6 ms·
I agree - there are not very many internet-scale (for lack of a better term), completely free and fast DNS servers who have an IP address that's easy to remembe
by manacit 9y ago
I agree - there are not very many internet-scale (for lack of a better term), completely free and fast DNS servers who have an IP address that's easy to remember.
Is that specific? sure, but I'll tell you when I go to set a new system up I'm going to type 8.8.8.8 because it's what comes to my mind.
- andypants 9y agoThere is quad9 - 9.9.9.9 :)
- bringtheaction 9y agoDoes quad9 offer encrypted DNS?
- alwillis 9y agoDoes quad9 offer encrypted DNS? From their FAQ: Does Quad9 support DNS over TLS? We do support DNS over TLS on port 853 (the standard) using an auth name of dns.quad9.net.
- sm64 9y agoHighly recommend Quad9. Their privacy policy is absolutely no identifying data logging, period. They're also the few providers offering DNS over TLS. Google, on the other hand, keeps identifying logs for 24-48 hours.
- corobo 9y agoJust watch out for them if you're not in the US - any DNS-based CDNs will send you to an American node rather than your closest, it could slow things down a little dig @9.9.9.9 icnerd-1e5f.kxcdn.com icnerd-1e5f.kxcdn.com. 3600 IN CNAME s-us-ca00.kvcdn.com. s-us-ca00.kvcdn.com. 55 IN CNAME p-ussj00.kxcdn.com. p-ussj00.kxcdn.com. 55 IN A 209.58.129.70 dig @8.8.8.8 icnerd-1e5f.kxcdn.com icnerd-1e5f.kxcdn.com. 21599 IN CNAME p-uklo00.kxcdn.com. p-uklo00.kxcdn.com. 59 IN A 217.146.91.55
- ctlee 9y ago9.9.9.11 is a CDN-friendly IP in Quad9. https://kznnog.co.za/wp-content/uploads/2017/11/Quad9-Intro-detailed.pdf https://kznnog.co.za/wp-content/uploads/2017/11/Quad9-Intro-...
- mulmen 9y agoFor "easy to remember" my preference is to use Level 3 because I don't (directly) use them for any other service. 4.2.2.1 4.2.2.2 For as often as I manually configure DNS (I use DHCP) it's not onerous to look up the IPs of whatever DNS is preferable for your purpose. edit: Depending on who you are this may redirect you to a search portal. Probably best to find an alternate DNS provider.
- duskwuff 9y agoLevel 3's resolvers will return fake NXDOMAIN responses that redirect to searchguide.level3.com.
- michaelmior 9y agoI thought NXDOMAIN responses indicated that the domain doesn't exist and there wasn't a way to actually direct the user anywhere. Your resolver could of course lie and return an IP instead of NXDOMAIN however. Perhaps I'm wrong.
- duskwuff 9y agoThey take the "lie" route: # dig +short this-should-be-a-nxdomain.com @4.2.2.2 198.105.254.11 104.239.213.7 They do it a little more cleanly than some other attempts I've seen, but there's still flaws in their approach. In particular, they will generate redirects for NXDOMAIN responses to certain records under domains that do exist: # dig +short why-does-this-resolve.example.com @4.2.2.2 198.105.254.11 104.239.213.7 Specifically, they'll generate a redirect for any record that starts with the letter "w". (No, I'm not kidding. Try it.) Other records generate a real NXDOMAIN.
- michaelmior 9y agoRight, what I meant is that you can't return an NXDOMAIN response that "redirects" the domain. (Of course this isn't really a redirect per-se.)
- 9y ago
- gruez 9y agoMost ISPs provide their own DNS server via dhcp, why not use that?
- cm2187 9y agoFor servers you typically have no DHCP. Also ISP often have annoying behaviours like redirecting you to their own websites for failed lookups. And my ISP doesn’t allow local non routable IPs (192.168.1.x) in DNS responses while google does.
- gruez 9y ago>And my ISP doesn’t allow local non routable IPs (192.168.1.x) in DNS responses isn't that the recommended behavior? otherwise you can do a bunch nasty stuff like rebinding attacks. https://www.ietf.org/proceedings/52/I-D/draft-ietf-dnsop-dontpublish-unreachable-01.txt https://www.ietf.org/proceedings/52/I-D/draft-ietf-dnsop-don...
- thisacctforreal 9y agoIt's necessary for adding SSL to an intranet service.
- gsich 9y agoBecause most of them suck (Censorship, NXDOMAIN fuckups). Or are not reachable outside the ISP network.
- manacit 9y agoMy ISP (Spectrum / Time Warner) will not return a proper NXDOMAIN, and will instead send you to an ad-filled "search" page. They're also slower than Google DNS somehow, and generally not much more than an opportunity for my ISP to get more information and ad revenue from me. At least I'm not paying Google to do the same, and I can trust that they'll send the proper results.
- majewsky 9y agoThere is a public DNS server at 141.1.1.1 (which I used for connection testing before there was 8.8.8.8 etc.), but I actually do not know by whom it is operated. Whois says Vodafone.
- Shelnutt2 9y ago141.1.1.1 is owned by vodaphone de now. https://dnslytics.com/ip/141.1.1.1 https://dnslytics.com/ip/141.1.1.1
- remir 9y agoWell, there's 9.9.9.9 (Quad9.net) which is global and secure, too.