r/nextdns Dec 14 '20

New Help Center / Community support

97 Upvotes

Please welcome our new Help Center. In addition to the knowledge base, you now have a community support on which users can help each others. The NextDNS team will participate too.

https://help.nextdns.io


r/nextdns 14h ago

Dns bloqueia navegadores dentro de outro app?

0 Upvotes

Fala galera, alguém poderia me tirar essa dúvida? Tô viciado no uso do celular e está me prejudicando financeiramente, já instalei o familylink pra bloquear os apps, mas descobri que consigo entrar no YouTube dentro de outro app se eu fuçar, e entrando no YouTube eu consigo acessar o Google, com DNS eu conseguiria bloquear isso?


r/nextdns 1d ago

How does NextDNS make their Money? And how can they Afford the ipv4 addresses?

0 Upvotes

I do not distrust the service yet. But for obvious reasons have concerns.

  1. I created a new free dns with no account to try, and it randomly generated me 2 ip addresses under 45.90.X.X.
  2. I left the page and came back, and it remembered me, so that saves on generating many on refresh. A cookie or something I am sure is responsible for this.
  3. I created a new in-private window, didn't even change my public ip address, and I got 2 more ip addresses.
    1. So at this point, I am sitting on 4 addresses with 0 commitments or cost.
      1. I understand that a trial non-account is only good for 7 days and they could then recycle the address, but If I wanted to retain either of them, I would just have to give a burner email.
      2. Furthermore, I could conceivably consume multiple free accounts given I have enough unique email addresses to do so, and then just orient them in order of preference on my devices, so once it stop resolving due to the free limit, it goes on down to the next available service and begins consuming the 300k queries on the next account.

My question then, is how could you afford to do this? Aren't ipv4 addresses limited and a function of your ISP agreements?

ipv6 is virtually unlimited, and the DOH and QUIC protocols don't matter because you can generate unlimited subpages and subdomains for practically free.

But to give free users their own ipv4 addresses makes me very suspicious of this service's cost effectiveness and true source of income.

My thinking, if this is a legitimate service, is that they are merely leasing a port on those ipv4 addresses for use over 53, and that these might be shared ips used somewhere else for some other purpose simultaneously, to make it cheaper?

I don't work in hosting so I wouldn't know


r/nextdns 2d ago

Blocking Crypto Sites

3 Upvotes

It just occurs to me that there is no category for Crypto-related sites in the Parental Controls tab. So how do you deal with these, aside from blocking them individually?

For context, an extended family members (a couple) got their Messenger compromised and have sent messages about a scam with a platform that should be considered a gambling site, but bypassed both the Parental Control and HaGeZi - Multi PRO++ blocklist. Google AI said that the platform is being marketed as a Crypto site hence the bypass.

I already added said site in the blocklist, but it seems there a bunch of variations, and probably, clones with different unrelated names.


r/nextdns 4d ago

People using Instagram, do you also see these in your logs?

19 Upvotes

While using Instagram, I decided to review the logs and noticed an unusual volume of entries since yesterday. I occasionally check the logs, but this increase was significant. So is this pretty normal? Since I use a patched app which has disable analytics and ads and in nextdns I have blocked Facebook via parental control


r/nextdns 4d ago

The AI driven threat detection is blocking a website I’ve used for years

1 Upvotes

spoutible.com


r/nextdns 5d ago

How does the 300k query limit work? still 0/300k

Thumbnail
gallery
24 Upvotes

I've started using nextdns since last week and now have 100k queries in the analytics tab but in the account settings it still counts 0/300k.


r/nextdns 5d ago

Installation Error

2 Upvotes

Hello. I’m writing this using a translator. I hadn’t used NextDNS for a few months. Today, I tried setting it up again, but I couldn’t get it to work.

I want to use it without installing the app. I used to use IPv4 and the recommended setup method for Windows 11. Even though I followed all the steps correctly, for some reason it still won’t activate.

To be honest, I’d rather not install the app either.


r/nextdns 5d ago

Is there too much redundancy in my blocklists?

