We are spending an incredible/stupendous amount of time on the Internet now because of having to endure Covid-19/Coronavirus/’rona/’vid. As a result, we are definitely at risk of exposing ourselves to more bad things that are on the Internet.
This post should hopefully give you a quick overview of how to provide some additional protection for you, friends, family, anyone/anything connecting to your network.
If you’re a little more technically savvy, you can browse to https://www.dnsperf.com to look at which DNS provider has the best performance for your location in the world.
Cloudflare
IPv4
Normal DNS services
- Primary DNS: 1.1.1.1
- Secondary DNS: 1.0.0.1
Normal DNS Services with Malware Blocking
- Primary DNS: 1.1.1.2
- Secondary DNS: 1.0.0.2
Normal DNS Servers with Malware and Adult Content Blocking
- Primary DNS: 1.1.1.3
- Secondary DNS: 1.0.0.3
IPv6
Normal DNS
- Primary DNS: 2606:4700:4700::1111
- Secondary DNS: 2606:4700:4700::1001
Normal DNS Services with Malware Blocking
- Primary DNS: 2606:4700:4700::1112
- Secondary DNS: 2606:4700:4700::1002
Normal DNS Servers with Malware and Adult Content Blocking
- Primary DNS: 2606:4700:4700::1113
- Secondary DNS: 2606:4700:4700::1003
References
- https://blog.cloudflare.com/dns-resolver-1-1-1-1/
- https://blog.cloudflare.com/introducing-1-1-1-1-for-families/
OpenDNS
IPv4
Normal DNS
- Primary DNS: 208.67.222.222
- Secondary DNS: 208.67.220.220
Normal DNS with Adult Content Blocking
- Primary DNS: 208.67.222.123
- Secondary DNS: 208.67.220.123
IPv6
Normal DNS
- Primary DNS: 2620:119:35::35
- Secondary DNS: 2620:119:53::53
Normal DNS with Adult Content Blocking (requires dual-stack connectivity)
- Primary DNS: ::ffff:d043:de7b
- Secondary DNS: ::ffff:d043:dc7b
Test Websites
- http://welcome.opendns.com – If you are using their service, you’ll see a Welcome to OpenDNS!
- http://www.internetbadguys.com – If you are using their service, you’ll see a “Domain is blocked due to a phishing threat.”
- http://www.exampleadultsite.com – If you are using their service, you’ll see a “This domain is blocked.”
- http://www.test-ipv6.com/ – For testing IPv6 connectivity.
References
- https://www.opendns.com/setupguide/#familyshield
- https://support.opendns.com/hc/en-us/articles/227986567-How-to-test-for-successful-OpenDNS-configuration-
Quad9
(Quad9 will not provide a censoring component and will limit its actions solely to the blocking of malicious domains around phishing, malware, and exploit kit domains.)
IPv4
No Content Filtering, but Malware Filtering
Primary DNS: 9.9.9.9
IPv6
Secure IPv6 Primary: 2620:fe::fe Blocklist, DNSSEC, No EDNS Client-Subnet
Secure IPv6 Secondary: 2620:fe::9 Blocklist, DNSSEC, No EDNS Client-Subnet
Unsecured IPv6 Primary: 2620:fe::10 No blocklist, no DNSSEC,No EDNS Client-Subnet
Unsecured IPv6 Secondary: 2620:fe::fe:10 No blocklist, no DNSSEC,No EDNS Client-Subnet
Secure IPv6 Primary (EDNS): 2620:fe::11 Blocklist, DNSSEC, EDNS Client-Subnet sent.
Secured IPv6 Secondary(EDNS): 2620:fe::fe:11 Blocklist, DNSSEC, EDNS Client-Subnet sent.
Testing?
Try to resolve the hostname isitblocked.org it should resolve to NXDOMAIN.
Other tests that you can perform (from Twitter):
To test what a blocked domain would look like,
try resolving βblocked.test.on.quad9.netβ – that should result in an NXDOMAIN,
while βnotblocked.test.on.quad9.netβ should resolve to 9.9.9.9.
References
- https://quad9.net/
- https://www.quad9.net/faq/
- https://twitter.com/Quad9DNS/status/1212124131346567168
I thought it would be useful to mention that Google doesn’t offering any filtering services through their DNS servers. They believe in providing an unfiltered internet.
IPv4
Normal DNS
- Primary DNS: 8.8.8.8
- Secondary DNS: 8.8.4.4
IPv6
Normal DNS
- Primary DNS: 2001:4860:4860::8888
- Secondary DNS: 2001:4860:4860::8844
| Provider | Description | IPv4 Primary | IPv4 Secondary | IPv6 Primary | IPv6 Secondary |
| Cloudflare | Normal DNS services | 1.1.1.1 | 1.0.0.1 | 2606:4700:4700::1111 | 2606:4700:4700::1001 |
| Cloudflare | Normal DNS Services with Malware Blocking | 1.1.1.2 | 1.0.0.2 | 2606:4700:4700::1112 | 2606:4700:4700::1002 |
| Cloudflare | Normal DNS Servers with Malware and Adult Content Blocking | 1.1.1.3 | 1.0.0.3 | 2606:4700:4700::1113 | 2606:4700:4700::1003 |
| OpenDNS | Normal DNS | 208.67.222.222 | 208.67.220.220 | 2620:119:35::35 | 2620:119:53::53 |
| OpenDNS | Normal DNS with Adult Content Blocking | 208.67.222.123 | 208.67.220.123 | ::ffff:d043:de7b | ::ffff:d043:dc7b |
| Quad9 | Normal DNS | 9.9.9.9 | |||
| Normal DNS | 8.8.8.8 | 8.8.4.4 | 2001:4860:4860::8888 | 2001:4860:4860::8844 |
