Choosing a Public DNS Resolver
evilbit.de
Choosing a Public DNS Resolver
1–10 of 143 posts
Re: Choosing a Public DNS Resolver
#2Re: Choosing a Public DNS Resolver
#3Re: Choosing a Public DNS Resolver
#4Re: Choosing a Public DNS Resolver
#5I pre-cache all the domains I use hourly via cron. My ISP is not going to dork with my DNS requests and their employees are bigger deviants than I. If I ever started browsing the web from a phone I would just set up my own public DoH server. It only takes a few minutes and gives me my own query logs for debugging weird issues.
[1] - https://tls-ech.dev/
Re: Choosing a Public DNS Resolver
#6Re: Choosing a Public DNS Resolver
#7Imagine seeing response times at P90 for a series of random lookups and comparing the median response times.
Re: Choosing a Public DNS Resolver
#8I use Unbound locally as a DoH server. The Alpine Linux Unbound package is compiled with libnghttp2, required for the built in DoH listener . That's more than enough to enable ECH [1]. I pre-cache all the domains I use hourly via cron. My ISP is not going to dork with my DNS requests and their employees are bigger deviants than I. If I ever started browsing the web from a phone I would just set up my own public DoH s…
Re: Choosing a Public DNS Resolver
#9I use Unbound locally as a DoH server. The Alpine Linux Unbound package is compiled with libnghttp2, required for the built in DoH listener . That's more than enough to enable ECH [1]. I pre-cache all the domains I use hourly via cron. My ISP is not going to dork with my DNS requests and their employees are bigger deviants than I. If I ever started browsing the web from a phone I would just set up my own public DoH s…
How does this look? Shell script querying a list of hostnames? What qualifies as a domain you use?
Re: Choosing a Public DNS Resolver
#10I use Unbound locally as a DoH server. The Alpine Linux Unbound package is compiled with libnghttp2, required for the built in DoH listener . That's more than enough to enable ECH [1]. I pre-cache all the domains I use hourly via cron. My ISP is not going to dork with my DNS requests and their employees are bigger deviants than I. If I ever started browsing the web from a phone I would just set up my own public DoH s…
Why pre-cache? For speed... what is it, 30-50ms at most? If the authoritative server's TTL is <60minutes, do you force it to 3600? Do you audit all the connections that occur for every website you visit, collect all the domains hosting assets, and pre-cache those as well, or is the main site's domain the only critical one because that affects perceived latency the most?