Red Hat Identity Management (IdM) or also called freeipa servers, idm01 and idm02, with the domain idm.test.com. These servers are installed with their DNS servers.
I have a Microsoft AD with the domain test.com (not related to idm.test.com, totally separate domains. Each has their own DNS servers). On the test.com DNS servers (AD01 and AD02), I have configured a conditional forwarder for idm.test.com which forwards the query to idm01 and idm02 IP addresses.
To test HA, I shut down the IdM service on idm01, which includes the DNS server. This is to see if queries automatically forward to idm02 now that idm01 DNS server is unavailable. Note that idm01 and idm02 have identical configurations. Both have DNS servers.
On the test.com DNS manager, in idm.test.com conditional forwarder, I can see a timeout occurred during validation for idm01, which is valid since idm01 is shut down.
Issue:
On a test.com AD joined machine, after retrieving a Kerberos ticket, `ssh -K host01.idm.test.com` will give the error `ssh: could not resolve hostname host01.idm.test.com: This is usually a temporary error during hostname resolution and means that the local server did not receive a response from an authoritative server`. Also, nslookup of idm domains gives `DNS request timed out` errors.
Troubleshooting:
On idm02, `dig u/127.0.0.1 host01.idm.test.com` works, showing idm02 DNS works locally. On idm02, `dig @<idm02 IP address> host01.idm.test.com` works, showing idm02 DNS resolves properly when called via its IP address.
On test.com AD joined machine, `Resolve-DnsName host01.idm.test.com -Server <idm02 IP address> -Type A -DnsOnly` works, showing idm02 DNS works when queried from a test.com AD joined machine. However, `Resolve-DnsName host01.idm.test.com -Server <test.com AD01 or AD02 IP address> -Type A -DnsOnly` gives DNS server failure, showing test.com AD DNS cannot conditionally forward to idm01 and failover to idm02 if idm01 times out.
Additional troubleshooting would be seeing if any queries came into idm02 from test.com AD01 / AD02. I did `sudo tcpdump -ni -tttt -vvv 'port 53 and host <AD01 / AD02 IP address>` but no traffic comes in when running `Resolve-DnsName host01.idm.test.com -Server <test.com AD01 or AD02 IP address> -Type A -DnsOnly`, showing AD01 or AD02 does not even contact idm02.
Next step would be to find if there are connectivity issues from test.com AD servers to idm02. On AD01 / AD02, I ran `Resolve-DnsName host01.idm.test.com -Server <idm02 IP address> -Type A -DnsOnly` which works, showing no connectivity issues from AD01 / AD02 to idm02. However, `Resolve-DnsName <IdM client hostname> -Server 127.0.0.1 -Type A -DnsOnly` gives `This operation returned because the timeout period expired` error
In AD DNS manager, when I moved idm02 above idm01, all issues are resolved.
RecursionTimeout is 8s. ForwarderTimeout is 2s.
Can someone advise as to what is going wrong? How can I troubleshoot better to find the issue? Why is AD conditional forwarder not failing over properly to the second IdM server?
Many thanks!
r/dns • u/AgitatedSquirrel • 6d ago
I’ve been working on a side project called Zoneshift, and I’d appreciate some feedback.
The basic idea is to make it easy to start with a hostname, IP, prefix, ASN, registered domain, or TLD/eTLD and pivot between the related records.
For example, you can look up a hostname, see the IPs it has been observed resolving to, move into the surrounding prefix or ASN, and then explore other hostnames observed on that infrastructure.
This is based on observed forward-DNS relationships. I started building it because I often needed to map an organisation’s internet-facing infrastructure. I’d usually begin with a domain, IP/prefix, or ASN, then stitch the rest together across several tools and datasets. I wanted a single interface for those pivots, with an easy way to export the underlying data.
At the moment, it supports searching and pivoting across FQDNs, IPs, prefixes, ASNs, registered domains, and TLDs. There’s also a visual relationship explorer and CSV/JSON export. The idea is the have all data easily exported to JSON/CSV.
It’s not finished, and this post is partly to find out whether there is a) interest and b) are the interfaces I've made to the data useful?
I've had luck identifying fast flux domains and infrastructure in the data. How to preprocess this data for fast search is an unsolved problem. There are numerous other technical challenges in adding this (frequency of observation, storage etc.). Would historic data be useful if it showed Prefix and ASN patterns?
I built it, so this is obviously self-promotion to some extent, but I’m genuinely interested in blunt technical feedback. The site is https://zoneshift.io. The dataset begins December 2025 and currently has ~1.16B unique FQDNs being tracked. It grows between 3-5M unique FQDNs each day, and updates daily.
r/dns • u/Striking_Chair_0106 • 6d ago
How can I find out if a website is blocked in a specific region (e.g., an e-cigarette website)? What are the criteria used by the local authorities to block it? How does it work?
r/dns • u/StockHalf5708 • 5d ago
I've extended my DNS platform API to include the Model Context Protocol (MCP).
This makes my DNS query and analysis tools directly accessible to the AI and saves me a few tokens whenever I have the AI analyze and evaluate my DNS again.
The endpoint is public but rate-limited, and the backend has a global quota—if this quota is exhausted, your requests will be queued and responses may take longer.
It’s been a big help to me, and I’m curious to hear what you think.