13 ms·
DNS0: The European public DNS that makes your internet safer
- Y_Y 4y agoPity they couldn't get a cool IP address like Cloudflare and Google. Since without some source of DNS you can't reach dns0.eu it's good to have something memorable like 1.1.1.1 or 8.8.8.8
- toyg 4y agoyeah I think that's really a big shortcoming. It probably comes down to funding, but it results in a big usability issue. I'll never remember those IPs, and when I can so easily remember 1.1.1.1 and 8.8.8.8, it's obvious what I'm always going to choose.
- zxcvbn4038 4y agoNo IPv6 either
- surmoi 4y agoThey have, but they listed them only in the Others and Linux tab for some reasons 2a0f:fc80:: 2a0f:fc81::
- zxcvbn4038 4y agoPerfect!
- 1f60c 4y agoAnd 1.1.1.1 + 8.8.8.8 = 9.9.9.9 (https://quad9.net https://quad9.net)
- jordiburgos 4y agoUse 1.1.1.1 to get the networking working, find DNS0.eu and change the DNS again :)
- dm 4y agoIt's kind of ironic that their main IPv4 addresses are x.x.x.0, while their "ZERO" filtering version uses x.x.x.9.
- deleted 4y ago[deleted]
- mdrzn 4y ago"dns0.eu is a French non‑profit organization founded in 2022 by Romain Cointepas and Olivier Poitrey — co-founders of NextDNS."
- eikaramba 4y agookay now it actually sounds way more interesting. Because NextDNS is by far my most beloved DNS resolver
- 8fingerlouie 4y agoSo the end of NextDNS ?
- theshrike79 4y agoNextDNS lets me pick what to block, I can't configure DNS0 except for the few variants that require me to change the DNS address completely. Also: I can't pay for DNS0, so how can I trust they stay up when I'm not their customer?
- breton 4y agoHow can you trust they stay up when you are their customer and pay them?
- theshrike79 4y agoBecause I give them money to keep the lights on? That way they don't need to rely on grants or investors who usually need hockey stick growth and make the business do stupid things. This is why I used to pay for pinboard (before the admin disappeared again) and still pay for Newsblur.
- ignoramous 4y agoDNS resolvers aren't that expensive to run. Besides, one of the founders of dns0.eu has already scaled and sold a venture-backed startup (DailyMotion: https://archive.is/4pN5e https://archive.is/4pN5e), and currently employed as Director at Netflix. Pretty sure they can keep paying for dns0.eu servers for multiple decades. The only problem is maintenance, which is automatable to a large extent.
- parminya 4y agoHow can you trust any company you pay to stay up even if you are their customer? I've used discontinued products before. Paid subscriptions to companies that merge with others and the service no longer really exists.
- 4y ago
- moffkalast 4y ago> 193.110.81.0 Ah yes, easy to remember /s
- andy_ppp 4y agoNot everyone has the resources of a Google to acquire lucky IP addresses.
- moffkalast 4y agoWell you'd think the EU would have more resources than a single company.
- sschueller 4y agoMost of those single digit addresses are in the hands of US corporations. Like 4.4.4.4 is Level 3.
- wtch98 4y ago2.0.0.0/16 and 2.2.0.0/16 are owned by Orange, a European company. I'm sure they'd be willing to lease 2.2.2.0/24 and 2.0.0.0/24 for a nominal fee 5.4.0.0/14 (so 5.5.5.5) is Telefonica Germany. Same thing there. Mercedes owns 53.0.0.0/8 which feels like a nice number for DNS too.
- capableweb 4y agoTelefonica and Orange are hardly companies that would just let you lease "valuable" ipv4 addresses without having to pay a hefty sum.
- andy_ppp 4y agoIf you only lease something the owner can at any time take your business and efforts from you.
- 4y ago
- iruoy 4y agoThis is founded by co-founders of NextDNS. But why? How is it different?
- __alexs 4y agoBecause NextDNS is a for-profit company they probably can't get funding from the EU for these silly EU vanity projects so easily.
