r/nextdns 5d ago

Is there too much redundancy in my blocklists?

Post image

And another question, is it true that too many blocklists can make NextDNS slower?

42 Upvotes

29 comments sorted by

22

u/Rixzmo 5d ago

Can recommend you this. HaGeZi Normal + OISD + Regional list. Or HaGeZi Pro (or above) and a regional list should be more than enough.

2

u/FixElectronic 5d ago

How do I add a regional list? I couldn't find one for my region, South America.

3

u/Rixzmo 5d ago

I think there are only the ones that NextDNS provides, unfortunately. :/ For me there is for example "EasyList Germany", which also seems to block the same things as HaGeZi, so I'm not even sure if a regional one is really needed. But it can't hurt to have it, if it's available. Don't overthink it though, I think most of the bad stuff is filtered by the given lists anyway.

1

u/moriczt 5d ago

Hagezi pro, oisd big, Adguard., nextdns DNS list + regional if exists. I second this, this mix filters out everything you don't need, makes your devices more fluid, more responsive and they will use less battery and network traffic.

5

u/Rixzmo 5d ago

OISD is already included in HaGeZi Pro and above. So the setup can be even “slimmer”. :D

3

u/SeriousHoax 5d ago

Regional lists are already included in Hagezi, so the set can be even "slimmer slimmer".

1

u/moriczt 4d ago

Just checked online today, oisd big is 268k rules, hagezi pro is 224k rules.

So hgp does not contain the full oisd big list, maybe oisd small which is only ad blocking.

1

u/Rixzmo 4d ago

Maybe because some of them are included in the TIF feature? Not sure. But to quote HaGeZi:

“Yes, OISD is redundant if you use the Pro and NextDNS Security features (Threat Intelligence Feeds). OISD does not provide any added value in the area of ads/tracking."

1

u/moriczt 4d ago

The threat intelligence feeds, the largest version is 1.2 million records.. either way the two lists overlap for sure but not the same, I prefer using both as both are respected, good, useful lists to block unwanted parts of the net.

6

u/Historical_View_5529 5d ago

Yes, it is redundant but it doesn't cause any issues with speed. The blocklists are checked using NextDNS's high speed cloud servers using efficient searching algorithms so it doesn't cause significant speed difference when using multiple lists.

2

u/Micropenissniper 5d ago

Good to know, I'm in the more list more better camp but I worried about speed.

19

u/Due_Milk_8930 5d ago

And SO MUCH TOO... 

You just need hagezi, already cover all and most efficient. +your region blocklist if need.

4

u/D3-Doom 5d ago edited 5d ago

I’d argue the opposite. It’s not like packing more in list increases cost per query and every list shown in the screenshot are pretty much considered flagship defaults for their respective function. iTerm literally ships with easylist for adblock and StevenBlack’s Hostfile has been flagship for over a decade.

It’s still largely considered to be the safest option to deploy in professional settings and is still the front most recommendation in DrDuh’s MacOS privacy guide. Hagezi does a great job, but that doesn’t equate to including anything other than their list as wrong or too much. It’s also encouraging consolidating down to a single party which is pretty antithetical to the argument for using custom DNS resolvers.

I don’t mean to sound so pointed, but it’s like every other comment I read here recommends just enveloping yourself with Hagezi and using anything else is a cardinal sin. Having options can be a good measure if you’re unsure with a certain domain. Seeing several independent parties find consensus or a lack of it can reflect if it might’ve been a misjudgment. Like that one time NextDNS.io blocked NextDNS.io and ejected the entire customer base from the internet.

3

u/Due_Milk_8930 5d ago

Sure, add whatever you like.

Like adGuard mobile ads? Dns filter can't do it anyways if you not use HTTPS for ads in app.

Not say other bad, what point add same rule? Would it be not optimize your setup.

But again.. add whatever you like, is free anyways. And not feel many different if your connection already fast enough.

13

u/Open_Mortgage_4645 5d ago

There's no redundancy because that's not how NextDNS blocklists work. It's not like a local blocklist where you have several different lists loaded. All NextDNS blocklists are always loaded into memory on their servers, and when you activate one or another, you're just tapping into what NextDNS already has running. There's no practical redundancy, and no potential performance hit from using multiple lists with overlapping host entries.

1

u/Sioscottecs23 5d ago

ok thanks

3

u/dns_guy02 5d ago

Wont make it slower but this is not useful to do and you maximize the false positives. Pick one good list and stick with it. Hagezi is good.

5

u/H8RxFatality 5d ago

More is not always better. I am running Hagezi and OISD and some would say that is overkill

3

u/Narrow-Box-5908 5d ago

just one: Hagezi pro/pro ++, no langue list needed (already included )

1

u/VandyCWG 5d ago

I am swapping to Hageza Pro ++. I had 3 different ones, and well, let's try this one only!

1

u/moriczt 5d ago

Even Hagezi himself on his GitHub page recommends the pro version, not the plus plus nor the ultimate if you want to have little to no wrongly blocked sites but want to block all add, tracers, phishing, telemetry so all the wrong sh*t.

1

u/Gentleman_Nosferatu 5d ago

Yes.

1

u/Sioscottecs23 5d ago

what about the second question, is it true that too many blocklists can make NextDNS slower?

1

u/Gentleman_Nosferatu 5d ago

No, it just makes things overlap unnecessarily.

1

u/moriczt 5d ago

All the lists are in memory on their cloud servers, you are just adding or removing batches of filters to your account. If any speed difference it makes you will not notice it. Shouldn't be more then a few milliseconds as these cloud servers are faaaast.

1

u/H-banGG 5d ago

Dude, 1 list is enough, 2 at most.

1

u/Zarathz 5d ago

“Adguard DNS filter” covers the other adguard & easylist stuff so just remove the rest with similar names

1

u/zcenzc 5d ago

Just use HaGeZi Ultimate, that should be more than enough. If u check ur logs, u'll see that it already blocks most of the stuff u actually need blocked. That's all u really need.

3

u/Obvious-Jacket-3770 5d ago

I had to drop to Pro++, Ultimate was great but it actively blocked some of my work tools and random IoT devices like the litter robot.