3 ms·
I am a djbdns user. I also use nsd and unbound. I do not use "upstream" third party DNS, such as 9.9.9.9. Surprised to hear that anyone still uses MaraDNS.
by x3blah 6y ago
I am a djbdns user. I also use nsd and unbound. I do not use "upstream" third party DNS, such as 9.9.9.9. Surprised to hear that anyone still uses MaraDNS.
What I am curious about are these massive blocklists. Does anyone actually read through them. Does it make sense to block 60,000 hosts when only, say 100 or even 1000, ever stand a chance of being accessed by a user's computer -- due to the user's particular usage habits.
- GekkePrutser 6y agoWell, why not? 60.000 isn't a huge amount for a modern computer. If they're known to contain ads/trackers you want to block, then why not include them? It might make sense though to do a periodic run through them to see if they still exist.
- deleted 6y ago[deleted]
- strenholme 6y agoIn my experience, using an upstream server is faster and more reliable than having a DNS server on a home network recursively solve the name. That said, MaraDNS/Deadwood does have full recursion support, which resolves correctly over 99.9% of domains, but there is that .1% or less of misconfigured domains which only resolve when a recursive DNS server is bug-for-bug identical to BIND. NSD/Unbound are good DNS servers, as is the newer Knot DNS suite. djbdns was really good in the early 2000s, but hasn’t been updated since 2001 and its age is starting to show. Yes, there are third party patches, but forks of the djbdns codebase have this annoying way of getting abandoned after a couple of years. I’ll probably end up doing basic maintenance of a djbdns fork just so there’s something getting minimal maintenance available to download.
- x3blah 6y agoI do not do recursive lookups at home. I store the DNS data I need in custom zone files. Once I have the data stored, this is faster than recursive lookups, especially with tinydns listening on localhost. djbdns works great for me year after year. I would never use MaraDNS.