Serious Discussion DNS Providers for Home Users – Still Cloudflare/Quad9, or Did NextDNS/Control D Finally Win?

What DNS provider(s) do you force on your home network / PC?

  • Cloudflare 1.1.1.1 (or 1.1.1.2/3) – speed king

  • Quad9 – best free malware/phishing blocking

  • Google 8.8.8.8 – I don’t care, just works

  • NextDNS – worth the config time and (sometimes) the $20/year

  • Control D – NextDNS but better UI and free tier actually good

  • AdGuard DNS – most aggressive ad/tracker blocking for free

  • Mullvad DNS / DNSCrypt – paranoid zero-log gang

  • My ISP’s DNS – yes I’m that guy

  • Self-hosted (Pi-hole, AdGuard Home, Technitium, etc.)

  • Mix – different DNS per device/profile


Results are only viewable after voting.
I havent used a DNS since the old NortonDNS (dont know if its still available) soooo i guess im that guy, just using the one built into my router lol
An example of how secure dns provider can save me

Screenshot_6-1-2026_95515_odfafepnkmbhccpbejgmiehpchacaeak.jpeg
Screenshot_6-1-2026_95552_www.virustotal.com.jpeg
Screenshot_6-1-2026_95530_safeweb.norton.com.jpeg


Except for Norton and G Data, only hagezi tif dns list was able to flag the website
 
NextDNS blocked Norton Cloud for me.
If you're using some questionable blocklists, there can be FPs. I just stick with HaGeZi and Cloudflare's categories and I rarely see any FPs.
I installed the Windows app, and I'm using Cloudflare Warp. Is there anything I need to change? I in FF I changed to Enable DNS over HTTPS.

View attachment 294369 View attachment 294371
Depends what you want. If you want DNS protection like NextDNS and WARP+ for free, you'll need to create a Cloudflare Zero Trust and GitHub account. If you want basic unlimited VPN, then WARP is more than enough for you.

WARP+ differs from WARP because it uses Argo Smart Routing which means Cloudflare looks for the best route to the requested server with less congestion in real-time instead of relying always on the same route regardless of the "traffic" like your ISP. This is why WARP+ is faster than typical WARP.

There's also an option to pay for unfiltered WARP+, but it's completely free for Zero Trust users.
I use DNS over HTTPS with Max Protection on my Firefox browser with Cloudflare as my service provider. Do I need to use a system-wide Domain Name System as well?
If you want your system to be covered with DNS-over-HTTPS as well, then yes.
 
I am using a mix
  1. NextDNS free in the Router
    Reason: security, IOT-telemetry and good reporting features.
    Config: enabled all security features and telemetry blocking (for smart TV), manually blocked all non-latin character TLD's
  2. Quad DNS free as default in laptop devices
    Reason: large number of servers available (for Amsterdam 8 in total), combines zero breakage with good malware blocking
  3. Cloudflare Zero trust free in browser
    Reason: good reporting and security, mild ad& tracker blocking and premium free feature geo location blocking (!)
    config: security categories and security related content categories enabled, plus OISD-small and geo-location blocking (Russia, China, North Korea, Iran)
    1767702208736.png
  4. In surfing profile uBol blocks (only) all TLD's except allowing some common TLDs (com, io, org, net, edu) and Country codes extended EU-zone and 5 Eyes
 
Last edited:
A safe block list for TLD's while maintaining the ability to research without blocking potential information. There is no need to get crazy blocking TLD's. Keep in mind I Created this list for the US, you may have to adjust accordingly per country block.

Tier 1

.zip

.mov

.top

.xyz

.cam

.click

.country

.gq

.link

.men

.ooo

.party

.pro

.review

.stream

.work

Tier 2 (Research/Isolated)

.ru

.cn

.ir

.kp

.tk

.ml

.ga

.cf

.su

.bid

.loan

.win
Considering also blocking all non-latin character TLD's
 
Considering also blocking all non-latin character TLD's
Blocking all non-Latin TLDs would result in a high-impact research degradation for subjects located in or affiliated with Russia, China, the Middle East, and parts of Asia.
 
I am using a mix
  1. NextDNS free in the Router
    Reason: security, IOT-telemetry and good reporting features.
    Config: enabled all security features and telemetry blocking (for smart TV), manually blocked all non-latin character TLD's
  2. Quad DNS free as default in laptop devices
    Reason: large number of servers available (for Amsterdam 8 in total), combines zero breakage with good malware blocking
  3. Cloudflare Zero trust free in browser
    Reason: good reporting and security, mild ad& tracker blocking and premium free feature geo location blocking (!)
    config: security categories and security related content categories enabled, plus OISD-small and geo-location blocking (Russia, China, North Korea, Iran)
    View attachment 294382
  4. In surfing profile uBol blocks (only) all TLD's except allowing some common TLDs (com, io, org, net, edu) and Country codes extended EU-zone and 5 Eyes
Why not just use Cloudflare for all of those? In Zero Trust Free you can create more DNS locations.
 
  • Like
Reactions: LinuxFan58
??? You block .ru .su .cn .ir .kp in your tier2 ???
These tier 2 sources are not usable for what I do. Blocking "ALL Non-Latin TLDs however would cause issue.

When you block Non-Latin TLDs (e.g., .рф), you become blind to local culture and native subjects.

When you block .ru or .cn from the Verification Layer, you are merely filtering out State Propaganda.
 
Last edited by a moderator:
If you have chosen your DNS, especially with the aim of blocking threats with a method that has a low impact on your PC's resources, consider running malware/phishing/fake site tests.

AG account with the usual list of filters that I use in NextDNS guarantee a lower total number of blocks than can be achieved with NextDNS.

I think it is understandable for anyone not to rely exclusively on the list of filters you have chosen.
 
Why not just use Cloudflare for all of those? In Zero Trust Free you can create more DNS locations.
That is why I added the reason :-) but to be honest I recently moved to Cloudflare Zero Trust because of positive posts (also from you) in Cloudflare thread. Let's say I half convinced on Cloudflare. Not moving over is partly lazyness (Cloud9) and not knowning Cloudflare als has blocklist for IOT-devices like NextDNS (thanks for attending me (y))

Cloud9 in the OS is because they are listed as one of the defaults in Linux (so mostly lazyness and partly because Cloud9 offers more servers on Amsterdam than Cloudflare).

I simply did not know that Cloudflare also has telemetry build-in blocklists like NextDNS (see below), I will have a look at it.
1767708853156.png
 
Last edited:
Cloud9 in the OS is because they are listed as one of the defaults in Linux (so mostly lazyness and partly because Cloud9 offers more servers on Amsterdam than Cloudflare).
You mean Quad9? Quad9 couldn't possibly have more servers than Cloudflare. Cloudflare uses three data centers in Amsterdam alone.
I did not know that Cloudflare also has telemetry build-in blocklists like NextDNS (see below), I will have a look at it (just recently moved to Cloudflare Zero trust)
It doesn't, but you can always add HaGeZi's Native Trackers lists which is what NextDNS uses, I think.
 
Technically Quad9 has no servers, it uses ISPs, like Adguard.

Yeah, pretty much everyone rents network and servers except Cloudflare and Google. They own their data centers and servers.
Cloudflare vs Quad9 Amsterdam servers (when checking with browserleaks)

View attachment 294387
Sorry to say this, but the larger amount of servers on the list doesn't mean anything. You don't get any benefits from it.

Beside, Cloudflare usually has multiple servers under the same IP; this is why you see only two IP addresses and not more.
But Quad9 is much more faster than AG for me!
And it should be faster considering it uses way larger network than AdGuard.