~/tools/dns
DNS & Network
last updated 2026-08-02 ยท 8 recommendations ยท what changed
Every site you visit starts with a DNS lookup, and by default those lookups go to
your ISP in plaintext. Switching to an encrypted, filtering resolver is a
ten-minute change that upgrades every device on your network,
blocking ads and malware before a connection is ever made.
before you pick
DNS filtering blocks requests at the name level: strong against trackers and
malware domains, weaker against ads served first-party (YouTube's, for instance).
It complements blocking in the browser;
it doesn't replace it. And any third-party resolver requires trusting that
party with your query log; self-hosting is the only way out of that trade.
what actually matters
encrypted transport
DoH or DoT keeps lookups unreadable on the wire. Every pick here supports both; your OS or router does too.
logging policy
The resolver sees every domain you visit. What it keeps, for how long, and under whose laws is the core question.
filtering control
From fixed lists (zero effort) to fully custom rules per device. More control means more maintenance: pick your tier.
consistency with your tunnel
If you run a VPN, your DNS should match its infrastructure: a mismatched resolver fragments your fingerprint and leaks intent.
recommendations

AdGuard DNS
the default pick
๐จ๐พ cyprusencrypted dnsad blockingfree tier
AdGuard DNS is a practical, reliable encrypted resolver with strong
blocklists and the broadest device support in the category: the public
resolver (94.140.14.14) blocks ads and trackers with
zero setup and no account. The server side isn't fully open
source, but the company has a long, consistent track record in security, and
its home-server sibling (AdGuard Home) is fully FOSS. It covers most
everyday use cleanly; the paid tier adds dashboards and custom rules.
good
- Ad and tracker blocking with no account needed
- Supports DoH, DoT, and newer DNS-over-QUIC
- Long-running company with an open-source culture
- Paid tier adds per-device profiles and custom rules
mind the
- Public tier keeps anonymized 24h logs for operations
- Server side isn't fully open source
- Cyprus jurisdiction is less battle-tested than Switzerland
- Founded in Moscow in 2009 before later relocating its HQ to Cyprus

Mullvad DNS
the contextual pick
๐ธ๐ช swedenencrypted dnsno logsno accountfree
Mullvad DNS is Mullvad's public resolver, free for everyone (not just VPN
customers), with the same no-logs stance as the VPN and optional ad and
tracker filtering endpoints. The headline use is consistency:
when you're on Mullvad's VPN (or Tor), keeping DNS inside the same
infrastructure preserves a uniform fingerprint instead of announcing a third
party. It's been growing into a solid standalone recommendation too.
good
- Clean no-logs policy from a raid-tested operator
- Filtering variants (ads, trackers, malware) selectable by hostname
- The right answer whenever Mullvad VPN is already in your stack
mind the
- Encrypted transport only: no plain port-53 fallback for dumb devices
- No dashboards, analytics, or per-device control at all
- Fixed lists; can't allowlist a single false positive

Quad9
the neutral pick
๐จ๐ญ switzerlandencrypted dnsno logsnonprofitfree
Set 9.9.9.9 and you're done: Quad9 is a Swiss nonprofit resolver
that blocks malware domains, keeps no per-user logs, and asks nothing of you.
It doesn't filter ads; it's a security resolver, not an ad
blocker, and that's exactly why it's worth knowing: a clean,
trustworthy, threat-focused option for when you want neutrality instead of
curation.
good
- Nonprofit under Swiss privacy law: no commercial incentive to log
- Malware/phishing blocklist on by default
- Anycast network; fast nearly everywhere
mind the
- No ad/tracker filtering: pair with browser-level blocking
- No customization or per-device control at all
- Occasional false positives are hard to appeal quickly

NextDNS
the power-user pick
๐บ๐ธ usaencrypted dnscustomizablefree tier
NextDNS is a Pi-hole in the cloud: pick your blocklists, see analytics per
device, set parental controls, and carry the config everywhere your devices
roam. It's the most filtering power you can get without hosting
anything, and the logging options match: you decide the retention,
down to zero. It's more tool than appliance; budget the occasional evening
of allowlisting.
good
- Granular blocklists, allowlists, and per-profile settings
- Works on the go: profiles follow your phone off the home network
- Configurable log retention and storage region, including none
mind the
- US company; logging is opt-out by configuration, not impossible by design
- Past the free quota (300k queries/mo) it stops filtering until you pay
- Easy to over-block and spend evenings whitelisting

