What's new

Selecting a DNS server service

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

alternety

Regular Contributor
I have spent a bunch of hours researching. I just can't seem to make a decision. There are a bunch of free DNS services with various objectives for users. Pretty much all of the sources I have read avoid actually doing a comparison resolving what service is optimal. I would really appreciate some specific decision points for selecting the provider. What I have seen is mostly general views.

My system is running on an Asus AC3100. That really does not play a part in the issue; but I figured someone would ask.

There are obviously trade-offs.
- Speed (delay) when dealing with a query for a target with various DNS server systems.
- Features that optimize speed of response at the cost of security.
- A balance of speed, privacy, and security functions.​

What I am looking for is a bit more distilled evaluation of the available DNS servers.

My criteria:
- And I realize there are going to be multiple points of view and criteria.
- Speed is a concern. It should not be awful. Half an hour: bad. Pretty soon now: OK. I do not do gaming so real time is not of interest. The objective is just responsive general internet activity.
- My major dilemma revolves around security.
- I don't care about filtering children, politically correct content, or sites with other "bad" things. I want raw internet.
- The various levels of provided security filtering with each provider tend to be a bit confusing/daunting.
- I would really prefer that the source of DNS will not be collecting and selling my activity.
- I want as much protective features as I can get. My major point in use is keeping my system secure.​

There are a lot of providers. Reviews tend to be nebulous.

What I want is WAN access speeds that do not suck. And the best protection I can get for my home network. I realize there are going to significant trade-offs. And they are not necessarily a static environment. Add to that providers likely to survive.

Here is your chance to write an article for the confused that will certainly induct you into the realm of "What an incredible insight and effective selection of trade-offs that will bring people with Camels and strange gifts bearing solutions."

Short request: help.
 
Speed of DNS servers is largely a non-issue because you should be using your router as a caching DNS forwarder (the opposite of what grc.com recommends :rolleyes:). Client devices also tend to have their own local caches. For uncached DNS requests your ISP's servers ought to be the next fastest, although whether that's the case is another matter. You'd have to check whether they're spying/selling your activity. Reliability might also be an issue.

You say "security" is your primary concern. I interpret what you wrote as protection (i.e. blocking) from malicious web sites. But you also said you wanted "raw internet" which is a contradiction. OpenDNS Home is one of the go-to places for free customisable filtering although I've personally not used it.

If by "security" you mean you want to encrypt your DNS requests so that big brother can't spy on you then you're talking about DoT or DoH. Be aware that there is a significant speed overhead by using this. In my own case a normal uncached query to 1.1.1.1 takes 14ms, using DoT it takes approximately 100ms. There are various threads in these forums about DoT (Stubby) but I can't remember seeing anybody complaining about the speed differential so I'm inclined to believe that supports my opening statement.
 
Let me rephrase. I did not do well with terminology.
- Speed is of lesser importance.
- I want the best free protection at the DNS provider.
- I have looked at many, but unable to pick due to a lack of significant understanding of the various services supplied by a free DNS supplier.
- The service provider needs to handle IPV4 and IPV6.

Thats all.
 
dnscrypt is your answer. Unless you want your ISP watching everywhere you go. Use unbound keep a large cache for speed. Use a dnscrypt resolver that mentions they do not log. Run it at the router level with a 3 servers selected for redundancy. dnscrypt V2 can block host names. Heyyyy free adblocker as well!
 

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top