- daneel_w 4y agoHow is this a "silly EU vanity project"?
- __alexs 4y agoThere is an EU fund for silly projects like Gaia-X which are mostly about vanity rather than actually producing anything useful. I am suggesting they've formed a non-profit to try and benefit from this fund.
- daneel_w 4y agoYeah I don't see what's silly about providing a resolver with the features being offered, no matter the "EU" branding or official project funding. Right off the bat I'm willing to bet these guys are more genuine and honest about privacy/integrity than e.g. Google.
- __alexs 4y agoThere is nothing silly about the product specifically. It's useful. However they already built it: https://nextdns.io/ https://nextdns.io/ What I am calling silly is not dns0. It's the way the EU is funding technology projects.
- daneel_w 4y ago> It's the way the EU is funding technology projects. I personally think that's a good thing, to provide funding and opportunity for gratis service projects with less risk of deviating in the way things often do in commercial context where revenue is the top priority.
- tambre 4y agoNo IPv6 in 2023, is this a joke?
- f_devd 4y agoThey do have a IPv6 address under Linux & Others if that's what you mean
- sschueller 4y agoThey are listed under Linux: [Resolve] DNS=193.110.81.0#dns0.eu DNS=2a0f:fc80::#dns0.eu DNS=185.253.5.0#dns0.eu DNS=2a0f:fc81::#dns0.eu DNSOverTLS=yes
- acatton 4y agoFrom the "other" tab: > DNS53 (IPv6) > 2a0f:fc80:: > 2a0f:fc81::
- deleted 4y ago[deleted]
- mhitza 4y agoThere's IPv6, but I see it's not suggested by default except for Linux configuration and on the Others tab.
- preisschild 4y agoIs this actually affiliated with the EU, other than just being hosted in the EU?
- leohonexus 4y agoNot affiliated with EU at all. Their branding and wording makes it look like they are until you scroll to the bottom and read the About. Admittedly I don't live in the EU so to some of you folks the non-affiliation may seem obvious.
- capableweb 4y ago> Their branding and wording makes it look like they are Because the website is blue and mentions "European Union"? It doesn't say anywhere that it's a official EU project, nor does it contain some of the famous "banners" that EU projects usually have in the footer to show their grants/funding, nor is it on a official EU domain. Clearly a not-EU project from first glance.
- leohonexus 4y agoI don't live in the EU (nor the Americas for that matter) so I'm speaking from first impressions of browsing the site.
- simongray 4y agoI live in the EU and I agree with your first impression. They definitely tried to pass as a typical EU website.
- simongray 4y agoIt seems like they went through enough trouble to ensure that the page is translated into the official languages of the EU which is usually only something you see on EU websites. For that reason, it does appear official'ish at first glance.
- nix23 4y agoI just use quad9: https://www.quad9.net/service/service-addresses-and-features https://www.quad9.net/service/service-addresses-and-features
- forgotpwd16 4y agoAlso operated by a non-profit and also in Europe (albeit in Switzerland that isn't part of EU).
- 5e92cb50239222b 4y agoI wish they'd put more resolvers around the globe. I have 10ms ping to the nearest Cloudflare colocation, but around 100ms to quad9. It makes browsing the web so much slower.
- richij 4y ago90 ms. So much.
- 5e92cb50239222b 4y agoKeep your sarcasm to yourself. Multiply 90ms by sometimes dozens of domains modern websites like to load from. Occasionally ISP reroutes me to another Cloudflare colocation and ping to 1.1.1.1 rises to 20-25 ms. It's easily noticeable. I like to play the guessing game, and almost always "win".
- nix23 4y agoCan you please tell them that? I feel you, 100ms ARE recognizable if you have otherwise a fast net, it like snap to clap.
- danuker 4y agoFrom Romania, I've been getting random delays/timeouts with quad9.
- AstixAndBelix 4y agoThe EU will actually start offering an official European DNS service later this year, not to be confused with this private initiative
- madspindel 4y agoIt's called DNS4EU: https://www.whalebone.io/dns4eu https://www.whalebone.io/dns4eu
- amai 4y agoWhalebone? Doesn't sound like an official EU domain.
