FYI about VPNs, they encrypt unencrypted traffic only part of the way. Everything is still unencrypted between the VPN server and the server you are connecting to. Just thought I’d say this because a lot of VPN ads are very misleading about this.

@Express_pickle@sh.itjust.works
creator
link
fedilink
1
edit-2
2M

deleted by creator

Contrary to common believe, iCloud Private Relay and NextDNS are compatible and can both be enabled at the same time, see page 10 of https://www.apple.com/icloud/docs/iCloud_Private_Relay_Overview_Dec2021.pdf. When you try to visit a blocked hostname in Safari, you’ll see that it won’t work. This is something that I’ve personally confirmed.

What NextDNS solves and iCloud Private Relay doesn’t, is blocking hostnames system wide, thereby completely blocking some ads and tracking. What iCloud Private Relay solves is hiding your browsing traffic a bit better within your local network and from your ISP, as well as hiding your IP from trackers and hiding your identity from their DNS resolver (not from NextDNS, though).

Some background information why using HTTPS together with encrypted DNS doesn’t fully hide which websites you visit (yet): https://blog.cloudflare.com/announcing-encrypted-client-hello.

If I had to choose, I’d go with NextDNS for system wide blocking and I’d add an adblocker browser extension to block trackers and ads that can’t be blocked with DNS based blocking. But you don’t have to choose and can use both at the same time.

@Express_pickle@sh.itjust.works
creator
link
fedilink
1
edit-2
2M

deleted by creator

So for some reason Apple keeps using their DNS resolver even with a custom DoH resolver configured, but in my testing it didn’t affect the blocking capabilities of NextDNS at all, meaning that the answers from their resolver are just ignored (or used for some other purpose). The way NextDNS knows that you’re using another resolver is by letting the browser resolve some unique hostnames, so that way it will show up even if the answers from that resolver aren’t used. As to why Apple does this I don’t know. In theory it could be the case that Apple just used whichever answer arrives first and that NextDNS just happened to be faster in my testing, but that doesn’t match with how it’s documented in their PDF.

Which one to pick (if you don’t just want to use them at the same time) depends on what your goal is. I use iCloud Private Relay + NextDNS + AdGuard, but nowadays I mainly use another browser with a built-in adblocker, so iCloud Private Relay and AdGuard aren’t used in that case.

I use NextDNS everywhere I can and use a list that prioritizes not breaking anything. It’s a nice backstop. It’s not a replacement for an in-browser adblocker in my opinion, unless you don’t care that it’s less effective.

@Express_pickle@sh.itjust.works
creator
link
fedilink
1
edit-2
2M

deleted by creator

If the iCloud Private Relay ODoH DNS server is used it will show up as a DNS leak, even if the IP address from its response isn’t used for browsing. For privacy it doesn’t matter, as with ODoH the DNS resolver doesn’t know your IP or identity, the most important thing is whether it will bypass the NextDNS blocklist. In my testing I couldn’t visit any website that was blocked by NextDNS, meaning that the iCloud DNS resolver wasn’t used as the primary DNS resolver, which matches with their documentation (that page 10 that I linked to earlier). Note that Apple will only use a custom DNS resolver if you’re using the native DoH option, so for example the configuration that you can get from https://apple.nextdns.io/.

You can easily test it yourself: block a hostname in NextDNS that you haven’t visited recently (due to cache) and try to visit it in Safari.

I don’t know why Apple still uses the Cloudflare DNS resolver even if it seems to be ignoring its responses. Maybe they use it for some custom metadata that’s sent along with the request which somehow is important for the relay. All I know is that I’ve never seen it bypassing the NextDNS blocklist, which again is exactly how it’s documented by Apple.

@Express_pickle@sh.itjust.works
creator
link
fedilink
1
edit-2
2M

deleted by creator

I’m not sure, it depends on your configuration and blocking list. I don’t use native tracking protection, and my blocklist (oisd) prioritizes functionality over blocking, so in my case everything just works and I don’t have anything special added to my whitelist. I don’t like DNS blocking to be in the way and I also share my configuration with some family members, so that’s why I’ve made this choice, but if you prefer a stricter approach you might have to do some whitelisting.

Just know that one of THE blocklist creators, HaGezi, dropped his recommendation for Nextdns because of the bad support. I still use Nextdns but I’m moving to another DNS provider.

why dropped? do you have link to the reason?

@Express_pickle@sh.itjust.works
creator
link
fedilink
1
edit-2
2M

deleted by creator

control d. I have been testing for about 24 hours now and it resolves fast. I’m going to keep using both for at least a month before I decide.

@Express_pickle@sh.itjust.works
creator
link
fedilink
1
edit-2
2M

deleted by creator

I use NextDNS and I do have a subscription, currently using it on my router via DNS over HTTPS.

It is an excellent service (like a Pi-Hole on cloud) and I like how it does things like logging and analytics.

For using it in iOS you shouldn’t need to use the app, just install a (signed) profile via apple.nextdns.io and it will be configured natively (this is Apple’s approved way to use 3rd party private DNS).

I use this profile method and just made an exception to my home & work wifi network but will always use it otherwise (on mobile network or any other wifi networks)

@Express_pickle@sh.itjust.works
creator
link
fedilink
2
edit-2
2M

deleted by creator

the nextdns app hasn’t been updated for about 3years on iOS

probably because it doesn’t require an app to set up: https://apple.nextdns.io/

@Express_pickle@sh.itjust.works
creator
link
fedilink
1
edit-2
2M

deleted by creator

Create a post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

  • 0 users online
  • 57 users / day
  • 383 users / week
  • 1.5K users / month
  • 5.7K users / 6 months
  • 1 subscriber
  • 2.47K Posts
  • 58.8K Comments
  • Modlog