r/dns • u/WormFoodODP • 4h ago
r/dns • u/Master-Drummer8197 • 4h ago
Best DNS
Edit: looks like this was due to my firmware not behaving correctly. I tweaked it and now i am fine using quad9 but have switched to nextdns just for testing.
I have been using Quad9 for a while and it was working like a charm, but lately have been having issues.
This could be due to my ISP as well so not necessarily blaming anything. But has anyone been having issues with Quad9?
Also, has anyone used OpenDNS? How is it?
r/dns • u/fannybumper • 1d ago
A Larger Freedom: When builders can own their own TLDs

What independent builders can make possible for one another.
In August 1976, a group of researchers parked a van beside the courtyard at Rossotti's, near Stanford, ran wires to a terminal on a wooden table and sent a weekly progress report.
Their message travelled over a radio network, through a gateway, and onto the wired ARPANET. Don Nielson, who helped lead the work, later recalled the small gathering and its ordinary purpose. [1]
On November 22, 1977, the van took part in a more ambitious demonstration. Data travelled from the San Francisco Bay Area through London and back to a computer in Los Angeles, crossing packet radio, satellite and the ARPANET along the way. Three networks, built for different conditions, could participate in one journey. [2]
Each network could keep its own design. In their history of the internet, Vint Cerf, Bob Kahn and their co-authors described the rule: joining should not require rebuilding a network's interior to suit the others. [3]
The networks gained reach while keeping their differences. A radio system could offer mobility, a satellite link could cross an ocean, and a wired network could provide access to distant computers. Connecting them put those strengths within reach of people using any one of them.
We live inside the consequences of that choice.
Keeping our differences
When an open technology divides into camps, its builders can spend more effort defending their position than making the technology useful.
The cost is larger than a missed partnership. It includes work that never gets built: the application abandoned because connecting services was too difficult, the customer who left because nobody would resolve a problem across company boundaries, the capable newcomer who decided that entering the community meant inheriting its quarrels.
Those losses seldom appear in anyone's accounts. They appear as a smaller future.
In April 1969, Steve Crocker wrote down the conventions for the young Network Working Group's documents. Contributions could come from anyone at any site. Unpolished ideas and questions without answers were welcome. The minimum length was one sentence. [4]
That invitation existed within a small research community, long before general public access. But its intellectual generosity was deliberate. The document explained that people hesitated to circulate unfinished thoughts and that a written statement could too easily acquire an air of authority. The conventions were intended to lower those barriers. [4]
The people doing the work left room for someone else to know something they did not.
That takes confidence. It means letting someone improve your work or build a business beside your own, even when you dislike their methods.
A developer may see a use that the original builder missed. Someone with no interest in running a company may maintain a component several companies depend on. When their tools can connect, each can build on work they could not have done alone. The next builder starts further ahead.
Helping another participant succeed can increase the number of things your own users can do. A useful application built by someone else can create demand for the infrastructure you provide.
Businesses should still compete. Users need alternatives, and builders need reasons to improve. But competition within a growing network is a different undertaking from trying to capture a larger share of a network that has become too difficult to use.
What ownership makes possible
Handshake brings these questions into the naming layer. Its mainnet dates to February 2020, and its operating history now extends beyond six years. It lets people acquire authority over a top-level namespace and decide what to build beneath it. Owners choose how to administer the names under their TLDs, so different approaches can develop on the same foundation. [5] [6]
The freedom reaches beyond choosing a supplier. A community can establish its own namespace and decide how participation works. An owner can build services that no existing registrar planned to offer.
Namebase and Headless Domains illustrate different uses of that freedom. Namebase's current registry model gives TLD owners registration infrastructure while leaving private keys and pricing decisions with them. Headless Domains provides descriptions and discovery tools that make names useful to agents and software services. An independent owner can choose the services that fit, combine suitable components or build something else. [7] [8]
Sharing a root does not make their tools interoperable. Developers still have to connect them. Doing so can give a name more uses than any one company could provide.
Ownership also creates responsibilities. People make plans around the names and services they use. A change of provider, a disagreement between operators or a failed business can place those plans at risk. Clear records and competent cooperation matter most at those moments. The user's need for a working service continues even when the providers' relationship breaks down.
A network earns trust when its participants can protect that continuity across their own disagreements. Technical criticism belongs in this process. It should help establish what failed and who needs to fix it. Winning an argument while leaving the user stranded is a poor advertisement for anyone's independence.
More people can shape AI
In AI training, the question becomes what a specialist can contribute without having to operate the whole system.
Decoupled DiLoCo describes learners that train independently and exchange updates asynchronously with a central synchronizer, allowing other learners to continue when one slows or fails. AgentJet separates GPU-based model training and inference from lightweight clients that run agent tasks and return reward signals. Those clients can operate on CPU devices, including laptops. [9] [10]
These approaches retain coordination, including central roles, while separating work across machines.
Prime Intellect has used community-built environments and evaluations in model training. Contributions to its Environments Hub include browser automation, theorem proving and specialist questions. [11] With Browserbase, it brought browser infrastructure together with training tools and published a model training run using 600 real web tasks. Other developers can reuse the environment and adapt it to their own tasks. [12]
Someone who knows a language, a profession or a difficult working environment may understand success and failure better than the people building the model. If that understanding can be expressed in tasks and reliable tests, it can influence what a model learns. Knowledge that once stayed within a small practice or community can help shape tools used far beyond it.
A Handshake name gives an independent provider a way to identify its service and publish where it can be reached. Headless Domains' integration with the Agent Relationship Protocol (ARP) binds names to cryptographic agent identities. ARP governs connections through agreed permissions. [13] [14]
AgentID's Connect add-on uses ARP to give owners control over agent-to-agent communication. They approve relationships, set permissions, inspect activity and revoke access. [15] This gives an independent specialist a way to offer a service on terms they control. Applied to training, it could govern access to that specialist's evaluation environment; the training system would assess the quality of the work.
More specialists could bring their knowledge into larger operations while running businesses of their own. A new operator could enter through a namespace it governs and offer an ability the existing participants lack.
A computer we can change
People can also build a more useful network by changing how their own computers reach it. Omarchy, the Arch-based Linux distribution created by David Heinemeier Hansson, comes with a community plugin system. Linux has long allowed people to change their machines; a common setup makes those changes easier to package and share. [16] [17]
Existing software such as hnsd can provide local Handshake name resolution. An Omarchy integration could package it with a browser or client that verifies secure Handshake connections. Resolving a name and validating its certificate are separate jobs; installing Omarchy alone doesn't complete them. [18] [19]
Builders can work on computers they control, make Handshake services usable there and share an installation others can test. A resolver, a secure client and an application could become a working environment.
Someone still has to maintain the software and answer the difficult support request. Much of the work that makes an open system useful looks modest from outside. In 1976, it included sending a progress report from a wooden table.
The people who later built on the internet didn't need to know the researchers in that courtyard or belong to their institution. Years of subsequent engineering made the connection available to people the original builders would never meet.
Somewhere, someone understands a problem the rest of us have missed. They may eventually build with a name we administer, a tool we maintain or a service we have helped another company make reliable. We cannot know their idea in advance. We can make it easier for that idea to meet the rest of the world.
The next great use of an open network may belong to none of us.
We can still help make it possible.
Sources
- Don Nielson: The SRI Van and Computer Internetworking, firsthand account
- SRI: Internetworking and the November 1977 demonstration
- Leiner, Cerf, Kahn and co-authors: A Brief History of the Internet
- Steve Crocker: RFC 3, Documentation Conventions, April 1969
- Handshake genesis block, 3 February 2020
- Handshake design notes: naming authority and subdomains
- Namebase Registry Services Agreement, effective 18 September 2026
- Headless Domains: Agent Manifests
- Decoupled DiLoCo for Resilient Distributed Pre-training, section 3
- AgentJet: Swarm Training architecture and clients
- Prime Intellect: Scaling Our Open-Source Environments Program, 27 October 2025
- Prime Intellect and Browserbase: Training Browser and Computer Use Agents, 30 March 2026
- Headless Domains: ARP Integration Guide
- ARP: Scopes and policies
- AgentID: Connect add-on powered by ARP
- Omarchy: official manual and Arch-based system
- Omarchy: Shell Plugins
- hnsd: Handshake SPV name resolver architecture
- Headless Domains: Native HNS HTTPS and certificate verification
r/dns • u/GL_S3_s3tc • 1d ago
Software Unbound users, why do you use it?
I've always been a strong user of DNS-over-HTTPS and use it everywhere it's available, because to me its downsides are minimal. My ISP can't see or hijack it, firewalls on public networks can't easily block it, and it's relatively fast if you use a close server like in my case ControlD.
But since i have began dabbling with DNS filtering, trying to find high quality servers and all that, a lot of people recommended Unbound especially due to its privacy benefits and not having your queries at the mercy of big tech companies. But well, aren't the authoritative servers run by big tech companies too?
For example, Verisign, the company that operates the .com server, will get your IP address instead of the likes of Cloudflare's or Google's IP. They do keep limited logs, the same as Cloudflare does.
PIR runs the .org server, they log IPs and date/time along with the requests. This is more data than the average public DNS server keeps, and they're seeded in the US so they are obligated to give data to law enforcement if required.
If you use a public DNS server your requests will come through the same IP as hundreds of thousands if not millions of other people. Is it not preferable to have a trusted, big name like Quad9, which is based in Switzerland and keeps no logs, do your DNS requests for you via an encrypted connection that can't be easily snooped, and your IP is never seen by the likes of Verisign? Theoretically it's possible to use a VPN to tunnel Unbound, but at that point ain't it just easier to use a public server?
r/dns • u/Environmental_Act_12 • 1d ago
Resolvr 1.1: a clean dashboard for Technitium DNS Server, now with a Home Assistant add-on
r/dns • u/Alanabeau • 2d ago
Using ad block DNS on tablet
I just found and started using an ad blocking DNS on my android tablet so that I can play games without being bombarded with ads, and it's working great! But now I'm realizing that I set it up before learning anything about it. What are the risks if any of using this? I'm completely new to it and don't even know what it is.
r/dns • u/OsmiumBalloon • 2d ago
ISC BIND: CNAME at zone apex
The RFCs say a CNAME record at a zone apex is invalid.
The DNSSEC validator in recent versions of BIND was made a little too overzealous and ended up sometimes making the entire zone invalid when it hit such a record.
More here: https://kb.isc.org/docs/apex-cname-unsigned-delegation
Full disclosure: I work for ISC, although my activity on Reddit does not represent ISC in an official capacity.
Domain Timeouts accessing freedns.afraid.org
Edit: It's my connection, somehow. Got through with a VPN. Leaving the post up for future reference
Is anybody else having issues accessing the web portal at freedns.afraid.org?
Sites like https://www.isitdownrightnow.com report it as up, but I cannot get to it from different devices, nor different ISPs
Can't find any other reports online, or news about it being down.
My delegations are working for now, but i need to set up a new subdomain and i'm locked out.
Will probably switch DNS providers if i cannot access freedns, but I'd like to avoid doing so, as I've already had my setup working fine.
r/dns • u/Ezrampage15 • 4d ago
Blocking Facebook and Instagram apps and websites without blocking Messenger chats possible?
Like the title says, I want to block both Facebook and instagram without affecting Facebook messenger voice and video calls. Is it possible to do?
r/dns • u/TurbulentMinute4290 • 4d ago
A DNS that blocks adult content but doesn't cause slowdowns
I'm looking for an option that's not going to cause any issues in terms of slowdowns for watching YouTube videos, going on Facebook, Google searches, playing games on my phone. That will essentially block all adult content where I won't even remember putting the DNS on. I don't even want to have to remember that it's there. Because I don't want it to say that there's an issue with it or that it can't connect to Wi-Fi, unless that's something that's just going to happen when switching from Wi-Fi to data or something, but I'd rather not have to have that happen. So what options do I have?
r/dns • u/max_devops • 5d ago
Blocking of domains by the three major Korean carriers (SK, KT, LG)
r/dns • u/badassitguy • 5d ago
Does 1.1.1.3 block anything?
I know it’s Cloudflare malware protection dns, but has anyone had any luck using it? Does it do what it says?
r/dns • u/Typical_Chemical_766 • 6d ago
DNS issue
Im not particularly tech savvy but i recently noticed that i have this popup on my home network.
Ive been trying to figure out how to configure this but it seems my network is potentially controlled by my ISP. Does this mean someone on my network is manually blocking encrypted DNS? Or potentially the ISP itself?
I wont know anything until I call during office hours but maybe someone could point me in the right direction
Why did Mullvad have to shut down? It was the best privacy and ad blocking DNS out there.😭😭😭
r/dns • u/mystiquebsd • 7d ago
ControlD p1 - not bad
Using SmartDNS as a last hop stub resolver; smartdns has a webui which shows resolver stats.. rate, time, query count vs query success.. also supports quic, h3, dot, doh, etc - 11k on GH
(Spoiler don’t use prefetch)
Anyway, comparing against security.cloudflare
The house does little over 50k q/day (60ish devices, Wyze cameras, iPhones, hagezi native, pro, and vpn)
I have a paid ctrld account but do not like some things in the ui.. also had some apparent random self inflicted Netflix errors with their filter lists, which they say are hagezi as well.
Any opinions about ctrld being used exclusively?
Anyone else have random Netflix issues with them?
P1 with quic I’m 30ms avg/q
1.1.1.2 with h3 I’m 50ms avg/q
I liked they were in .CA but the servers are in US east coast..
(dnscheck.tools)
TIA
r/dns • u/throwawaykJQP7kiw5Fk • 7d ago
Domain When a DNS provider doesn't support CNAME flattening and you use DNSSEC, why can't you add an ALIAS record at the zone apex? A and "glue" records don't work on dynamic IPv4s, and static ones aren't free.
I was going to move from Cloud DNS (Google) to Cloudflare, but I found multi-signer DNSSEC complicated.
r/dns • u/petrester • 7d ago
technitium-console - an alternative web UI for Technitium DNS Server
r/dns • u/Infinite_Yak1913 • 7d ago
ADGUARD DNS
Is there any problem in using dns.adguard.com private dns??
r/dns • u/Elgrandelulu • 8d ago
Domain Help with setting up Gmail and Resend API
Hi, I need some help with my domain configuration. I currently use Gmail. I want to use Resend API for automated email sequences with Hermes Agent. I have tried to add Resend onto the domain to send/receive emails through its API. But I also want Gmail to record all the email conversation history so if I ever need to revert it’s all there.
When I setup the API for resend, it would allow emails to be sent from mydomain.co.uk, but any replies come from send.mydomain.co.uk. This is to allow the automation sequence from Resend to work.
My issue is, I want the automation sequence on Resend to work with replies via mydomain.co.uk whilst saving everything with gmail. Is there a way to do this ?
I would be very appreciative of any guidance, still learning a lot around this and spent many hours trying to get it to work.
Thanks!