Advice Request Best practices for setting up a new router: single vs multi-band SSID & firewall security level?

Please provide comments and solutions that are helpful to the author of this topic.
I haven't installed YogaDNS yet, and I haven't manually adjusted my device's DNS settings. The result below is entirely dependent on the router settings, which show that DNS changes are effective. 😊

Control D Troubleshooting - Mon, 03 Aug 2026 14:52:27 UTC
-----------------------------------------------------------------
IPv4 ISP | 8376 (Orange Jordan, JO)
IPv6 ISP | 8376 (Orange Jordan, JO)
Using Control D | No
Resolver | N/A
DNS Protocol | N/A
Approx. DNS Latency | 78ms
DNS Host | cdg-h10
Proxy Authorized | No
Null Routed | No
Approx. Proxy Latency | 92.42ms
Proxy Host | ams-pxy51

And this is my DNS speed test result based on the control D speed test.

View attachment 299209

Below are the test results.

View attachment 299210
Thanks! Your ISP has horrible routing. Instead of being routed to Control D servers in Bucharest (which is closest to you), your ISP routes you to their servers in Paris. Control D used to offer a server in Istanbul, but they got rid of it as it was often down and had terrible hardware.

AdGuard has servers in Istanbul, and yet, you have even worse ping than with Control D. In the end, your best bet is Cloudflare over DoQ. If you want ad blocking DNS, your best bet would be Control D but you'd need to contact Control D support and report routing issue.
 
I haven't installed YogaDNS yet, and I haven't manually adjusted my device's DNS settings. The result below is entirely dependent on the router settings, which show that DNS changes are effective. 😊

Control D Troubleshooting - Mon, 03 Aug 2026 14:52:27 UTC
-----------------------------------------------------------------
IPv4 ISP | 8376 (Orange Jordan, JO)
IPv6 ISP | 8376 (Orange Jordan, JO)
Using Control D | No
Resolver | N/A
DNS Protocol | N/A
Approx. DNS Latency | 78ms
DNS Host | cdg-h10
Proxy Authorized | No
Null Routed | No
Approx. Proxy Latency | 92.42ms
Proxy Host | ams-pxy51

And this is my DNS speed test result based on the control D speed test.

View attachment 299209

Below are the test results.

View attachment 299210
Use ControlD for a few days and see how it performs.
 
@lokamoka820 @Parkinsond You can contact Control D support (they reply within a day) like they described here. I did few months ago because one Croatian ISP routed users to Amsterdam instead of Frankfurt which resulted in over 50ms latency. Within a week they raised the issue with the ISP which then normally started to route to Frankfurt.
 
@lokamoka820 @Parkinsond You can contact Control D support (they reply within a day) like they described here. I did few months ago because one Croatian ISP routed users to Amsterdam instead of Frankfurt which resulted in over 50ms latency. Within a week they raised the issue with the ISP which then normally started to route to Frankfurt.
I've just sent the email, thank you for your assistance.
 
If you have any questions, feel free to ask. I was suspicious of YogaDNS at first because it's closed source. But it turns out many DNS services actually recommend it and NextDNS uses it as their official client. Privacy policy is also simply and clearly written so I had no reason not to trust it. Turns out it works better than Control D Setup Utility which gave me headaches and limited me to slow DoH.
I installed YogaDNS but I'm not sure which options to choose since I'm unfamiliar with all these protocol types. However, I ran a test by importing the providers, and the results are shown in the screenshots.

2026-08-08 03_25_52-Import servers from the web.png2026-08-08 04_56_28-Import servers from the web.png
 
I installed YogaDNS but I'm not sure which options to choose since I'm unfamiliar with all these protocol types. However, I ran a test by importing the providers, and the results are shown in the screenshots.

View attachment 299289View attachment 299290
So what you got here is list od DNS servers that come with YogaDNS and it's asking you to select DNS server you want. You don't have to do it this way. You can close this window and add server manually as well as choose protocol of your liking.

