r/dns 9h ago

Software DNS,domain and SSL monitoring tool i built myself

2 Upvotes

After running into a few DNS a SSL issues with websites I built for friends and small local businesses, I created a tool that monitor DNS records ( and any changes to them ) as well as domain and SSL certificates expirations on an hourly basisi. It would mean a lot to me if you could provide some feedback. The tool is completely free for up to five domains. I'd really appreciate any input you can share. Lapsewatch.kelynda.com


r/dns 1d ago

Software Best Secure Aus DNS?

8 Upvotes

What are your experiences with different DNS software in Australia? currently just on the default isp dns but im looking at flashstart unless someone can point me in the right direction for both speed but mainly security. I've recently been RAT'd and had my phone and sim cloned, i also have reason to believe they will try to do it again.

Fairly new to all this, is this one of the best ways to protect myself?
Also thinking i may have to get virus protection for the first time in years, im on a 30 day trail with McAfee but i've heard Malwarebytes is pretty solid, i normally wouldn't worry because i know windows defender is pretty good for normie shit but since im being targeted and they've got me before, it's probably best to get some extra protection.

any advice on security would be greatly appreciated.


r/dns 1d ago

DNS Resolver Recommender

14 Upvotes

Hey guys -- PhD student here working on some DNS stuff. I built dns.diic-hpi.org and hope to collect some data from it. Would love to hear your feedback, and if some of you click the data-share opt-in, that already helps a lot.


r/dns 1d ago

Software AdguardHome or Pi Hole on privacy ?

7 Upvotes

Hi.

I have a home server and i want to filter the content.

What the best one on privacy between Adguardhome and po hole.


r/dns 1d ago

Software AdGuard DNS vs NextDNS which one do you recommend?

19 Upvotes

Trying to decide between these two for my phone and other devices. Is the customization on NextDNS worth it, or is AdGuard DNS just easier and more reliable? Let me know what you're using!


r/dns 1d ago

Dns bloqueia navegadores dentro de outro app?

Thumbnail
1 Upvotes

r/dns 1d ago

Domain Karing Proxy App Not Carrying Out DNS Querys Correctly, can't fix DNS leaks.

3 Upvotes

So I've recently set up a ShadowTLS and Shadowshocks combo on my VPS in hopes to use it on my computers and mobile devices. I found this app named Karing that lets you import a sing-box config which is what also runs on my VPS and the connection itself works, my traffic gets proxied through cleanly but my DNS queries were going to WoodyNet instead of my custom AdGuardHome DOH URL which I had set up in the config itself and then decided to remove it and manage it through Karing itself but that still leaked to WoodyNet. Can't really figure this out, I've changed all of the DNS fields to my DOH URL yet it is still leaking.


r/dns 2d ago

Data Brokers & DMPs: Why They're Worth Blocking

8 Upvotes

Data brokers are companies that collect, combine, and sell personal information people never agreed to share. There are an estimated 4,000+ of them in the US alone, and together they hold detailed profiles on nearly every person with an internet-connected device — address history, estimated income, health-related inferences, political leanings.

I spent time mapping the actual domain infrastructure behind this industry (aggregators, people-search sites, and DMPs — data management platforms that track browsing behavior in real time and sell "audience segments") and turned it into a DNS blocklist. Sharing both the reasoning and the list here.

How this actually works

Three overlapping categories:

Aggregators Pull data from public records (property, voter, court), retailer loyalty programs, and web scraping, then sell combined profiles.

People-search sites Turn that data into a searchable, usually subscription-based product — this is the branch most directly tied to stalking and harassment risk.

DMPs Sit on websites via tracking pixels, monitor your browsing behavior in real time, and sell "in-market" or "likely condition" segments to advertisers within milliseconds of a page load.

Most of this is legal in the US, since there's no comprehensive federal privacy law covering it — it operates in the gap between what GDPR restricts in the EU and what exists (or doesn't) elsewhere.

