4 ms·
Is there an easy explanation anywhere of how I can achieve the most secure DNS configuration that is reasonably simple to set up today? I.e. what's the best I
by 2bitencryption 7y ago
Is there an easy explanation anywhere of how I can achieve the most secure DNS configuration that is reasonably simple to set up today?
I.e. what's the best I can do, short of hosting my own DNS?
- josteink 7y agoHosting your own DNS is easy. I’m pretty sure there are pre-made images for the raspberry pi just for this purpose.
- babypuncher 7y agoI have a few VMs that run all my networking services. One of them runs cloudflared and Pihole. Cloudflared is a DNS server that routs all DNS queries to 1.1.1.1 using DoH. I have Pihole configured to use cloudflared as its upstream DNS. So in addition to the Pihole's ad/tracker blocking, all DNS requests leaving my network are done over DoH regardless if clients actually support it.
- basch 7y agoIf taking safest in the most literal sense, and you trust PCH/IBM, then Quad9 is a pretty good choice for most people. Unlike normal DNS, Quad9 purposely does not resolve threatening results. If you view "safest" more to mean "prevents the spread of malware, keeping everyone safer" than "gives me absolute privacy I can audit" then it's hard to beat. They do log data at the city/metropolitan level for threat analysis. It's one of the few services that supports DoH, and Chrome already automatically upgrades requests when it detects you using Quad9. https://www.quad9.net/policy/ https://www.quad9.net/policy/