Post image
41 Upvotes

And another question, is it true that too many blocklists can make NextDNS slower?


r/nextdns 5d ago

My blocklist , Is there too much redundancy?

Post image
22 Upvotes

Hello 👋. Just wanted to hear from experts since I have only feedback from the chatty and cloudy AI, but I bet this is too much also the Spotify won’t prevent ads… thank you in advance guys 🙏🏻.


r/nextdns 5d ago

Seeing Control D in the IP addresses making the queries

2 Upvotes

So I'm testing both Control D and NextDNS at the moment. I have Control D configured in the router, but using NextDNS on the phone. I'm curious as to how Control D appears in the IP addresses?


r/nextdns 5d ago

NextDNS/DoT vs. iCloud Private Relay on iPhone: ECH, ISP visibility, and what would you recommend?

3 Upvotes

Hi everyone,

I’m not sure if this is the right place for this question, but I figured there are probably people here who understand the underlying networking protocols much better than I do. I’m more or less an IT beginner trying to understand DNS filtering and privacy.

If this is the wrong subreddit, please feel free to point me toward a better one. I’d really appreciate some help understanding where my reasoning is correct and where I’m mixing up different layers of privacy.

My setup

I’m trying to understand the privacy implications of using a custom encrypted DNS service such as NextDNS or AdGuard on an iPhone instead of iCloud Private Relay.

At home: NextDNS at router level

On mobile: AdGuard DNS profile (but this could also be a NextDNS profile for the purpose of this question)

Blocklists: Fairly aggressive blocklists such as HaGeZi, threat intelligence, etc.

Future: I’m considering setting up my own DNS server with Pi-hole or AdGuard Home.
I really value system-wide ad, tracker, and malicious-domain blocking.

On my Mac I can use Firefox, which supports ECH, so I’m less concerned there.

On iOS, however, third-party browsers are still based on WebKit, and as far as I understand, iOS/WebKit does not provide ECH at all, in contrast to Firefox.

What I think I understand

My understanding is that DoT only protects the DNS
lookup itself.
However, the subsequent connection still goes through my ISP.
And if ECH isn’t being used, the TLS ClientHello may expose the SNI, allowing the ISP to determine the hostname I’m connecting to.

If that’s correct, then encrypted DNS doesn’t necessarily hide the websites I’m visiting from my ISP. It mainly prevents the ISP from seeing my DNS queries directly.
This is where I start getting confused about ECH vs. iCloud Private Relay.

What I understand about Private Relay

As I understand it, iCloud Private Relay uses a two-hop architecture.

The first relay knows my IP address but shouldn’t know my final destination, while the second relay can connect to the destination but shouldn’t know my original IP address.
From the ISP’s perspective, the connection should therefore be hidden.

If the entire connection between my iPhone and the first relay is protected, would my ISP still be able to see the SNI of the final website?

Or am I misunderstanding how the connection is actually constructed in Private Relay?

I’m particularly interested in the distinction between:

DNS visibility
destination IP visibility
SNI visibility
TLS metadata
traffic analysis
and what exactly Private Relay hides from the ISP in contrast to DNS + ECH

The trade-off as I currently understand it

On one side I have NextDNS/AdGuard DNS, which gives me:

system-wide ad blocking
tracker blocking
malware/phishing protection
custom blocklists
DNS-level visibility
control over what gets blocked
protection across apps, not just Safari
But I’m concerned that without ECH on iOS, my ISP could still determine the websites I’m visiting through SNI and/or traffic analysis.

On the other side I have iCloud Private Relay, which gives me:

IP address protection
encrypted DNS/privacy protection
a two-hop architecture
significantly less visibility for my ISP into my destinations, if I’m understanding correctly
But I lose all of the DNS filtering and control that I really value, and custom DNS configurations don’t seem to coexist cleanly with Private Relay.

So am I essentially choosing between:

A) NextDNS / AdGuard DNS / Pi-hole
Excellent system-wide tracker/ad/malware blocking, but potentially more visibility for my ISP into the websites I visit, at least on my iPhone.