Open YogaDNS main window, then click on DNS Servers in the top left of the window. Then click on Add and here's where you add your desired DNS server. Type is DNS protocol you want to use. My recommendation is either DNS-over-QUIC or DNS-over-HTTPS/3 with DNS-over-QUIC being the fastest and DNS-over-HTTPS/3 closely following. Regular DNS-over-HTTPS and DNS-over-TLS are quite slower to those two so if you want the fastest DNS response time, choose one of first two I mentioned.

IP address field is bootstrap DNS or an IP address which will only be used to resolve DoQ or DoH/3 hostname. Enable DNSSEC supported (make sure there's checkmark). And under Hostname goes the DoQ/DoH3 hostname of your DNS server. Once you're done click OK and you can check using dnscheck.tools if DNS servers are properly configured and if there is some kind of DNS leak.

Here's how it's configured on my PC:

Screenshot_1.png


There's also Rules part which allows you to select which domain or network interface will/won't go through selected DNS servers, I just left this on default so everything goes through Control D.

Screenshot_2.png


Did Control D support get back to you? What did they tell you regarding latency?
 
Last edited:
I haven't received a reply from Control D yet. What DNS server would you recommend for my location to use with YogaDNS?
If you want simple ad blocking DNS, Control D is the answer despite higher latency. Its Hagezi Pro/Pro Plus resolvers do a great job blocking ads and tracking with none breakage. If you want uncensored, private and fastest DNS, you should set up Cloudflare 1.1.1.1 or 1.1.1.2 if you want protection from malware.

I say try with Control D for a few days, see how it behaves. If it slows down surfing the web, go with Cloudflare at least until support contacts you regarding the latency issue. In both cases, Set it up using DNS-over-DoQ. If it doesn't work (ISPs in countries with censored internet might block UDP port 853 necessary for it to work), then choose DNS-over-HTTPS/3 as it's much harder to block.
 
Last edited:
If you want simple ad blocking DNS, Control D is the answer despite higher latency. Its Hagezi Pro/Pro Plus resolvers do a great job blocking ads and tracking with none breakage. If you want uncensored, private and fastest DNS, you should set up Cloudflare 1.1.1.1 or 1.1.1.2 if you want protection from malware.

I say try with Control D for a few days, see how it behaves. If it slows down surfing the web, go with Cloudflare at least until support contacts you regarding the latency issue. In both cases, Set it up using DNS-over-DoQ. If it doesn't work (ISPs in countries with censored web might block UDP port 853 necessary for it to work), then choose DNS-over-HTTPS/3 as it's much harder to block.
Do I simply need to copy the settings from your screenshots and that’s it?
 
  • Like
Reactions: Sorrento
@Marko :) Is this error log normal or is it a false positive? I'm using Control-D's malware protection DNS.

View attachment 299327

I ask because there are entries for Microsoft, Firefox, Mega, Lenovo, and others, but I don't use any tracking protection filters unless the malware filter has one by default.
Is log full of those? If yes, then something isn't right. It seems HTTP3 traffic is blocked sometimes.

Are you using DoQ? If so, switch to DoH3. I barely get any reds, only when I cancel the reauest.
 
Is log full of those? If yes, then something isn't right. It seems HTTP3 traffic is blocked sometimes.
Yes, that is correct, though I am unsure whether it is due to the DNS service provider or the protocol used. For instance, I did not encounter any errors with NextDNS on YogaDNS, and the logs are also clean of errors when using Mullvad DNS. 🤷‍♂️
Are you using DoQ? If so, switch to DoH3. I barely get any reds, only when I cancel the reauest.
I tried using DoQ as well. When I check it through YogaDNS, it shows faster performance, but it produces "timeout" errors rather than the connection errors I experienced with HTTP/3.

Anyway, I'm really impressed by the experience and want to learn more about DNS servers. Before starting this thread, all I knew about DNS was Cloudflare and Google, along with the idea that I should select the fastest one for a smoother web experience. Currently, I'm testing various DNS services. While results on dnscheck.tools vary—sometimes showing high numbers with yellow and red indicators, or even errors—I notice no lag when browsing daily. I want to learn how to properly test and determine the best service for my needs, or find out if those tests are just theoretical and don't reflect real-world performance.