Self-host
the self-host pick
self-hostableopen sourcecustomizablead blockingfree
Run your own filtering resolver on a Raspberry Pi or any always-on box, and
no third party sees your lookups at all, which is the only
complete answer to the trust question every entry above carries. AdGuard Home
is the slicker, FOSS, encrypted-out-of-the-box option; Pi-hole is the
decade-old community classic. Pair either with Unbound and you're not even
trusting an upstream resolver.
good
- Your hardware, your rules, your logs (or none)
- Covers smart TVs and IoT junk that can't run blockers
- With Unbound upstream, fully independent recursive resolution
- AdGuard Home speaks DoH/DoT natively, both directions
mind the
- You're now a sysadmin: updates, uptime, and "the internet is broken" complaints are yours
- Only protects you at home unless you route back via WireGuard
- Needs an always-on device (~โฌ40 Pi or an existing server)

ControlD
the customization pick
๐จ๐ฆ canadaencrypted dnscustomizablefree tier
ControlD is the dial-in-everything option: per-device profiles, toggleable
block-list categories (ads, malware, social, gambling, and dozens more),
custom rules per domain, and analytics, all from one dashboard. It's
more granular than NextDNS in the controls it exposes, at
the cost of a steeper setup curve. Pick it if you want to tune exactly
what's blocked on exactly which device, not if you want to set it once and
forget it.
good
- Very granular per-device and per-profile block-list control
- Supports DoH, DoT, and DNS-over-QUIC
- Free tier is genuinely usable, not just a trial
- Custom routing rules (split DNS, redirects) beyond simple blocking
mind the
- The dashboard's depth is a learning curve, not a five-minute setup
- Canada is a Five Eyes jurisdiction, if that's in your model
- Easy to over-configure and spend an evening tuning rules

ReThinkDNS
the all-in-one pick
๐ฎ๐ณ indiaencrypted dnspartially open sourceno accountfree tier
ReThinkDNS is a free encrypted resolver (DoH and DoT) with over 190
selectable blocklists, run by Celzero out of India. Its Android app pairs
the resolver with a local firewall that tracks and blocks
connections per app, and neither needs a signup. A WireGuard VPN
add-on (RPN, from $1.75/month) rounds out a bundle nothing else in this
category offers in one free app. The open app and resolver code are the
main reassurance on offer; no independent audit exists, and Indian
jurisdiction brings data-retention rules worth weighing.
good
- Free core with no signup: encrypted DNS plus a per-app firewall and connection tracker
- DNS, firewall, and WireGuard VPN in one Android app is a rare bundle
- App and resolver code are both open source
mind the
- No independent audit; the no-logging policy is the company's word alone
- India's CERT-In rules require five-year identity retention from VPN-classified providers; the company hasn't publicly addressed this
- The app (firewall included) is Android-only; other platforms only get the resolver endpoints
- RPN is a paid add-on, separate from the free core

Cloudflare DNS
the audited pick
๐บ๐ธ usaencrypted dnsauditedpartially open sourcefree
Cloudflare DNS (1.1.1.1) is the big mainstream free resolver,
and what sets it apart here is verification: KPMG has
independently audited Cloudflare's data-handling claims, most
recently in April 2026, so the 25-hour retention figure is a checked fact
instead of a promise. Few free resolvers can show anything close. Just
know what you're getting: it's a plain, fast resolver that filters
nothing, run by a giant US company, and the trust rests on that audit,
not on open code.
good
- KPMG-verified logging claims: 25-hour retention, full IPs never written to disk
- Free with no tiers; DoH, DoT, DNS-over-Tor, and Oblivious DoH all supported
- Never blocked or filtered content despite legal requests, per its transparency reports
- Only one third party (APNIC) receives query data, anonymized and IP-free
mind the
- The base resolver doesn't filter ads or trackers at all
- The resolver's backend is closed source, and the KPMG report is request-only
- US jurisdiction, if that's in your threat model
- A 62-minute global outage in July 2025, disclosed in a detailed public post-mortem
at a glance
all support encrypted transport (self-hosted via upstream configuration; mullvad is encrypted-only).
worth knowing
Set it at the router if you can. One change covers every device,
including the ones you can't configure. Phones and laptops that leave the house
should also get the resolver set per-device (iOS/Android both support DoT/DoH
profiles natively).
Match DNS to your VPN. A VPN tunnel
carries its own DNS. On Mullvad, use Mullvad DNS; on Proton, NetShield.
Keeping resolution consistent with the tunnel's infrastructure preserves a
uniform fingerprint; fighting your VPN to use a third party does the opposite.
Expect some breakage, know the fix. A login page that won't load
or an email link that dies is usually one allowlist entry away. Filtering DNS
without knowing how to whitelist is how people end up back on the ISP default.
Your resolver sees a lot: choose like it matters. Domain
history is a complete map of your interests. "Free" resolvers from ad companies
are free for a reason; everything recommended here has a published, plausible
reason to exist, and self-hosting removes the question entirely.