- daneel_w 4y agoMy router runs Unbound in order to rotate queries across a number of different DNS-over-TLS providers. I'll toss these guys into the mix as well out of curiosity just to see how it goes.
- dorfsmay 4y agoGiven the restrictions on this server which won't be on the other, adding it to a rotating list will make DNS answers inconsistant. Why would you want to do that?
- daneel_w 4y agoI won't be using the "zero" resolver.
- ignoramous 4y agoBetter to send your queries to a single DNS provider (over TLS/HTTPS) rather than spread it out, because now, not one but multiple providers can build your browsing history. As someone who runs a public DNS resolver, I can tell you that it isn't that hard to build user profiles. If you're running Unbound, might as well recurse DNS queries, instead of upstreaming it. If you are adamant on spreading DNS queries across multiple upstreams; doing so over ODoH and/or Anonymized DNSCrypt is what I'd recommend.
- addingnumbers 4y agoWon't recursing also spread your queries across multiple providers? And in the clear for deep packet inspectors to see, instead of encrypted?
- ignoramous 4y agoYou wish all nameservers would support DoH / DoT, but until then using Qname minimisation limits exposure.
- daneel_w 4y ago
- conradfr 4y agoDo they block or allow mandated blocked domain by EU countries?
- aaron695 4y ago[dead]
- andridk 4y agoUnbelievable that so many operating systems don't support encrypted DNS out of the box.
- helb 4y agoBefore i start digging into it, does anybody know how they do "No mature videos on YouTube" (in the "kids" filter) with just DNS?
- oriettaxx 4y agouh, you are right: +1 for this question
- rmccue 4y agoIt appears this is functionality provided by YouTube themselves where you can set a CNAME: https://support.google.com/a/answer/6214622?hl=en#zippy=%2Coption-dns https://support.google.com/a/answer/6214622?hl=en#zippy=%2Co...
- helb 4y agothanks, looks like you're right: $ kdig +tls www.youtube.com @kids.dns0.eu … ;; QUESTION SECTION: ;; www.youtube.com. IN A ;; ANSWER SECTION: www.youtube.com. 300 IN CNAME restrictmoderate.youtube.com. restrictmoderate.youtube.com. 1611 IN A 216.239.38.119
- nicolaslem 4y agoThe DNS responds with forcesafesearch.google.com for google.com. https://support.google.com/websearch/answer/186669?hl=en https://support.google.com/websearch/answer/186669?hl=en
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- VoodooJuJu 4y agoThey make it seem like they're affiliated with the EU, from brand colors, to TLD, and more. But of course they're unaffiliated. Seems intentionally deceptive.
- richij 4y agoThe blurb makes it crystal clear that it's talking about location or situs. In other words, regulated by EU regulations. The TLD is specifically for sites that are "in" the EU (as opposed to being "by" te EU).
- czechdeveloper 4y agoI did not have that feeling and .eu domains quite standard nation-like domain.
- Mindwipe 4y agoDoesn't disclose where their blocklists come from for the child product, hugely overblocks legitimate websites, has no appeals process for miscatagorisation. What an awful product.
- daneel_w 4y agoCan you provide any examples of legitimate sites that they block on their "zero" resolvers?
- daneel_w 4y agoI'll answer the question myself by providing an example I saw elsewhere, which also illustrates that their "default" resolver differs from the curated "zero" resolver: dig @193.110.81.0 uni.cf a status: NOERROR, ANSWER: 2 IN A 67.199.248.12 IN A 67.199.248.13 dig @193.110.81.9 uni.cf a status: NXDOMAIN, ANSWER: 0 IN A
- oriettaxx 4y agoNote that for the iphone's configuration to work, you need to use Safari to open their "configuration profile" link
- 1f60c 4y agoSo this is just NextDNS but without a control panel, and it’s 100% free? That’s nice.
