Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There's also Quad9 that I saw in an article earlier (not sure if it was on HN).


Quad9 blocks malicious domains by default, which is probably fine for most, but may not be wanted in all use cases.


They also provide 9.9.9.10, which doesn't have a blocklist.

https://www.quad9.net/faq/#Is_there_a_service_that_Quad9_off...


However, 9.9.9.10 does not perform DNSSEC validation, as 8.8.8.8 (Google), 64.6.64.6 (Verisign), 9.9.9.9 (Quad9), and now 1.1.1.1 (CloudFlare) do, so results may not be as trustworthy.


It does.

  $ dig @9.9.9.10 +dnssec +short verisignlabs.com
  72.13.58.64
  A 8 2 3600 20180413202737 20180330202737 31485 verisignlabs.com. KrnT9i6qytaYWDZWThBmBwc6anOmawNxJTxmSlpaY3L7Yfupga9FS70l 8nMVp8ggbEtA+CnS9AbNwObkPaYvk3nFpDvo4C+2hg+PECsP1HVTgGxl G3eblfnYAMNfYzLYlfUnSBgM7kLSIXY4rLBxsl01KiPJYezNhmQ53KYf ygs=


My personal experience is that I had reliability problems that I didn’t have with Google. And DNS is a critical step in the connection for which you really want reliability.


And mine is the opposite. I have not seen reliability problems with Quad9.

Use cases are different - Quad9 for "nasty" filtered and 8.8.8.8 for err probably not filtered.

Do it yourself otherwise.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: