3 ms·
So then what do you use or recommend instead?
by fuzzy2 2y ago
So then what do you use or recommend instead?
- udev4096 2y agoMullvad [1], dns.watch, dnscrypt [2] 1 - https://mullvad.net/en/help/dns-over-https-and-dns-over-tls https://mullvad.net/en/help/dns-over-https-and-dns-over-tls 2 - https://dnscrypt.info/public-servers/ https://dnscrypt.info/public-servers/
- accrual 2y agoI use a combination of 1.1.1.1, 9.9.9.11, and OpenDNS over DNSSEC via Pihole. Not sure if it's a "good" strategy, though.
- ratorx 2y agoI think the France legislation is aimed at most major resolvers. You might get away with more niche ones for now, but the only stable way is to self-host a recursive resolver (like unbound) that walk the DNS tree themselves.
- prmoustache 2y agoHost your own dns resolver. It isn't hard.
- udev4096 2y agoHosting is never hard. It's about maintainability. How do you handle HA? How will you expose the service? What about backups? How efficiently are you running it? That's just the tip of the iceberg. For an average joe, this is not something they wanna deal with
- DanAtC 2y agoBro it's a DNS server. People happily run Pi-holes without all that.
- udev4096 2y agoGood luck when something goes wrong, which it will. At the very least, you need HA for pi-hole which is easy to do with something like nebula-sync
- prmoustache 2y ago> (1) How do you handle HA? (2) How will you expose the service? (3) What about backups? (4) How efficiently are you running it? We are talking a DNS resolver at home or on a VPS. 1. you don't need HA, if it dies you revert back to your ISP DNS while you fix it. And you always have a secondary resolver set up anyway. 2. you just set up its ip address as first dns server on your home router and as DoH on your devices browsers. 2. you don't need to back up a local resolver, the only data it has is cache. 4. a local DNS resolver serving the needs of a household needs very little resource.
- udev4096 2y agoYou are doing a bare minimum job which is of course not what I intended. Your workloads doesn't seem to be that sensitive. If you can afford a few minutes of downtime, sure. I cannot afford downtime because lots of critical services will fail which will require manual intervention