Settings

Theme

An open DNS recursive service for free security and high privacy

quad9.net

86 points by mooreds · 27 comments

Reader

9 threads
Habgdnv

Just a quick note for the unsuspecting: I run two local DNSes, one recursive and one forwarding. The forwarding one uses few services, like 1.1.1.1, 8.8.8.8, 9.9.9.9, etc. One day I noticed inconsistent responses and started investigating. Turns out that by default 9.9.9.9 have "protection" and for your safety will lie and return NXDOMAIN or something else, for some dangerous domains, taking into account their definition of "dangerous". I am not saying that this is bad, probably lots of non-HN people don't want to run their DNS or anything related and just want a tablet that works because they don't even have laptop. It just hit me hard because I did not expected filtering on these servers.

  • LeoPanthera

    You can use 9.9.9.10, which is unfiltered, or 9.9.9.12, which is unfiltered and passes ECS.

  • drewfax

    That is the point and business of Quad9. It's not their fault for you not knowing what Quad9 is.

    I don't want my family to get malware from sketchy websites. Quad9 offers a simple solution for these usecases. I'll take the false positive anyday over unfiltered DNS.

greyface-

Sending every single query to a centralized third party is hard to square with "high privacy". I prefer to run my own local recursive resolver.

  • ebb_earl_co

    Please correct me if I am mistaken, but unless there’s a local resolver for every single one of your clients, aren’t the DNS requests sent in plaintext to the upstream of your local resolver?

    That might not be an issue for your situation, but I recall the benefit of something like Quad9’s offering is the encryption between client and their endpoint(s), particularly for untrusted ISP or similar.

    • staviette

      Yes, that's a real benefit in many situations. Everything on your lan can do normal DNS queries to your local forwarder, which talks DNS over TLS or DNS over HTTPS to Quad9.

      Downside is Quad9 can see all your DNS traffic. But without it if you run your own recursive resolver your ISP sees all your queries, and many others see portions of them, unencrypted.

      • kayson

        > But without it if you run your own recursive resolver your ISP sees all your queries, and many others see portions of them, unencrypted.

        This hopefully shouldn't be an issue for long with stuff like RFC 9539 and OOTS/SVCB.

  • winstonwinston

    > I prefer to run my own local recursive resolver.

    Used to be fine. I stopped doing it when average TTL dropped to 300 seconds and it takes far too long for my local recursor to get the answer >100ms, when 3rd party resolver delivers in <10ms.

    • pocksuppet

      You don't have to obey TTL. You can use Unbound options like:

          cache-min-ttl: 3600 // seconds
          cache-min-negative-ttl: 3600 // seconds
      
      or

          serve-expired: yes
          serve-expired-client-timeout: 20 // milliseconds to wait for resolution before serving the old value to the client
    • bigstrat2003

      It's still fine. I run my own recursive resolver and have no noticeable issues.

jedberg

I've been meaning to switch my in-laws to Quad9 and just not mention it to them. They fall for too many scams, I'd love for those websites to just not work anymore.

LeoPanthera

In California, from Xfinity Cable, Google’s DNS consistently has the lowest latency.

From AT&T fiber, Cloudflare’s 1.1.1.1 is always the fastest, though Quad9 is a very close second.

It’s interesting that it’s different from different ISPs.

  • jedberg

    Cloudflare probably has a server on AT&Ts network, but not on Xfinity. Google is probably the opposite.

  • doublepg23

    Yup, I get 1-3ms to 1.1.1.1 and 18-20ms to Google from a semi-local fiber provider.

    Definitely blew my mind coming from the ~20ms DOCSIS adds.

  • ButlerianJihad

    https://en.wikipedia.org/wiki/Anycast#Domain_Name_System

      --- 8.8.8.8 ping statistics ---
      10 packets transmitted, 10 received, 0% packet loss, time 9015ms
      rtt min/avg/max/mdev = 23.666/25.241/27.628/1.022 ms
    
      --- 9.9.9.9 ping statistics ---
      10 packets transmitted, 10 received, 0% packet loss, time 9015ms
      rtt min/avg/max/mdev = 23.811/25.256/27.003/1.024 ms
    
      --- 1.1.1.1 ping statistics ---
      10 packets transmitted, 10 received, 0% packet loss, time 9014ms
      rtt min/avg/max/mdev = 13.216/14.553/15.835/0.739 ms
    
    Of course, these ICMP reply times are apples-to-oranges comparisons. With the proper tooling, you should be able to measure DNS reply latencies.
Cider9986

quad9 is recommended by Privacy Guides. There's also other recommendations.

https://www.privacyguides.org/en/dns/#recommended-providers

Linserin

Quad9 DNS sometimes returns a CDN node with obviously slower response and higher delay, so I have rarely used it since then.

annoyingnoob

I tried Quad9 at our business for a while, about a year. I ended up moving to something else due to latency. I'm not sure if it was a routing issue or what but there were a lot of timeouts and slow responses. I have not had these issues with other providers.

  • winstonwinston

    When I run a mix of CF and Quad9 resolvers, Quad9 was consistently slower in response times when measured. But it didn’t make any perceivable difference in real usage.

    • esseph

      > But it didn’t make any perceivable difference in real usage.

      It can, it depends on the systems and user patterns. Example: if an end user is going to the same site over and over, those DNS responses are probably cached locally on the device, and may also be cached on any upstream resolvers. OTOH if you were somebody without a Facebook account that went to Facebook.com to view a post from a link, you could easily have 120 different DNS lookups for various resources on that domain that haven't been DNS or web resource cached yet.

  • jordand

    I'd used NextDNS for a while but the service kept degrading with more timeouts regardless if you were on free/paid. Haven't had any issues with Quad9

woadwarrior01

What are the odds that it's a honeypot?

sbseitz

Downvote.*, holy old.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection