Autonomía digital y tecnológica

Código e ideas para una internet distribuida

Linkoteca. DNS


Captura de pantalla de infosecmonkey.com

A few patterns work well in practice. Use Cloudflare 1.1.1.1 (or 1.1.1.2 if you want malware blocking) as your primary, with Quad9 9.9.9.9 as your secondary. You get Cloudflare’s speed for the common case and Quad9’s blocking as a fallback if Cloudflare ever has a hiccup, which has happened, briefly, more than once. For a household with kids, 1.1.1.3 at the router level is the simplest configuration that exists; OpenDNS FamilyShield is the equivalent if you’d rather have Cisco’s categorization. If you want any kind of custom rules, site-by-site allowlists, per-device policies, time-of-day blocking, none of the free tiers really cuts it; that’s where NextDNS, ControlD, or a self-hosted Pi-hole start to make sense.

SPs (Internet Service Providers) generally offer DNS services to their customers, so when you don’t set up DNS servers on your computer or router, your DNS queries will run on your ISPs DNS servers. Using the default ISP DNS servers can result in certain problems while browsing the Internet:

Issues can happen with DNS requests themselves; most of the time they’re unencrypted and this leaves room for different types of DNS attacks.

Easy: you need to set a CNAME record in your xxxx.com domain, pointing to your dynamic DNS domain at xxxx.strangled.net

DNS resolver will follow the CNAME transparently. User will not notice any difference. It might add a hundred milliseconds or so to the whole query, but that shouldn’t be a problem. When you type htpc.xxxx.com in your browser, it will still stay htpc.xxxx.com. You will not even realize that the strangled.net address is involved in all this.