Hello!
My knowledge about DNS resolvers is somewhat limited. So, in an effort to expand my knowledge and find a DNS resolver that works for me, I’ve come for help here.
Here is a list of terminology that I either know too little about, don’t know anything about, or want to make sure my understanding is correct about:
Cleartext (What does this mean in the context of protocols? Is it inherently bad?)
DoH (I somewhat understand this, but is it less secure than DoT?)
DoH/3 (How is this different from DoH?)
DoT (Is this more private than DoH?)
DoQ (I don’t know enough about this, how does it compare to DoH and DoT?)
DNSCrypt (I’m not sure what this is.)
Do53 (I’m not sure what this is. Is it a replacement for DoH/DoT/DoQ, or does it work alongside it?)
DNSSEC (I don’t know what this is.)
EDNS padding (I’m pretty sure I know what this is, it just pads DNS queries. What happens if “Cleartext” is used, does it still pad it?)
As for what I’m looking for in a DNS resolver: I don’t plan to self host it, I would like support for iOS, Linux, and Android, I would like it to be free, I would like EDNS padding, DoH is preferred (although I don’t quite understand the alternatives). I am aware that the DNS resolver will usually be the same as my VPN. Note: I’m not looking for a beginner DNS resolver, I’ve been using NextDNS for a while now, I’m looking for one with strict privacy and security.
I’ve tried looking at Privacy Guides and Wikipedia, but I don’t know enough to make an educated decision.
Any suggestions?
Thank you all!
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
[Matrix/Element]Dead
much thanks to @gary_host_laptop for the logo design :)
Mullvad has a public DNS service, would recommend checking that out. Supports DoH, DoT, and is encrypted.
I tried Mullvad’s DNS service and found that it messed up sites that rely on geography based DNS routing. For example, I’d get sent to a service’s servers in Singapore instead of the US. This caused some noticeable lag.
I second Mullvad as a service.