outline-server icon indicating copy to clipboard operation
outline-server copied to clipboard

A (way more?) better default DNS

Open c2xusnpq6 opened this issue 3 years ago • 3 comments

I think Outline should set Cloudflare DNS (Firefox user's version) and Quad9 as the default DNS to ensure user's browsing security, instead of OpenDNS.

For more information:

  • https://wiki.mozilla.org/Trusted_Recursive_Resolver
  • https://wiki.mozilla.org/Security/DOH-resolver-policy
  • https://www.quad9.net/service/service-addresses-and-features
  • https://www.quad9.net/service/locations
  • https://www.quad9.net/service/privacy

c2xusnpq6 avatar Jul 10 '22 01:07 c2xusnpq6

Cloudflare (Firefox ver):

https://mozilla.cloudflare-dns.com/dns-query

Quad9 (Malware Blocking, DNSSEC Validation):

https://149.112.112.112/dns-query
https://9.9.9.9/dns-query
https://149.112.112.9/dns-query

Quad9 (Malware blocking, DNSSEC Validation, ECS enabled):

https://9.9.9.11/dns-query
https://149.112.112.11/dns-query

Quad9 (No Malware blocking, no DNSSEC validation):

https://9.9.9.10/dns-query
https://149.112.112.10/dns-query

NextDNS (Firefox ver):

https://firefox.dns.nextdns.io/

c2xusnpq6 avatar Jul 10 '22 01:07 c2xusnpq6

And I suggest you put that HTTPS DNS on Bootstrap DNS too. (Quad9? DNS.SB?)

DNS.SB (Owned by xTom and based in Germany, which is within the EU):

https://185.222.222.222/dns-query
https://45.11.45.11/dns-query

c2xusnpq6 avatar Jul 10 '22 01:07 c2xusnpq6

One more thing, the Firefox version of Cloudflare DNS may reject DNS requests for commercial IPs. (So... Quad9 it is?)

c2xusnpq6 avatar Jul 10 '22 01:07 c2xusnpq6