~/tools/dns

DNS & Network

last updated 2026-08-02 ยท 8 recommendations ยท what changed

Every site you visit starts with a DNS lookup, and by default those lookups go to your ISP in plaintext. Switching to an encrypted, filtering resolver is a ten-minute change that upgrades every device on your network, blocking ads and malware before a connection is ever made.

before you pick DNS filtering blocks requests at the name level: strong against trackers and malware domains, weaker against ads served first-party (YouTube's, for instance). It complements blocking in the browser; it doesn't replace it. And any third-party resolver requires trusting that party with your query log; self-hosting is the only way out of that trade.

encrypted transport

DoH or DoT keeps lookups unreadable on the wire. Every pick here supports both; your OS or router does too.

logging policy

The resolver sees every domain you visit. What it keeps, for how long, and under whose laws is the core question.

filtering control

From fixed lists (zero effort) to fully custom rules per device. More control means more maintenance: pick your tier.

consistency with your tunnel

If you run a VPN, your DNS should match its infrastructure: a mismatched resolver fragments your fingerprint and leaks intent.

AdGuard DNS

the default pick
๐Ÿ‡จ๐Ÿ‡พ cyprusencrypted dnsad blockingfree tier

AdGuard DNS is a practical, reliable encrypted resolver with strong blocklists and the broadest device support in the category: the public resolver (94.140.14.14) blocks ads and trackers with zero setup and no account. The server side isn't fully open source, but the company has a long, consistent track record in security, and its home-server sibling (AdGuard Home) is fully FOSS. It covers most everyday use cleanly; the paid tier adds dashboards and custom rules.

good
  • Ad and tracker blocking with no account needed
  • Supports DoH, DoT, and newer DNS-over-QUIC
  • Long-running company with an open-source culture
  • Paid tier adds per-device profiles and custom rules
mind the
  • Public tier keeps anonymized 24h logs for operations
  • Server side isn't fully open source
  • Cyprus jurisdiction is less battle-tested than Switzerland
  • Founded in Moscow in 2009 before later relocating its HQ to Cyprus
public free ยท private from ~$3/mo adguard-dns.io โ†’

Mullvad DNS

the contextual pick
๐Ÿ‡ธ๐Ÿ‡ช swedenencrypted dnsno logsno accountfree

Mullvad DNS is Mullvad's public resolver, free for everyone (not just VPN customers), with the same no-logs stance as the VPN and optional ad and tracker filtering endpoints. The headline use is consistency: when you're on Mullvad's VPN (or Tor), keeping DNS inside the same infrastructure preserves a uniform fingerprint instead of announcing a third party. It's been growing into a solid standalone recommendation too.

good
  • Clean no-logs policy from a raid-tested operator
  • Filtering variants (ads, trackers, malware) selectable by hostname
  • The right answer whenever Mullvad VPN is already in your stack
mind the
  • Encrypted transport only: no plain port-53 fallback for dumb devices
  • No dashboards, analytics, or per-device control at all
  • Fixed lists; can't allowlist a single false positive

Quad9

the neutral pick
๐Ÿ‡จ๐Ÿ‡ญ switzerlandencrypted dnsno logsnonprofitfree

Set 9.9.9.9 and you're done: Quad9 is a Swiss nonprofit resolver that blocks malware domains, keeps no per-user logs, and asks nothing of you. It doesn't filter ads; it's a security resolver, not an ad blocker, and that's exactly why it's worth knowing: a clean, trustworthy, threat-focused option for when you want neutrality instead of curation.

good
  • Nonprofit under Swiss privacy law: no commercial incentive to log
  • Malware/phishing blocklist on by default
  • Anycast network; fast nearly everywhere
mind the
  • No ad/tracker filtering: pair with browser-level blocking
  • No customization or per-device control at all
  • Occasional false positives are hard to appeal quickly
free, nonprofit quad9.net โ†’

NextDNS

the power-user pick
๐Ÿ‡บ๐Ÿ‡ธ usaencrypted dnscustomizablefree tier

NextDNS is a Pi-hole in the cloud: pick your blocklists, see analytics per device, set parental controls, and carry the config everywhere your devices roam. It's the most filtering power you can get without hosting anything, and the logging options match: you decide the retention, down to zero. It's more tool than appliance; budget the occasional evening of allowlisting.

good
  • Granular blocklists, allowlists, and per-profile settings
  • Works on the go: profiles follow your phone off the home network
  • Configurable log retention and storage region, including none
mind the
  • US company; logging is opt-out by configuration, not impossible by design
  • Past the free quota (300k queries/mo) it stops filtering until you pay
  • Easy to over-block and spend evenings whitelisting
free tier ยท ~$2/mo unlimited nextdns.io โ†’

Self-host

the self-host pick
self-hostableopen sourcecustomizablead blockingfree

Run your own filtering resolver on a Raspberry Pi or any always-on box, and no third party sees your lookups at all, which is the only complete answer to the trust question every entry above carries. AdGuard Home is the slicker, FOSS, encrypted-out-of-the-box option; Pi-hole is the decade-old community classic. Pair either with Unbound and you're not even trusting an upstream resolver.