I tested my download and upload speeds on Speedtest.net, and they ranged from 140–190 Mbps for download and 130–170 Mbps for upload across different services, so I'm not sure if I should be concerned about this variation.

By the way, I'm currently using these services and appreciate that YogaDNS allows me to switch between them with a single click.

1786457600025.png

Today's Mullvad DNS test shows a clean log so far.

1786457678942.png
 
@Marko :) Is this error log normal or is it a false positive? I'm using Control-D's malware protection DNS.

View attachment 299327

I ask because there are entries for Microsoft, Firefox, Mega, Lenovo, and others, but I don't use any tracking protection filters unless the malware filter has one by default.
Can you test DoH of ControlD and see if you see these errors also? ControlD's DoH/3 and QUIC doesn't work most of the time for me. Maybe it's an issue with some of their PoP in some regions. DoH and DoT are more stable.
 
I just noticed that even with Mullvad DNS, I encounter some errors, but they all occur at three specific times. I'm not sure what I was doing at 17:51 and 18:47, but 19:54 is when I opened my laptop lid, causing it to wake from sleep. I'm still wondering about this, as I didn't experience any slowdowns or other issues. 🤔

1786468667964.png
 
Yes, that is correct, though I am unsure whether it is due to the DNS service provider or the protocol used. For instance, I did not encounter any errors with NextDNS on YogaDNS, and the logs are also clean of errors when using Mullvad DNS. 🤷‍♂️

I tried using DoQ as well. When I check it through YogaDNS, it shows faster performance, but it produces "timeout" errors rather than the connection errors I experienced with HTTP/3.
Test DoQ with Cloudflare. If it doesn't have the same entries in the log, it's Control D's fault (support could help). If it's the same, it's most likely your ISP messes with the port or something on your PC causes DoQ to misbehave. DoH3 might help with that.

The reason why I also recommended you DoH3 is because it's essentially the same as DoQ. The only difference is it doesn't use dedicated 587 port and instead uses 443 port also used for regular HTTP/3 and HTTPS traffic, meaning it's much harder to block than DoQ. To break DoQ, you only need to block port 587. To block DoH3/DoH, you need to block 443 and as a result you also blocked all HTTPS websites.
Anyway, I'm really impressed by the experience and want to learn more about DNS servers. Before starting this thread, all I knew about DNS was Cloudflare and Google, along with the idea that I should select the fastest one for a smoother web experience. Currently, I'm testing various DNS services. While results on dnscheck.tools vary—sometimes showing high numbers with yellow and red indicators, or even errors—I notice no lag when browsing daily. I want to learn how to properly test and determine the best service for my needs, or find out if those tests are just theoretical and don't reflect real-world performance.
dnscheck.tools sometimes also varies for me too. Usually it's ranging from 28 to 40 ms, but sometimes it goes up to 80 ms. I'm assuming has something to do with the browser, not necessarily DNS server itself because once I restart Firefox, DNS response time goes back to normal.

Open the browser console when doing the test on dnscheck.tools; there you get exact measurements of response time along with the tested domains. Bottom corner is supposed to show average.

The best choice depends on what you need from DNS really. After years of using Cloudflare, I wanted to try DNS with ad blocking capability. Control D checked all the boxes for me. It's free, unlimited and offers variety of options even for free users which I really appreciate. I stopped using AdGuard Public DNS because it left me without internet access when their anycast stopped working. Beside, Control D with Hagezi blocklists blocks way more than AdGuard Public DNS does with their default DNS filter.
After starting using Control D with Hagezi Pro Plus on my phone, I noticed battery life increasing as lots of unnecessary requests simply end up in the sinkhole.

If all you need is fast, private and uncensored DNS, Cloudflare is no brainer. If you want DNS with ad blocking capability without wanting to spend money on customizable DNS services, Control D is clearly the answer. If you want DNS with malware protection only, Cloudflare's 1.1.1.2 or Quad9.
I tested my download and upload speeds on Speedtest.net, and they ranged from 140–190 Mbps for download and 130–170 Mbps for upload across different services, so I'm not sure if I should be concerned about this variation.
DNS actually doesn't have any effect on the internet speed at all. All DNS does is translate domains to IP addresses and that's it. In simpler terms, its only job is whenever you type malwaretips.com to find corresponding IP address of the server hosting it, nothing else. It's also worth to note that DNS doesn't work all the time. Once you request malwaretips.com, the response is saved in DNS cache for some time. DNS is only queried if you don't already have the domain tied to corresponding IP address in cache, or if the cache entry expired.

When we're talking about DNS response time, we're talking about time DNS server took to find the IP address of the server for corresponding domain, not how fast website loaded. And while it doesn't have any effect on how fast website assets will be downloaded from the server, ad blocking DNS might improve your website loading times in terms of simply rejecting domains that are present in the blocklist used.
By the way, I'm currently using these services and appreciate that YogaDNS allows me to switch between them with a single click.

View attachment 299348
That works until trial is active. Free version is limited to one DNS server only which should be enough for you once you choose your provider of choice.
Today's Mullvad DNS test shows a clean log so far.

View attachment 299349
It's clear because you haven't sent any DNS requests yet so it has nothing to show. Try loading some website in the browser, DNS requests will appear.
I just noticed that even with Mullvad DNS, I encounter some errors, but they all occur at three specific times. I'm not sure what I was doing at 17:51 and 18:47, but 19:54 is when I opened my laptop lid, causing it to wake from sleep. I'm still wondering about this, as I didn't experience any slowdowns or other issues. 🤔

View attachment 299355
I assume this was YogaDNS logging the requests while device was asleep. Because there isn't internet access during sleep, DNS requests failed. That could also explain why it happens immediately when you wake up PC from sleep. YogaDNS showing you requests that failed.
Can you test DoH of ControlD and see if you see these errors also? ControlD's DoH/3 and QUIC doesn't work most of the time for me. Maybe it's an issue with some of their PoP in some regions. DoH and DoT are more stable.
I'm connected Frankfurt and it works exceptionally well every since they switched provider from NetActuate to DataCamp. Using DoQ.

Screenshot_1.png
Screenshot_2.png
 
Last edited:
If all you need is fast, private and uncensored DNS, Cloudflare is no brainer. If you want DNS with ad blocking capability without wanting to spend money on customizable DNS services, Control D is clearly the answer. If you want DNS with malware protection only, Cloudflare's 1.1.1.2 or Quad9.
I am mainly looking for malware protection, but I would also appreciate ad and tracking blocking as long as it doesn't break web pages.
DNS actually doesn't have any effect on the internet speed at all. All DNS does is translate domains to IP addresses and that's it. In simpler terms, its only job is whenever you type malwaretips.com to find corresponding IP address of the server hosting it, nothing else. It's also worth to note that DNS doesn't work all the time. Once you request malwaretips.com, the response is saved in DNS cache for some time. DNS is only queried if you don't already have the domain tied to corresponding IP address in cache, or if the cache entry expired.

When we're talking about DNS response time, we're talking about time DNS server took to find the IP address of the server for corresponding domain, not how fast website loaded. And while it doesn't have any effect on how fast website assets will be downloaded from the server, ad blocking DNS might improve your website loading times in terms of simply rejecting domains that are in the blocklist used.
Thanks for the details; I'll stop testing with Speedtest.net every five minutes. 😅
It's clear because you haven't sent any DNS requests yet so it has nothing to show. Try loading some website in the browser, DNS requests will appear.
I meant clear of errors at that point, as I had selected "Error Only" from the log dropdown menu. When I previously tested with Control D over HTTP/3, the log was immediately flooded with errors right after starting Windows. However, with Mullvad over HTTPS, the log remained clean of errors after restarting.
I assume this was YogaDNS logging the requests while device was asleep. Because there isn't internet access during sleep, DNS requests failed. That could also explain why it happens immediately when you wake up PC from sleep. YogaDNS showing you requests that failed.
I agree. After switching to Control D over HTTPS, as SeriousHoax recommended, I checked the logs and found similar errors upon waking my PC from sleep. While not identical, one error occurred during PC usage: "content-signature-2.cdn.mozilla.net - request timeout: server=Control D Malware Protection." This issue only appears with Control D.