9 ms·
Show HN: Which DNS servers are you pointing to?
- Fileformat 6y agoI kept running into DNS issues, and needed to triple-check that I was pointing to the right DNS servers, so I made this utility website that does exactly that: which-dns [1] This isn't a new idea ([2]), but mine supports https (hat tip to Matt Holt's certmagic [3]), is ad-free, and the source is available [4]. Let me know what you think! [1] https://which.nameserve.rs https://which.nameserve.rs [2] http://www.whatsmydnsserver.com/ http://www.whatsmydnsserver.com/ [3] https://github.com/caddyserver/certmagic https://github.com/caddyserver/certmagic [4] AGPL. It is my first foray into golang. https://github.com/redirect2me/which-dns https://github.com/redirect2me/which-dns
- kortex 6y agoI find this really useful! I seem to frequently run into dns weirdness. Does it work internally e.g. diagnosing dns queries on a local net?
- Fileformat 6y agoIt only sees the "last hop" of recursive DNS resolution [1]. If you have internal DNS servers, you would need to run a copy of which-dns internally, and your internal DNS servers would need have the which-dns entries added. If you want to see if a local workstation is pointing to a different public/external DNS server than the rest of your network, it should work. [1] https://www.cloudflare.com/learning/dns/what-is-recursive-dns/ https://www.cloudflare.com/learning/dns/what-is-recursive-dn...
- sleavey 6y agoI just read the GitHub readme: > How does it work? You make a request to a hostname with a unique prefix. All hostnames resolve to the same IP, but the DNS server records which IP address the query came from. The webserver looks for this record and returns it. That's a smart way of detecting a user's DNS server - well done! Is there a way to "fail" the first request and try to force the user's secondary DNS to kick in so that it can be detected too?
- Fileformat 6y agoIt would be really nice to detect the user's secondary DNS. I'm not sure failing will do that, but it might reveal interesting things anyway. I'll add it to the to-do list.
- dgl 6y agoThe extended test on https://www.dnsleaktest.com/ https://www.dnsleaktest.com/ does that. There’s also various tests that reveal EDNS subnet leakage. It’s pretty easy to implement; somehow don’t respond to a request, but do respond to a second. (If you’re clever you can probably do it without server side state, e.g. encode a deadline in the custom hostname.)
- justsomedood 6y agoWow, this is such a useful tool and a clever way of finding out the DNS server. Great job!
- bt1a 6y agoAgreed, the unique site prefix is one of those 'aha' ideas (im sorry not good with words)
- teknologist 6y agoI often use dnsleaktest.com for this; it runs multiple rounds so you see all the ones you might be using.
- WarOnPrivacy 6y agoVery nice. I don't think I've used them before.
- WarOnPrivacy 6y agoI have a local DNS server that forwards over TLS (DoT) to Cloudflare & Quad9, round-robin. Page alternately returns WOODYNET @ rrdns.pch.net and CLOUDFLARENET. I like the pch.net info - it's something about Quad9 I didn't know.
- daneel_w 6y agoThis was a surprise to me as well. For anyone else reading this it means that Quad9, not your system, is relaying DNS traffic to WoodyNet.
- ilikepi 6y agoPCH provides the infrastructure for Quad9...so I don't think it makes sense to say that Quad9 is "relaying" DNS traffic to PCH/WoodyNet. There isn't some organizational boundary that's being crossed.
- bwoodcock 6y agoHi. I'm Bill Woodcock, the eponymous "woody" of "woodynet." And executive director of PCH, and chairman of Quad9's board. They are three separate corporations, which exist for different reasons, and under different tax regulations (PCH and Quad9 are public-benefit not-for-profits, whereas WoodyNet exists to pay taxes on taxable transactions and keep the non-profits' books clean), but they're very closely related. In this case, you're seeing WoodyNet IPs and IN-ADDRs because WoodyNet is giving transit to the Quad9 anycast instance you're talking to. I'm happy to answer any questions you may have about how all this works. I'd also note that round-robining between two different organizations with radically different privacy practices and security services... um... might not make the most sense? Depending what your goal is, of course. Again, happy to talk about any of this, just let me know if I (or any of the Quad9 or PCH folks) can be of help. -Bill
- apple4ever 6y agoThanks Bill for the explanation. I appreciate the detail about why WoodyNet/PCH shows up.