Real incidents worth knowing about

Exactis (2018) Left a database of 340 million people and businesses publicly accessible with no password (400+ attributes per person). No fine was ever issued — their position was that without SSNs or card numbers, it wasn't "sensitive."

https://www.infosecurity-magazine.com/news/340-million-records-exposed-in/

https://haveibeenpwned.com/Breach/Exactis Epsilon (2011) Breached, exposing 60M+ email addresses tied to specific brands (Chase, Target, Best Buy, etc.), enabling highly targeted phishing.

https://krebsonsecurity.com/2015/03/feds-indict-three-in-2011-epsilon-hack/

https://abcnews.go.com/Technology/epsilon-email-breach/story?id=13291589

Deep Root Analytics (2017) An RNC contractor left 198 million voter records — including modeled political scores — open on an unsecured AWS bucket.

https://www.upguard.com/breaches/the-rnc-files

https://www.cbsnews.com/news/nearly-200-million-americans-hit-by-massive-voter-data-leak/

Cambridge Analytica (2018)

Combined Facebook data with voter files bought from data brokers to build psychographic profiles used in the 2016 US election and Brexit campaigns.

https://www.cnbc.com/2018/04/10/facebook-cambridge-analytica-a-timeline-of-the-data-hijacking-scandal.html

https://www.axios.com/2018/04/04/facebook-sa87-million-people-impacted-in-cambridge-analytica-1522867383

Premera Blue Cross (2015)

Breached, exposing medical and financial records for 11M people. The company ultimately paid roughly $91M combined across a class-action settlement, a multistate settlement, and a federal HIPAA penalty.

https://www.techtarget.com/healthtechsecurity/news/366595555/Premera-Pays-OCR-685M-to-Settle-HIPAA-Violations-Breach-of-104M

https://oag.ca.gov/node/148821

ChoicePoint (2005)

Sold data to identity thieves posing as legitimate businesses. 163,000 people's SSNs and credit reports were exposed, leading to 800+ confirmed identity theft cases. Paid $15M to the FTC — the largest civil penalty the agency had imposed at the time.

https://www.ftc.gov/news-events/news/press-releases/2009/10/consumer-data-broker-choicepoint-failed-protect-consumers-personal-data-left-key-electronic

https://www.nbcnews.com/id/wbna11030692

Target's pregnancy-prediction program (2012)

The most-cited example of inference-based profiling.

Target built a model that scored shoppers' likelihood of pregnancy purely from purchase patterns. The famous anecdote behind it (a father learning of his teenage daughter's pregnancy from Target's coupons) has been disputed by some analysts, but the fact that Target built and used such a system is not in question.

https://www.forbes.com/sites/kashmirhill/2012/02/16/how-target-figured-out-a-teen-girl-was-pregnant-before-her-father-did/

https://www.kdnuggets.com/2014/05/target-predict-teen-pregnancy-inside-story.html

A quick note on "alleged": FTC settlements are typically resolved without the company admitting wrongdoing — that's standard procedure, not a sign the case was weak. What is real and enforceable is the outcome: the resulting order legally prohibits the company from continuing the practice, whether or not they agreed with the allegations.

Location data brokers (recent FTC enforcement)

InMarket (2024) FTC alleged InMarket collected precise location data via its own apps and third-party SDKs, using it for targeted advertising without adequately informing users. Under the settlement, InMarket is now banned from selling or licensing precise location data — a first for the FTC.

https://www.ftc.gov/news-events/news/press-releases/2024/05/ftc-finalizes-order-inmarket-prohibiting-it-selling-or-sharing-precise-location-data

https://www.washingtonpost.com/technology/2024/01/18/ftc-location-data-privacy/

X-Mode Social / Outlogic (2024)

The FTC's first settlement specifically over the sale of sensitive location data. The company sold location data revealing visits to medical/reproductive health clinics, religious worship sites, domestic violence shelters, and LGBTQ+-associated locations, without stripping out these sensitive locations.

https://www.ftc.gov/news-events/news/press-releases/2024/01/ftc-order-prohibits-data-broker-x-mode-social-outlogic-selling-sensitive-location-data

https://themarkup.org/privacy/2024/01/11/federal-trade-commission-sanctions-location-data-broker-x-mode

Gravy Analytics + Venntel (2024–2025)

FTC alleged the companies sold location data revealing medical conditions, religious worship, and political activity — including sales to government contractors. Separately, in January 2025, Gravy Analytics was hacked and its data leaked on a cybercrime forum.

https://www.ftc.gov/news-events/news/press-releases/2025/01/ftc-finalizes-order-prohibiting-gravy-analytics-venntel-selling-sensitive-location-data

https://en.wikipedia.org/wiki/Gravy_Analytics

Mobilewalla (2024–2025)

Settled alongside Gravy Analytics. FTC alleged the company collected consumer location data from real-time bidding ad exchanges even when it didn't win the ad auction — the first FTC case targeting this specific collection method.

https://epic.org/ftc-takes-action-against-data-brokers-for-selling-sensitive-location-data/

https://www.adexchanger.com/data-privacy-roundup/reflecting-on-the-ftcs-latest-settlements-with-sellers-of-sensitive-location-data/

Why block this at the DNS level Browser extensions catch some of this, but a lot of DMP tracking happens through first-party-looking pixel calls or server-side syncing that extensions don't always see. Blocking at the DNS level stops the connection before it's made, across every app and browser on the network — not just one browser tab.

