21

I responded to someone in comments on a post that may not get as much visibility, and wanted to share something that might help some others who are new or unfamiliar.

I referenced Quad9 DNS as probably one of the best private DNS you can use, Swiss based, no log, no tracking, no data to sell, etc. They also implement DNSSEC, DoH, DoT, QUIC, ECS (which you may or may bot want), malware blocking, content filtering, and maybe something else I'm forgetting.

Many DNS sinkhole apps, OSes, or systems can actually utilize Quad9 for your resolver while those systems also block ads. Below is my functional list of systems that I'm aware of, though I haven't tested everything. I believe all are considered FOSS, too. If you don't have a spare Raspberry Pi laying around, try running in HomeAssistant, Yunohost, ZimaOS (previously CasaOS), or others.

DNS sinkhole (Adblocking) apps:

  1. Pihole
  2. eBlocker
  3. Technitium
  4. AdGuard
  5. uBlock Origin

Feel free to comment and add your own I'm maybe not aware of. I'm no software engineer, but I can read through some code, though not an expert, nor have combed through these personally. Usually I've tested/run at the recommendation of others over the years before my ban on Reddit (for shitting on AI).

Hope this helps!!

top 10 comments
sorted by: hot top new old
[-] yodeljunkmanenvy@piefed.social 4 points 1 week ago* (last edited 1 week ago)

+1 for both Quad9 and AdGuard.

I run AdGuard Home and all of the devices in my home use it for DNS.

In the last 24 hours, 41% of the DNS queries on my network were blocked as a tracker or ad.

ZVgAvCw6JIpvCZ2.png

[-] hneerqe@lemmy.world 4 points 1 week ago

I just do it all in my openwrt router now. Set up any DoH (https-dns-proxy) or DoT (stubby) with DNSSEC, plus blocklists with adblock-fast.

Hagezi has some servers with default blocking https://github.com/hagezi/dns-servers

https://github.com/hagezi/dns-blocklists#dnsservices

I was liking NextDNS, they have good features, and I liked not having to maintain blocklist files with shady domains in plain text saved in my hardware, but their jurisdiction and their code being closed source made me reevaluate.

[-] hobata@lemmy.ml 3 points 1 week ago

do you use something of DNSSEC, DoH, DoT, QUIC, ECS and if, why?

[-] unitedwithme@lemmy.today 3 points 1 week ago

I do use DNSSEC for my website and my XMPP server. I do not use ECS as Quad9 references possible IP addresses leaking https://quad9.net/support/faq/#edns.

For my home network, my piholes point to:

IPv4

  • 9.9.9.9
  • 149.112.112.112

IPv6

  • 2620:fe::fe
  • 2620:fe::9

I do also use https://dns.quad9.net/dns-query for my phone when on data or non-Home WiFi. I typically use a VPN, but for logging into my bank website I need to disable the VPN. I have LineageOS with no 3rd party Google Play apps, they're all FOSS through F-Droid.

[-] hellmo_luciferrari@lemmy.zip 2 points 1 week ago

For years I used Pihole; and still use it as a secondary DNS. But I tried Adguard, and just did not like it. So ultimately I landed on using Technitium. That has been one of the best switches for me when it comes to DNS hosting. But it may not do the job everyone is looking for.

The big reason I switched to using Technitium over Pihole for my primary DNS had less to do with privacy and more to do with functionality. I wanted to automate DNS entries, and while I could with Pihole, it was not as clean. I use DNSWeaver, and whilei DNSWeaver can use Pihole's API to add DNS records, it doesn't automatically clean up records when a container stops. So, in came Technitium; allowing TXT records to be created. That is how DNSWeaver knows which DNS records to clean up.

Anyways, big fan of Technitium.

[-] non_burglar@lemmy.world 2 points 1 week ago

I've been using technitium in a primary/secondary pair for about three years, and oldheads like me definitely like the real DNS server options, like zone transfers. Very stable, too.

[-] Apocrathia@lemmy.ml 2 points 1 week ago

DNS is one of those things that takes everything down with it when it breaks, so I avoid running it at home without a reliable backup resolver. I’ve used NextDNS for years now and it’s been great.

[-] unitedwithme@lemmy.today 3 points 1 week ago

That is why I not only use 2 IPv4 but 2 IPv6 addresses, and 2 piholes. Quad9 has 99.994% uptime. They show the last outage for 4 minutes back on June 29th.

[-] Newhere@lemmy.ml 1 points 1 week ago

I find annoying that eBlocker is using local VPN.

[-] eleitl@lemmy.zip 1 points 1 week ago

Opnsense has packages can directly DNS resolve, with blocklist subscriptions.

this post was submitted on 20 Sep 2026
21 points (92.0% liked)

Privacy

51115 readers
558 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 6 years ago
MODERATORS