good
  • Your hardware, your rules, your logs (or none)
  • Covers smart TVs and IoT junk that can't run blockers
  • With Unbound upstream, fully independent recursive resolution
  • AdGuard Home speaks DoH/DoT natively, both directions
mind the
  • You're now a sysadmin: updates, uptime, and "the internet is broken" complaints are yours
  • Only protects you at home unless you route back via WireGuard
  • Needs an always-on device (~โ‚ฌ40 Pi or an existing server)
free software ยท ~โ‚ฌ40 one-off hardware adguard home โ†’ ยท pi-hole โ†’

ControlD

the customization pick
๐Ÿ‡จ๐Ÿ‡ฆ canadaencrypted dnscustomizablefree tier

ControlD is the dial-in-everything option: per-device profiles, toggleable block-list categories (ads, malware, social, gambling, and dozens more), custom rules per domain, and analytics, all from one dashboard. It's more granular than NextDNS in the controls it exposes, at the cost of a steeper setup curve. Pick it if you want to tune exactly what's blocked on exactly which device, not if you want to set it once and forget it.

good
  • Very granular per-device and per-profile block-list control
  • Supports DoH, DoT, and DNS-over-QUIC
  • Free tier is genuinely usable, not just a trial
  • Custom routing rules (split DNS, redirects) beyond simple blocking
mind the
  • The dashboard's depth is a learning curve, not a five-minute setup
  • Canada is a Five Eyes jurisdiction, if that's in your model
  • Easy to over-configure and spend an evening tuning rules
free tier ยท paid tiers from ~$2/mo controld.com โ†’

ReThinkDNS

the all-in-one pick
๐Ÿ‡ฎ๐Ÿ‡ณ indiaencrypted dnspartially open sourceno accountfree tier

ReThinkDNS is a free encrypted resolver (DoH and DoT) with over 190 selectable blocklists, run by Celzero out of India. Its Android app pairs the resolver with a local firewall that tracks and blocks connections per app, and neither needs a signup. A WireGuard VPN add-on (RPN, from $1.75/month) rounds out a bundle nothing else in this category offers in one free app. The open app and resolver code are the main reassurance on offer; no independent audit exists, and Indian jurisdiction brings data-retention rules worth weighing.

good
  • Free core with no signup: encrypted DNS plus a per-app firewall and connection tracker
  • DNS, firewall, and WireGuard VPN in one Android app is a rare bundle
  • App and resolver code are both open source
mind the
  • No independent audit; the no-logging policy is the company's word alone
  • India's CERT-In rules require five-year identity retention from VPN-classified providers; the company hasn't publicly addressed this
  • The app (firewall included) is Android-only; other platforms only get the resolver endpoints
  • RPN is a paid add-on, separate from the free core
free core ยท RPN from $1.75/mo rethinkdns.com โ†’

Cloudflare DNS

the audited pick
๐Ÿ‡บ๐Ÿ‡ธ usaencrypted dnsauditedpartially open sourcefree

Cloudflare DNS (1.1.1.1) is the big mainstream free resolver, and what sets it apart here is verification: KPMG has independently audited Cloudflare's data-handling claims, most recently in April 2026, so the 25-hour retention figure is a checked fact instead of a promise. Few free resolvers can show anything close. Just know what you're getting: it's a plain, fast resolver that filters nothing, run by a giant US company, and the trust rests on that audit, not on open code.

good
  • KPMG-verified logging claims: 25-hour retention, full IPs never written to disk
  • Free with no tiers; DoH, DoT, DNS-over-Tor, and Oblivious DoH all supported
  • Never blocked or filtered content despite legal requests, per its transparency reports
  • Only one third party (APNIC) receives query data, anonymized and IP-free
mind the
  • The base resolver doesn't filter ads or trackers at all
  • The resolver's backend is closed source, and the KPMG report is request-only
  • US jurisdiction, if that's in your threat model
  • A 62-minute global outage in July 2025, disclosed in a detailed public post-mortem
resolverblocks adsblocks malwarecustom rulesloggingeffortcost
AdGuard DNSyesyespaid tier24h ops logsnonefree
Mullvad DNSoptionaloptionalnonone keptnonefree
Quad9noyesnonone keptnonefree
NextDNSyesyesfullyou configurelowfree / ~$2/mo
Self-hostyesyesfullyours alonehighhardware
ControlDyesyesfull, per-deviceyou configuremediumfree / ~$2/mo
ReThinkDNSyesyesblocklist choicestated no-logs, unauditedlowfree
Cloudflare DNSnonono25h, auditednonefree

all support encrypted transport (self-hosted via upstream configuration; mullvad is encrypted-only).

Set it at the router if you can. One change covers every device, including the ones you can't configure. Phones and laptops that leave the house should also get the resolver set per-device (iOS/Android both support DoT/DoH profiles natively).

Match DNS to your VPN. A VPN tunnel carries its own DNS. On Mullvad, use Mullvad DNS; on Proton, NetShield. Keeping resolution consistent with the tunnel's infrastructure preserves a uniform fingerprint; fighting your VPN to use a third party does the opposite.

Expect some breakage, know the fix. A login page that won't load or an email link that dies is usually one allowlist entry away. Filtering DNS without knowing how to whitelist is how people end up back on the ISP default.

Your resolver sees a lot: choose like it matters. Domain history is a complete map of your interests. "Free" resolvers from ad companies are free for a reason; everything recommended here has a published, plausible reason to exist, and self-hosting removes the question entirely.