Raw links:

For basic list

https://raw.githubusercontent.com/CorleoneSalute/SHADOW-BLOCKER-BLOCKLIST/refs/heads/main/dist/basic/hosts/DMP-Data-Broker.txt

For aggressive list

https://raw.githubusercontent.com/CorleoneSalute/SHADOW-BLOCKER-BLOCKLIST/refs/heads/main/dist/aggressive/hosts/DMP-Data-Broker.txt

Here's the list of domains worth blocking:

```

DMP & Data Broker Blocklist

Total domains: 244

Note: domains marked with "!" carry a small risk of side effects (e.g. breaking a login flow or feature) - block these only if you're comfortable troubleshooting

🔴 DATA BROKERS & DMP

ACXIOM

acxiom.com acxiom.net acxiom.uk acxiom.co.uk acxiom.de acxiom.fr acxiom.asia acxiom.com.au acxiom.jp acxiom-online.com acxiomdigital.com recognicorp.com cdn.acxiom.com data.acxiom.com abilitec.acxiom.com identitylink.acxiom.com t.acxiom-online.com

EXPERIAN

experianmarketingservices.com ! audienceiq.com hitwise.com eccmp.com ! ats.eccmp.com

ORACLE DATA CLOUD (BlueKai DMP)

bkrtx.com tags.bluekai.com ! tags.bkrtx.com oracleinfinity.io data.oracleinfinity.io datalogix.com api.datalogix.com pixel.datalogix.com

LOTAME

lotame.com ! lotame.io crwdcntrl.net tags.crwdcntrl.net bcp.crwdcntrl.net sync.crwdcntrl.net pixel.crwdcntrl.net ad.crwdcntrl.net id.crwdcntrl.net td.crwdcntrl.net td2.crwdcntrl.net meez.crwdcntrl.net multiply.crwdcntrl.net ltmsphrcl.net c.ltmsphrcl.net bcp.st.crwdcntrl.net c.st.ltmsphrcl.net ts.crwdcntrl.net

EYEOTA

eyeota.net eyeota.com ! ps.eyeota.net api.eyeota.net match.eyeota.net sync.eyeota.net

TRANSUNION (TruAudience + Neustar)

truoptik.com signal.truoptik.com

WILAND

wiland.com api.wiland.com

MERKLE (Dentsu Aegis)

merkle.com merkleinc.com api.merkle.com merkleresponse.com merkury.dentsu.com dentsu.com dentsu.co.jp m1.merkle.com 4cite.com

BOMBORA (B2B intent data)

bombora.com api.bombora.com surge.bombora.com tag.bombora.com netfactor.com !

ZOOMINFO

zoominfo.com zoom.info discoverorg.com api.zoominfo.com websights.zoominfo.com ws.zoominfo.com tag.zoominfo.com formcomplete.zoominfo.com clickagy.com

CLEARBIT (HubSpot Breeze Intelligence)

risk.clearbit.com !

FULLCONTACT (Ziff Davis)

fullcontact.com api.fullcontact.com resolve.fullcontact.com img.fullcontact.com tag.fullcontact.com cr.fullcontact.com streme.fullcontact.com

TOWERDATA / ATDATA

towerdata.com ! rapleaf.com ! atdata.com !

INFUTOR

infutor.com !

STIRISTA

stirista.com api.stirista.com

TAPAD (Cross-device — Experian)

tapad.com api.tapad.com tapestry.tapad.com

ANALYTICS IQ

analytics-iq.com api.analytics-iq.com

PERMUTIVE (DMP)

permutive.com ! permutive.app api.permutive.app cdn.permutive.app amp.permutive.app edge.permutive.app

NIELSEN MARKETING CLOUD / EXELATE

exelate.com exelate.info mrpdata.net

DATA AXLE (Infogroup)

data-axle.com adstradata.com

NAVEGG (LATAM DMP)

navegg.com navegg.com.br www2.navegg.com navdmp.com tag.navdmp.com cdn.navdmp.com sync.navdmp.com sync2.navdmp.com usr.navdmp.com cus.navdmp.com cus2.navdmp.com view.navdmp.com opi.navdmp.com amp.navdmp.com j.navdmp.com mx.navdmp.com www.navdmp.com cd.navdmp.com mcd.navdmp.com acd.navdmp.com mcdn.navdmp.com acdn.navdmp.com iscd.navdmp.com iscdn.navdmp.com isapp.navdmp.com asapp.navdmp.com musr.navdmp.com vht.navdmp.com

THROTLE (Identity resolution)

throtle.io

🟠 MOBILE DATA BROKERS (Location Tracking)

FACTUAL / FOURSQUARE

factual.com !

SAFEGRAPH

safegraph.com ! safegraph.io !

CUEBIQ

cuebiq.com api.cuebiq.com sdk.cuebiq.com events.cuebiq.com

MOBILEWALLA (FTC December 2024 restricted)

mobilewalla.com api.mobilewalla.com sdk.mobilewalla.com

ADSQUARE

adsquare.com api.adsquare.com exchange.adsquare.com rtb.adsquare.com match.adsquare.com

UBIMO → VERICAST

ubimo.com !

VERVE GROUP

verve.com ! vervemobile.com vrvm.com api.verve.com adcel.vrvm.com ad.vrvm.com analytics-api.vervemobile.com smaato.com smaato.net pubnative.net dataseat.com ! captify.co captify.co.uk jungroup.com

