4 ms·
Suggestion: if your network provider's recursive DNS service sucks so much that you cannot bear to use it (and even if it doesn't, quite frankly) your next best
by mfincham 13y ago
Suggestion: if your network provider's recursive DNS service sucks so much that you cannot bear to use it (and even if it doesn't, quite frankly) your next best bet is probably to install unbound (https://unbound.net/ https://unbound.net/) listening on localhost on your workstation.
Not only does this give you known-good DNS resolution, but you can also enable DNSSEC validation and be fairly confident that it'll actually do its job in preventing your local machine from resolving poisoned zones.
- aidenn0 13y agoI set up a caching recursive DNS server on my lan, but had to add a second entry for a caching public DNS server since: 1) Most DNS entries these days seem to have very short TTLs 2) Occasionally the recursive queries would fail
- mfincham 13y agoWould you mind clarifying what you mean by "second entry"?