- eterevsky 4y agoIt has quite extreme filtering: - No porn or other adult websites - No explicit search results - No mature videos on YouTube - No dating websites or apps - No mixed-content websites - No piracy - No ads
- shasts 4y agoIf I choose their DNS, the website shows a text at the bottom that says "You are using dns0.eu" How does the website know I'm using their DNS? I couldn't find anything in the HTTP header that would help them with this. https://imgur.com/fMZwxYz https://imgur.com/fMZwxYz
- dec0dedab0de 4y agoThey could be giving out different IP (or CNAME) for people using their DNS. Then the site is just slightly different depending on how it is accessed. or i suppose they could be looking at logs of the ips using their dns and checking all visitors to the website, but that would be wild. ooh they could also have a host that is only resolvable from those servers, and have the front end dynamically load that message from that host. and if it fails it does not show anything.
- HerrMonnezza 4y agoI guess they redirect you to a different IP than they publish in the public DNS?
- helb 4y agoJS does a GET request every 2 seconds or so to some random subdomain (probably to avoid caching): https://i.vgy.me/qCTabA.png https://i.vgy.me/qCTabA.png The JSON response contains 'status: "unconfigured"' when you're not using their resolver and 'status: "ok"' when you are: https://i.vgy.me/iVgIe1.png https://i.vgy.me/iVgIe1.png That green bar just appears after a "ok" response (no page reload needed).
- kapsteur 4y agoEurope having already planned to launch a service which will be called DNS4EU, it looks a bit like phishing. Source: https://joinup.ec.europa.eu/collection/ict-standards-procurement/solution/dns-rfc-1034-rfc-1035-domain-name-system/news/dns4eu https://joinup.ec.europa.eu/collection/ict-standards-procure...
- dschuetz 4y agoNo, thanks.
- helb 4y agoIf anyone's wondering which are the "High-risk TLDs" blocked in the "zero" filter: CF, CG, GA, GQ, ML, TK, TOP, WIN (right now, i guess it may change any time) The "kids" filter blocks the same TLDs, so it allows XXX or PORN, i guess they just block individual 2nd level domains. I just looped through IANA's TLD list with a simple script to get this. The resolver returns NXDOMAIN with "negative-caching.dns0.eu." SOA for the blocked ones: $ kdig +tls ns tk @zero.dns0.eu … ;; ->>HEADER<<- opcode: QUERY; status: NXDOMAIN; id: 39321 … ;; QUESTION SECTION: ;; tk. IN NS ;; AUTHORITY SECTION: tk. 300 IN SOA negative-caching.dns0.eu. hostmaster.tk. 0 1200 300 1209600 300
- Symbiote 4y agoIt seems pretty ridiculous to block those domains outright. There are plenty of legitimate government, tourist and local sites, which could at least be whitelisted. They've blocked UNICEF's link shortener: https://uni.cf https://uni.cf
- KingOfCoders 4y ago"They've blocked UNICEF's link shortener: https://uni.cf https://uni.cf" Which I consider a good thing, why route links through the influence space of a country that is in a civil war with foreign mercenaries running parts of the show?
- Symbiote 4y agoThat's not their reason for blocking, since e.g. North Korea is allowed (tried airkoryo.com.kp).
- denton-scratch 4y ago> safe for children Ah, it's filtered. Someone decides what "children" means. Someone decides what "safe" means. There are people who think that not just under-16s, but almost everyone is incapable of making adult decisions. And different (responsible, informed) adults may come to different conclusions about what is and isn't safe. Curated DNS may suit some people, but I appreciate having access to the real internet.
- xctr94 4y agoNonsense. You can choose which version to use, same with Cloudflare’s 3 different DNS choices.
- Mindwipe 4y agoAnd much like Cloudflare the lack of accountability and clumsy blocking schema of the "child safe" one is dangerous and worthy of criticism.
- mhitza 4y agoThere are separate dns servers, the one for kids is different from the one mentioned on the landing page.
- KingOfCoders 4y agoIf it's not for you it's not for you. I always wonder about people who go to a French restaurant and want Pizza.
