I responded to someone in comments on a post that may not get as much visibility, and wanted to share something that might help some others who are new or unfamiliar.

I referenced Quad9 DNS as probably one of the best private DNS you can use, Swiss based, no log, no tracking, no data to sell, etc. They also implement DNSSEC, DoH, DoT, QUIC, ECS (which you may or may bot want), malware blocking, content filtering, and maybe something else I’m forgetting.

Many DNS sinkhole apps, OSes, or systems can actually utilize Quad9 for your resolver while those systems also block ads. Below is my functional list of systems that I’m aware of, though I haven’t tested everything. I believe all are considered FOSS, too. If you don’t have a spare Raspberry Pi laying around, try running in HomeAssistant, Yunohost, ZimaOS (previously CasaOS), or others.

DNS sinkhole (Adblocking) apps:

  1. Pihole
  2. eBlocker
  3. Technitium
  4. AdGuard
  5. uBlock Origin

Feel free to comment and add your own I’m maybe not aware of. I’m no software engineer, but I can read through some code, though not an expert, nor have combed through these personally. Usually I’ve tested/run at the recommendation of others over the years before my ban on Reddit (for shitting on AI).

Hope this helps!!

  • non_burglar@lemmy.world
    link
    fedilink
    arrow-up
    1
    ·
    3 小时前

    I’ve been using technitium in a primary/secondary pair for about three years, and oldheads like me definitely like the real DNS server options, like zone transfers. Very stable, too.

  • hneerqe@lemmy.world
    link
    fedilink
    arrow-up
    2
    ·
    11 小时前

    I just do it all in my openwrt router now. Set up any DoH (https-dns-proxy) or DoT (stubby) with DNSSEC, plus blocklists with adblock-fast.

    Hagezi has some servers with default blocking https://github.com/hagezi/dns-servers

    https://github.com/hagezi/dns-blocklists#dnsservices

    I was liking NextDNS, they have good features, and I liked not having to maintain blocklist files with shady domains in plain text saved in my hardware, but their jurisdiction and their code being closed source made me reevaluate.

    • unitedwithme@lemmy.todayOP
      link
      fedilink
      arrow-up
      1
      ·
      15 小时前

      I do use DNSSEC for my website and my XMPP server. I do not use ECS as Quad9 references possible IP addresses leaking https://quad9.net/support/faq/#edns.

      For my home network, my piholes point to:

      IPv4

      • 9.9.9.9
      • 149.112.112.112

      IPv6

      • 2620:fe::fe
      • 2620:fe::9

      I do also use https://dns.quad9.net/dns-query for my phone when on data or non-Home WiFi. I typically use a VPN, but for logging into my bank website I need to disable the VPN. I have LineageOS with no 3rd party Google Play apps, they’re all FOSS through F-Droid.