- bloopernova 6y agoThis is great, thank you for creating it and sharing it. I'll be sharing this with all my colleagues!
- jelv 6y agoYou can check your best available dns server via this easy tool https://www.grc.com/dns/benchmark.htm https://www.grc.com/dns/benchmark.htm (win and wine)
- Fileformat 6y agoThanks, that's a really interesting tool.
- DavideNL 6y agoFYI, there's also: https://github.com/google/namebench https://github.com/google/namebench
- CircoDesktop 6y agoGreat tool !
- compsciphd 6y agoI'm using 8.8.8.8 and its coming up as cloudflarenet not whatever google should presumably be?
- treis 6y agoMe too. Can someone explain why Cloudflare shows up when (as far as I know) I don't use Cloudflare.
- _-___________-_ 6y agoYour browser is not using the system resolver, but is probably using DoH instead.
- dheera 6y agoGosh, I feel old, how do I set DNS servers in Linux these days? I used to just edit /etc/resolv.conf and add 8.8.8.8 to it but now recent distros have "Do not edit." in resolv.conf and don't tell you what to actually edit. Why do they have to do this to us ... things used to be simple.
- teddyh 6y agoIt depends on whether you are using NetworkManager or systemd-resolved, or something else.
- Denvercoder9 6y agoYou can still edit /etc/resolv.conf. If it has a "Do not edit" comment in it, it's probably a symlink to some file that's dynamically managed (most likely to automatically use or fallback to the DNS server advertised on the network, as needed for e.g. captive portals). Just replace the symlink with a text file with your prefered DNS server in there.
- vetinari 6y agoBecause it is not adequate to use cases today. Today, you can set up DNS per interface and designate, which DNS accessible via which interface can resolve which zones. So your intranet.company.com can go through specific VPN connection and the rest via your default route, for example. You can't do that with simple /etc/resolv.conf.
- lucb1e 6y agoIf Mozilla silently enabled DOH-via-CloudFlare for you, it would show up here right? Because if yes, this would make it quite easy to find whether you have the right settings without having to find it somewhere in a configuration screen or trying to find out which users' throats Mozilla ended up deciding to force this down.
- Fileformat 6y agoSort of: it doesn't differentiate between DoH and normal resolution (it only does IPv4 TCP & UDP resolution). This means that it will return Cloudflare (i.e. ASN of CLOUDFLARENET), but probably the same Cloudflare as if you are using Cloudflare's public DNS servers. Tip: You can check a specific DNS server with dig and curl: UUID=$(uuidgen) dig ${UUID}.which.nameserve.rs @1.1.1.1 curl --silent https://which.nameserve.rs/debug.txt | grep ${UUID} and then do a ASN lookup on the IP address Note: the debug page is unofficial, and may change, so don't bake this into anything.
- Thorrez 6y agoThanks for this comment, I was quite confused why this site said Cloudflare when my OS is configured to use 8.8.8.8.
- Cantbekhan 6y agoNextdns.io and cloudflare externally. Pi-hole pointing to those internally. Preferably encrypted. Preferably with Firefox due to esni support.
- leokennis 6y agoVery satisfied NextDNS user here. Easy to set up, and it’s a surprise for me how much nicer ad and tracker blocking is over my entire network (all laptops, phones, smart TV etc.) than just using a blocker in my web browser.
- captn3m0 6y agoIn my case NextDNS shows up as Google, both here and on https://www.dnsleaktest.com/ https://www.dnsleaktest.com/ since they are using GCP.
- kamyarg 6y agoDid not know about nextdns, thank you. One question popped into my head is how do you trust nextdns? or are you doing something so that you do not need to trust it?
- anderspitman 6y agoI just use it to block ads.
- arminiusreturns 6y agoThis is really cool, especially because I can just 'wget -qO- $RANDOM.which.nameserve.rs/api.json?callback=myfunction' which means I can use this in scripts. (For example an added field to scripts that grab from ifconfig.co)
- Fileformat 6y agoThanks, I use it like this for some of my pages. But please, only light, non-commercial use! It is on the cheapest static IP that I could find with no failover or anything. It is really easy to run your own copy if you need it for a commercial project.