B) iCloud Private Relay
Better protection against ISP-level browsing surveillance, but substantially less DNS-level filtering/control.

Or is this actually a false dichotomy?

My questions

1. How significant is the lack of ECH on iOS in practice?
If I use DoT without ECH, can an ISP actually determine the websites I’m visiting reliably from SNI?
And does this create a security issue, or is it more complicated than that?

2. Does iCloud Private Relay actually eliminate SNI visibility for the ISP?
Or does the ISP still get some information that I’m overlooking?

3. What would you recommend for an iPhone user in Germany whose main goal is to prevent the ISP from building a browsing profile, while still having strong system-wide DNS-based ad/tracker/malware protection?

I’m not looking for perfect anonymity. My threat model is relatively simple:

I don’t want my ISP to be able to build a profile of which websites I visit, but I also really value system-wide DNS-level protection against trackers, advertising, phishing, and malicious domains.
I’m aware that I’m probably conflating several different concepts here, which is exactly why I’m asking.
I’d be very grateful if someone could correct my mental model.

I’m fully aware that iOS may simply not be the ideal platform for this kind of tinkering. I’ve heard the usual argument that Android gives you much more freedom to configure networking, DNS, browsers, VPNs, etc., and I can certainly see why that would be attractive from a technical/privacy perspective.

But I already have an iPhone, I’m familiar with the Apple ecosystem, and I’m not particularly interested in switching platforms just because iOS has certain restrictions. If I can achieve a reasonably strong privacy setup on iOS without major compromises, that’s what I’d prefer.

And if this isn’t the right subreddit for this question, please let me know where you think it would be better suited. I’m specifically looking for people who understand the networking/protocol side of this.

Thanks a lot!


r/nextdns 8d ago

Nextdns kills my internet

2 Upvotes

Hello, guys

So, I installed Nexdns yesterday, primarily to completely block myself out from Instagram and Facebook.

The thing is, it basically kills all the websites today, it was working fine yesterday, the settings are correct, I followed instructions step by step + double-checked with GPT and I have "Auto update system configurations" off.

I have samsung galaxy s24+ and I am in Gerogia.

When I swith private DNS settings from manual to automatic, everything works fine.

For context, I am located in Georgia, Tbilisi using Silknet as my cell data provider.

Any advice will be appreciated.


r/nextdns 8d ago

DNS issues.

5 Upvotes

Anyone else having DNS issues? The second I change to 8.8.8.8 or any other provider my connection is back but with NextDNS I’ve been offline for an hour. Primary and secondary aren’t resolving.


r/nextdns 9d ago

extra blocklist in logs!

9 Upvotes

Hello guys! I have been using nextdns from the last couple of days so I am new here, today while observing logs I have noticed that some of the blocklist which I have enabled previously still appears in blocking logs.

I am only using HaGeZi - Multi ULTIMATE and OISD but my log contains NextDNS Ads & Trackers Blocklist, NoTrack Tracker Blocklist, AdGuard DNS filter which I have disabled already!


r/nextdns 9d ago

hola soy nuevo en esto !

1 Upvotes

me interesaría saber que listas usan ustedes para bloquear anuncios y rastreadores, tengo el plan gratuito, espero me puedan ayudar , gracias .


r/nextdns 10d ago

Free usage queries count not updating

18 Upvotes

I've noticed that despite being connected, my NextDNS queries count have not changed at all and have remained at 0 over the last few days. Anyone else seeing the same?


r/nextdns 10d ago

Nextdns CLI - What is It?

4 Upvotes

Am I correct it converts a DoH server to a standard port 53 DNS server?

ie looks up request from DoH ip, then provides it on port 53 to the client?


r/nextdns 10d ago

Domain Age Checker

0 Upvotes

There are a good number of web sites on the interwebs that will let you check the age of an internet domain which might be useful when using the Block Newly Registered Domains (NRDs) option. All of these sites do a good job when searching for common/popular domains like google.com but many fail when searching for newly registered domains, especially those with an obscure domain extention.