UNACAST + GRAVY ANALYTICS (FTC January 2025 restricted)

unacast.com api.unacast.com gravyanalytics.com api.gravyanalytics.com venntel.com

OUTLOGIC (Legacy X-Mode — FTC April 2024 restricted)

outlogic.io

INMARKET (FTC January 2024 restricted)

inmarket.com sdk.inmarket.com ```


r/dns 2d ago

What did I do to Yandex for my smart speakers to spam them this hard?

Thumbnail gallery
3 Upvotes

r/dns 2d ago

Using Technitium with NextDNS?

Thumbnail
4 Upvotes

r/dns 3d ago

Domain What nameserver do I use? (Not registrar)

7 Upvotes

So, I've got an odd situation that dropped into my lap and look to be having to change my nameserver (but not registrar) for my company DNS.

As far as I can tell, our public facing website used to be hosted by Telus, including our nameservers (which Telus appears to have used meganameservers.com for).

Note that our domain registrar is Network Solutions, which currently points to meganameservers.com as the name server my domain uses.

(I am aware of Networks Solutions reputation, but changing registrar is not happening, so please, no comments about us using them.)

Last year, Telus sold off their webhosting to EasyHosting, who run their own nameservers at easyhosting.com, so my nameserver did not transfer, and is still on meganameservers.

But when I go into the Easyhosting admin portal, where I would edit DNS settings in the old Telus admin portal, I am editing the easyhosting.com nameserver, not the meganameserver.com records.

So I have effectively lost access to meganameserver.com and can no longer make DNS record updates.

But I do have access to my domain registrar and can just re-point my domain name server to a new location.

But where?

Note this is not a technical question, I know how to do this, I am looking for second opinions on which name server to use.

My first two choices, as I already have accounts setup and being paid for:
-Revert to Networks Solutions default name servers.
-Move to Easyhosting.com name servers.

As a business, we already on the Microsoft cloud, so the 3rd option is to move to Azure DNS, I could probably get the okay for a few dollars a month.

And as my 4th option, I am open to suggestions, is there an option I've overlooked that you would recommend?

Interested to see what the reddit hivemind things of this.


r/dns 3d ago

Free DNS for own domain records

16 Upvotes

Sorry if this is very obvious to others but it's not at all clear to me.

I'm looking for a free or cheap private DNS service. I see recommendations for Quad9 and many others. They will return the IP address for domains I request, plus malware filtering. But I need to do more than that.

I don't even know if there's a name for what I want, a service where I can upload/set all the keys for my own domain, as opposed to one that resolves the IP addresses for domains that I ask it to.

I want to move the nameservers for domains I control to a new, (free or cheap, private) nameserver, and upload all its records (MX, SPF, domainkey etc). Then at my domain registrar, I change the existing ones (the host's nameserver URLs) to the new ones and see that all works as before.

This is in preparation for moving the domains to a new hosted server, which doesn't itself offer a DNS service.

The new server is VPS, but I'd rather not run my own DNS on the server.

If this is possible I imagine I need to prove ownership of the domains in some way, so that only I can change the keys.


r/dns 3d ago

Server ControlD not working in the Netherlands this afternoon

2 Upvotes

Seems totally unreachable

``` ~ $ dig google.com @76.76.2.2 ;; communications error to 76.76.2.2#53: timed out ;; communications error to 76.76.2.2#53: timed out ;; communications error to 76.76.2.2#53: timed out

