Use your ISPs official DNS so that you get the shortest path possible from the ISPs handoff location to the CDN (and overseas trunks), not a generic DNS that doesn’t know about your ISPs layout. ISP: 1ms to Cloudflare Cloudflare: 10ms to Cloudflare Thank you for your attention to this matter. Edit: will clarify, this advice applies to countries with good privacy laws and no national surveillance i.e. not the USA
Choosing a Public DNS Resolver
91–100 of 143 posts
Re: Choosing a Public DNS Resolver
#92It would be nice if a site like this could offer a basic speed comparison test to your local network. Imagine seeing response times at P90 for a series of random lookups and comparing the median response times.
Re: Choosing a Public DNS Resolver
#93If it is this hard to choose a resolver, imagine how hard it is to choose a web browser, which is a choice that actually matters.
The nearest resolver is
$ sudo apt-get install unbound
and now your own host is your resolver. The complexity of this is roughly a millionth of a percent of that of your web browser.Re: Choosing a Public DNS Resolver
#94Why cloudflare is listed under maximum privacy?
Re: Choosing a Public DNS Resolver
#95Earlier quoted context omitted.
Be cautious with Quad9; their main address (9.9.9.9) has a "malware" blacklist that has misfired several times already: twice for a private torrent tracker, once for gist.github.com, issue was resolved within minutes to hours. They have a non-filtered address (9.9.9.10), but it doesn't do DNSSEC verification. IMO they're too unreliable to be worth the hassle.
Quad9 employs DNSSEC on all endpoints now. https://quad9.net/news/blog/quad9-enables-dnssec-on-all-serv...
[0]: https://quad9.net/service/service-addresses-and-features/
Re: Choosing a Public DNS Resolver
#96Use your ISPs official DNS so that you get the shortest path possible from the ISPs handoff location to the CDN (and overseas trunks), not a generic DNS that doesn’t know about your ISPs layout. ISP: 1ms to Cloudflare Cloudflare: 10ms to Cloudflare Thank you for your attention to this matter. Edit: will clarify, this advice applies to countries with good privacy laws and no national surveillance i.e. not the USA
That’s no good if you want uncensored DNS.
Re: Choosing a Public DNS Resolver
#97ok now add benchmarking a-la https://www.grc.com/dns/benchmark.htm to rank them on performance for your specific region etc. note on privacy: if you are using port 53 you are cooked so make sure you are using dns-over-tls or dns-over-https.
Re: Choosing a Public DNS Resolver
#98Use your ISPs official DNS so that you get the shortest path possible from the ISPs handoff location to the CDN (and overseas trunks), not a generic DNS that doesn’t know about your ISPs layout. ISP: 1ms to Cloudflare Cloudflare: 10ms to Cloudflare Thank you for your attention to this matter. Edit: will clarify, this advice applies to countries with good privacy laws and no national surveillance i.e. not the USA
Re: Choosing a Public DNS Resolver
#99Use your ISPs official DNS so that you get the shortest path possible from the ISPs handoff location to the CDN (and overseas trunks), not a generic DNS that doesn’t know about your ISPs layout. ISP: 1ms to Cloudflare Cloudflare: 10ms to Cloudflare Thank you for your attention to this matter. Edit: will clarify, this advice applies to countries with good privacy laws and no national surveillance i.e. not the USA
Changing your DNS does basically bupkis for privacy, since they can still read your DNS queries and SNIs.
Re: Choosing a Public DNS Resolver
#100Use your ISPs official DNS so that you get the shortest path possible from the ISPs handoff location to the CDN (and overseas trunks), not a generic DNS that doesn’t know about your ISPs layout. ISP: 1ms to Cloudflare Cloudflare: 10ms to Cloudflare Thank you for your attention to this matter. Edit: will clarify, this advice applies to countries with good privacy laws and no national surveillance i.e. not the USA
Changing your DNS does basically bupkis for privacy, since they can still read your DNS queries and SNIs.