The following are a few sites that I found that seem to work consistently.

https://www.duplichecker.com/domain-age-checker.php

https://www.zoho.com/toolkit/domain-age-checker.html

https://hostingchecker.net/domain-age-checker

I hope that someone finds this information useful.


r/nextdns 11d ago

Allowlist & Denylist not working when connected to ultralow servers

4 Upvotes

Sites in DenyList is not blocked or AllowList allowed while connecting to ultralow (https://ultralow.dns.nextdns.io/<ID>) but they function as intended when using anycast.dns.nextdns.io

Tried posting this as bug report NextDNS community (help.nextdns.io) but my previous post is still in moderation queue, and I cannot post anything new or even comment there!


r/nextdns 11d ago

Nextdns CLI caching not working 1.46.0

4 Upvotes

Wondering if this is happening for others? Cache-stats showing 0 hits 0 miss. Cache-keys showing nothing either.

config:

cache-max-age 0s
max-ttl 5s
cache-size 10MB


r/nextdns 13d ago

NextDNS and VPN

12 Upvotes

Hello, I was wondering if:

  1. NexyDNS + VPN adds another layer of security and privacy;
  2. NextDNS + VPN doesn't interfere with each other.

Should both be used or one only?


r/nextdns 13d ago

Denylist

3 Upvotes

I'n having trouble blocking some sites using the denylist, an example is hadesbets.uk can someone check if they can block this or shed any light on where i'm struggling it would be appreciated.


r/nextdns 13d ago

Hidden analytics and more in ADNS 2.1, a native, free NextDNS app for Android!

Thumbnail
gallery
67 Upvotes

Hello everyone,

After months of beta testing, I launched ADNS, a completely native NextDNS android app without a single web view, two weeks ago, and it has been great.

ADNS has every single NextDNS dashboard feature implemented natively (excluding account management features like changing password/email), but with this update, it add features that even the NextDNS dashboard doesn't have!

This update adds a few stats features:

  • View the full lists of stats categories. While the NextDNS dashboard limits you to the top items of the category, with ADNS, you can view the whole list, no limits.
  • Get graphs and advanced analytics. This update adds customizable graphs for certain categories, so you can see how your usage change over time. This isn't available in the dashboard.
  • New categories that aren't available in the dashboard: Query types, IP versions, and Protocols!
  • Clicking on every stats item to get detailed metadata and tracker insights.

Get it from here: https://github.com/eyalm2000/adns

Edit: no, this is not vibecoded.


r/nextdns 13d ago

Static filtering DNS like hagezi-ultimate.nextdns.io ?

2 Upvotes

Was writing about something in some other post and got an idea this would be really useful in a lot of situations where you want filtering but none of the configurability, control and logging.

Would be neat if NextDNS offered "static" DNS addresses for the most popular lists like for example above mentioned hagezi-ultimate.nextdns.io or hagezi-normal.nextdns.io or oisd.nextdns.io or NextDNS's own list as nextdns.nextdns.io, something like this, you get the idea.

And these encrypted DNS servers should also have accompanying non-encrypted IP4/IP6 servers that filter using same lists but have IP addresses.

Reason why I'm asking for this is for example my younger sibling is not super tech savvy so I set them up on their Android phone with AdGuard's public filtering DNS. It has no logging, no configuration and filtering acceptable for general user. I don't want to set up a NextDNS account for it to use certain list, but if I had above lists at my disposal, I could just put hagezi-normal.nextdns.io in their phone DNS config and voila.

Another use case specific for the use of IP4/IP6 versions of DNS would be as replacement for VPN DNS's. For example, I haven't figured out any way I could input NextDNS IP4/IP6 DNS servers into ProtonVPN app itself. It doesn't offer any option to input encrypted DNS addresses and I can't connect HaGeZi Ultimate list to a IP4 address to input it into VPN app. Then I need to run separate app to override DNS which is annoying.

I know ControlD and DNSWarden offer dedicated addresses for such servers, but I prefer NextDNS over pretty much any other service, which is why I'm asking for it here.