Just a quick note for the unsuspecting: I run two local DNSes, one recursive and one forwarding. The forwarding one uses few services, like 1.1.1.1, 8.8.8.8, 9.9.9.9, etc. One day I noticed inconsistent responses and started investigating. Turns out that by default 9.9.9.9 have "protection" and for your safety will lie and return NXDOMAIN or something else, for some dangerous domains, taking into account their defini…
Instead of CloudFlare's 1.1.1.1 I like CloudFlare's 1.1.1.3: it filters known porn and known malware sites. By now I expect many sites to be filtered out: too much crap out there. Then I also run my own DNS (unbound) and after seeing a warning from one of my banks about a phishing site where one letter differed in the domain name from the real bank's site, I went ballistic: I did generate hundreds of thousands (maybe…
Re: An open DNS recursive service for free security and high privacy
#41To be thorough, you should check your domain names for any characters that can be changed by a single bit flip. It probably will not look right as far as spelling, but the idea is that eventually something like a cosmic ray will pass through a memory chip and flip that single bit for a connection, and they get redirected to another site set up to handle the request. It's a thing. It takes patience, but but does work. People were doing this to fbcdn.com and other large targets years back.