- jMyles 4y ago> I always wonder about people who go to a French restaurant and want Pizza. To be fair, this is more like trying to lookup contact information for the local pizzeria, and realizing to your surprise that the phone book you've picked up has directed you to the French restaurant instead.
- bennyp101 4y ago
- jedisct1 4y agoNo support for Anonymized DNSCrypt nor ODoH. Guess they still want to see client IP addresses.
- RobotToaster 4y agoI just use OpenNIC https://www.opennic.org/ https://www.opennic.org/
- 0x00101010 4y agoToday it's a feature. Tomorrow it becomes mandatory by law. Loosing freedom with a big bang and a hole lot of happy people because they cannot compute. There is nothing good about things like that, at least on the long run.
- bragr 4y agoThis is run by a French non-profit, not the EU government. What are you on about?
- msm_ 4y agoThis slope is very slippery. This is an optional service that you can use, or ignore. Your position is like saying that kids-safe movies are a feature today, but will become mandatory in the future.
- jedisct1 4y agoSince they don't seem to be mentioned on their website, DNS Stamps are sdns://AgMAAAAAAAAAACCaOjT3J965vKUQA9nOnDn48n3ZxSQpAcK6saROY1oCGQdkbnMwLmV1Ci9kbnMtcXVlcnk ("zero" version) and sdns://AgMAAAAAAAAAACCaOjT3J965vKUQA9nOnDn48n3ZxSQpAcK6saROY1oCGQxraWRzLmRuczAuZXUKL2Rucy1xdWVyeQ ("kids" version). But these are already present in the list of public encrypted resolvers (https://github.com/DNSCrypt/dnscrypt-resolvers/blob/master/v3/public-resolvers.md https://github.com/DNSCrypt/dnscrypt-resolvers/blob/master/v...).
- edpichler 4y ago"The European public DNS" sounds misleading to me.
- tuananh 4y agoit's so slow for me. probably only deployed in Europe.
- H4ZB7 4y ago> 100% European but is it gluten free? /s at least it's not google or cloudflare it's pretty funny how a completely irrelevant broken protocol that i don't actually needed (could just type the 4 IP digits) is the central talking point of politics junkies
- somat 4y agoWhile I don't think it should be the only choice. Recursive dns does sound like the sort of service a government should offer it's citizens. Authoritative dns also sounds like the sort of service a government should offer it's citizens. I mean, sure, it would suck compared to commercial dns, but at least everybody could have a name if they wanted.
- alpenbazi 4y agonope. What do you do if your gov says "no" to your website? via your idea that would be a simple matter of seconds
- somat 4y agoThen you use another choice, the internet is great like that, what do you do when google's resolver says "nope" to your domain? Personally, all my devices run through my own recursive resolver which in turn directly resolves the address. Then I get to say "nope" to whatever domains I want(mainly ad services). Except for those thrice infernal dns over https devices, hard to police them that way.
- xav0989 4y agoCIRA, Canada's Internet Registry, runs a number of public DNS servers[1]. The main attraction is that the service is provided by a non-profit and the data and control are held in Canada, subject to Canadian laws and regulation. They also offer a number of levels of protection, from none (simply resolving the queries) to one blocking suspected malware/C2 domain and one blocking pornographic material. [1] https://www.cira.ca/cybersecurity-services/canadian-shield https://www.cira.ca/cybersecurity-services/canadian-shield
- codesniperjoe 4y agoWarning: Do not go to this site with enabled javascript! They spam your uplink DNS provider with thousands of uniq, uncachable (fingerprinting?) 'test' dns keys without your consent, to identify & track the DNS service you are using! Take a look at your DNS outbound log yourself!
- amai 4y agoComparison to PiHole: https://news.ycombinator.com/item?id=22718670 https://news.ycombinator.com/item?id=22718670 and https://help.nextdns.io/t/q6hmvay/what-is-the-advantage-of-using-nextdns-over-pi-hole https://help.nextdns.io/t/q6hmvay/what-is-the-advantage-of-u...