- arminiusreturns 6y agoDuly noted. It's ok, most of my scripts just pile up the cobwebs and never get used anyway, and they are all personal, not commercial. I would of course consider standing up my own for any real use. Good work! Now you have me thinking about the economics of api as a service... another rabbit hole.
- jwilk 6y agoNote that $RANDOM is just 15 bits of entropy. You should use something more random.
- Symbiote 6y ago$RANDOM$RANDOM$RANDOM$RANDOM$RANDOM should be fine :-)
- makeworld 6y agoI run my own DNS resolver at home, and it's coming up with my own public IP address, with my ISP as the name. Neat.
- afkqs 6y agoWhat are the best practices/choices today when choosing your DNS servers when it comes to privacy?
- surround 6y agoI recommend running your own DNS resolver, so that you don’t have to trust any 3rd party server with your DNS traffic. I run Unbound (a DNS resolver) alongside Pi-hole on a dedicated raspberry pi for my home network.
- javajosh 6y agoThis is a good solution. Another much lighter-weight solution is to simply add a static name/ip association in your local /etc/hosts file. It's a bit brittle, but honestly for a lot of websites its a lot less brittle than you think (and it's even more efficient than a Pi-hole). The biggest drawback is that you'll have another thing to trouble-shoot if something goes wrong. But that's true for any privacy-preserving DNS solution.
- ryankrage77 6y agopi-hole now allows custom DNS entries, which will then work for all devices on your network and not just the one you edited /etc/hosts on (useful for, e.g, phones & smart devices where DNS configuration can be very limited).
- chimen 6y agoDid one for my project that discovers more servers [1] Not an easy task I tell you that. [1] https://dnsadblock.com/dns-leak-test/ https://dnsadblock.com/dns-leak-test/
- fwr 6y agoNeat, this helped me realize I haven't switched away from my provider's default DNS when I moved in, which is something I usually do. How to choose a DNS server? I usually just go with 8.8.8.8/8.8.4.4, I used to always test this with Namebench (https://en.wikipedia.org/wiki/Namebench https://en.wikipedia.org/wiki/Namebench) and these always turned out as the fastest - but it looks like it hasn't been updated since 2010 - are there any better tools for this, or any considerations in general? I prefer performance over privacy here, I think privacy should be on a different layer.
- Fileformat 6y agoSomeone else in this thread suggested GRC's benchmark utility [1]. It sounds pretty comprehensive, but I haven't tried it yet. [1] https://www.grc.com/dns/benchmark.htm https://www.grc.com/dns/benchmark.htm
- dheerajvs 6y ago> I think privacy should be on a different layer. Can you elaborate which layer?
- fwr 6y agoClient devices, I think - filtering that happens transparently and without an easy way to disable is just asking for problems - I couldn't deal with having to log in to the DNS management console every time when a website notices that ads didn't load and therefore doesn't display content. I don't think we're at a point where privacy can be guaranteed by technology choices - it's all about behavior of end users (like avoiding websites which block content if ads don't load ;-) Is it possible these privacy/filtering DNS services like NextDNS come without a performance hit? Imagine setting it up and forgetting about it, and discovering later that all your DNS queries happened with a substantial lag - it's like realizing you've been driving with a hand brake on
- formerly_proven 6y agoJust run your own recursive resolver, it's very easy and reliable (e.g. knot-resolver).
- Fnoord 6y agoDoesn't show IPv6 for me. I always use IPleak.net [1]. Works for public IPv4, IPv6, DNS server, Tor/AirVPN exit node, BitTorrent, geolocation, and all kind of browser metadata. Browsing through comments shows this can do some things IPleak.net can't do such using wget/curl with API. [1] https://ipleak.net https://ipleak.net
- Fileformat 6y agoIt looks like ipleak.net does have an API [1]. Website is a bit "information overload" though. [1] https://airvpn.org/forums/topic/14737-api/ https://airvpn.org/forums/topic/14737-api/
- znpy 6y agoI run my own DNS servers at home. I have a small virtualization cluster and run a small DNS vm on each physical host. My resolvers perform queries against the root servers directly and cache results. It's refreshing to skip all the DNS fuckery that's going on nowadays.