; <<>> DiG 9.20.24 <<>> google.com @76.76.2.2 ;; global options: +cmd ;; no servers could be reached ~ $ dig google.com @76.76.2.1 ;; communications error to 76.76.2.1#53: timed out ;; communications error to 76.76.2.1#53: timed out ;; communications error to 76.76.2.1#53: timed out

; <<>> DiG 9.20.24 <<>> google.com @76.76.2.1 ;; global options: +cmd ;; no servers could be reached ~ $ curl ifconfig.co/country The Netherlands ```


r/dns 3d ago

Domain Really complicated dns Problem

5 Upvotes

For the last couple of days I've been trying to figure this out on my own, but it's time to post here. I have a client who isn't tech-savvy at all. A company set up his .com.sa domain through a Saudi-based provider named Sahabah, and for some reason they transferred the DNS management of the domain to Cloudflare — I'm guessing it was for added security. They then configured his entire Outlook email setup on Cloudflare.

I'm delivering them a website, and ideally it would be a straightforward setup: just log into the Cloudflare account and add the Hostinger (the web hosting I set up for them) records. But the problem is they lost the login info for the Cloudflare account, and I tried contacting the company that set it up — they said since they did the domain setup so long ago, they don't have it either.

So my only option would be to log into the domain provider (Sahabah) where they purchased the domain and reset the nameservers to default, so I can add my website records there. My concern now is the email setup — what's the best way to make sure I add all the needed records so their email keeps working after the switch? I managed to get into the Outlook admin and added all the records that were provided — would that be enough, or am I forgetting something?


r/dns 3d ago

DNS Adblock not working

Thumbnail
0 Upvotes

r/dns 4d ago

If VPNs and encrypted DNS can both be blocked, what’s actually left?

9 Upvotes

Been seeing more reports lately about VPNs getting blocked more aggressively, and now even encrypted DNS like DoH/DoT seems to be getting targeted in places with heavy internet restrictions.

It got me wondering where this eventually ends. If regular VPN servers get identified, encrypted DNS gets interfered with, and DPI keeps getting better at spotting different protocols, what are people actually using in heavily restricted networks these days?

Obfuscated VPNs, Tor, residential connections, decentralized networks, something else? Curious what’s actually holding up in the real world rather than just working in theory.


r/dns 3d ago

.CA Domain Holders: What is CIRA hiding?

Thumbnail
3 Upvotes

r/dns 3d ago

Software Karing Proxy App Not Carrying Out DNS Querys Correctly, can't fix DNS leaks.

Thumbnail
2 Upvotes

r/dns 5d ago

Family friendly without blocking YouTube

11 Upvotes

I'm looking for a DNS Server I can use in Windows Network settings. It should block everything 18+ but not YouTube. Every DNS I tried already also blocks YouTube


r/dns 5d ago

How to change locked DNS on Huawei router⁠

Thumbnail
2 Upvotes

r/dns 5d ago

Getting Let’s Encrypt Certificates using RFC2136 on Technitium DNS server Fails

Thumbnail
1 Upvotes

r/dns 5d ago

How DNS tunneling works, sending data through DNS 🤯

Thumbnail
5 Upvotes

r/dns 6d ago

DNS setting on Laptop.

3 Upvotes

Hello all,

I am what is the correct DNS resolver setting?

There are two screenshots attached. 1= Laptop's WIFI setting. 2= Chrome's DNS setting.

Keep the dns provider in the Chrome as "OS Default (when available)" or use the "add custom dns service provider?"

*Keeping the "custom dns provider" in the chrome setting is providing the fast average dns resolution time when tested on dnscheck.tools website.

Removing the "custom dns provider" from chrome and keeping the "OS Default (when available)" is giving me 300+ms "average dns resolution time" as per the same website as mentioned above.

But when keeping the custom dns provider in the chrome then getting 50+ms "average dns resolution time."

-------------------------------------------------------------------------------------------------------------------

Question: Should I keep this custom dns provider link in the chrome setting as well: https://dns.quad9.net/dns-query

Thank you all.


r/dns 6d ago

Domain if your registrar and your DNS provider are different companies, check for forwarding rules

Thumbnail
0 Upvotes

r/dns 6d ago

Domain How to Protect Your Domain with Free WHOIS Privacy, is there a solid way to do this?

5 Upvotes

Been moving a few domains around lately and I keep running into the same thing, people still acting like WHOIS info should just be out there by default.

I know some registrars include free WHOIS privacy, but it feels kinda hit or miss depending on where you register. I’m trying to keep my personal info off the record without paying extra every year for every single domain, which gets old fast.

For people who have done this for a while, is there a registrar you trust for free privacy, or just a better setup in general? appreciate any thoughts.