- minerjoe 6y agoI do the same, but I read that that is also sending your IP all around the internet, which can have repercussions? The alternative is to not use a recursive resolver, but just punt to one of the "safer" ones such as 1.1.1.1? edit: downvoting honest questions?
- jlgaddis 6y agoWhat, exactly, does "sending your IP all around the internet" even mean?
- minerjoe 6y agoMeaning, if you don't want people to know you are searching for snm.donkeyporn.com than going out to the nameserver that donkeyporn is using is not exactly keeping the information private.
- viraptor 6y agoIn practice with 1.1.1.1 you're trading the parties who know about your access from: Donkeyporn's DNS provider, com's DNS provider (0.1% chance it's not already cached), your ISP, transit providers, donkeyporn's ISP, donkeyporn service To: cloudflare, your ISP, transit providers, donkeyporn's ISP, donkeyporn service It's not a huge change and it's really about whether you trust CloudFlare more than the service donkeyporn has chosen.
- minerjoe 6y agoI though correctly switching to cloudflare should just be me -> cloudflare via an encrypted channel?
- rosstex 6y agoSuper useful, thanks!
- tsjq 6y agoGood one. Thanks
- armSixtyFour 6y agoIt would be neat if this also recognized that you're hosting your own dns, instead of spitting your own IP back at you. I didn't recognize my IP at first.
- Fileformat 6y agoNice idea, and it should be pretty easy to do. Added to the to-do list!
- babuskov 6y agoUnrelated, but I found a typo on this page: https://resolve.rs/http/myheaders.html https://resolve.rs/http/myheaders.html It says: > These are the HTTP headers that are being sent my your browser. Great set of tools, BTW.
- Fileformat 6y agoThanks! Typo fixed too.
- gslin 6y agoAkamai also provides something similar: * https://developer.akamai.com/blog/2018/05/10/introducing-new-whoami-tool-dns-resolver-information https://developer.akamai.com/blog/2018/05/10/introducing-new...
- robertcope 6y agoI really like NextDNS. But right now, I'm pointed to Cloudflare Gateway servers.
- _-___________-_ 6y agoThis shows which DNS server performed the recursive query for you, but in more complicated setups it won't be the DNS server your system is pointed to. For example if you're using 1.1.1.1, this will show some other CloudFlare IP.
- Fileformat 6y agoThat's correct, but it is still useful (IMHO). The ASN value should be the same (or at least related). If it isn't, there is something going on that you should probably investigate.
- ycombonator 6y agoAlso is there a crawler / network tool to find a recursive resolver close to your geographical location
- Fileformat 6y agoIn this thread, @jelv suggested GRC's Benchmark [1]. There is also namebench [2], an older python tool. I personaly haven't used either one (yet). Definitely an opportunity for a new, portable tool! [1] https://www.grc.com/dns/benchmark.htm https://www.grc.com/dns/benchmark.htm [2] https://github.com/catap/namebench https://github.com/catap/namebench
- known 6y agoDIY script to find out the fastest DNS for you; for i in `cat dns_list.txt|grep -v '^#'` do qt=`dig @$i archive.is| grep "Query time:" |cut -f2 -d ':'` echo "$i: $qt" done
- Fileformat 6y agoI've added an "Alternatives" section [1] to the README with several of the sites/services/etc mentioned in this HN thread. [1] https://github.com/redirect2me/which-dns#alternatives https://github.com/redirect2me/which-dns#alternatives
- anderspitman 6y ago> I specifically made the API be JSONP only (i.e. you need to provide a callback parameter), so if you abuse it, bad things will happen to your clients! Is OP threatening to inject harmful code into abusers' script tags, or am I totally misreading this.
- Fileformat 6y agoYes: I've made free APIs in the past that have been abused. I've made this for my needs and am happy to share, but it isn't a moneymaker. It is really simple to host your own copy, and I've tried make it pretty clear that it should only be for light, non-commercial use. You can see the code, so obviously I haven't done anything nefarious. Hopefully just the possibility will be enough of a deterrant. I'm curious how everyone else is dealing with freeloaders. I'm open to alternative suggestions.
- anderspitman 6y agoOh I don't have an alternative suggestion. Just thought it was an interesting approach. Also I've never used JSONP and hadn't considered the security implications of using a JSONP api you don't control.