New Update NextDNS adds several new Early Access security features

Yes for home use was my question. I use a (free) VPN on demand, but only when I am travelling (and usually only for stuff I need to enter password or passkey/code for).

For corporate use it is more or less standard in the Netherlands for working at home.
 
Don´t want to derail this thread but why do you feel a VPN is important?
@n8chavez put it perfectly to be honest

Why do you feel it's not. I'm ALWAYS using a VPN. I think it's required now, what with everyone trying to steal your data/identity. Anything that can at least try to keep my somewhat private is good in my book.
It's not about being untraceable or unhackable or super anonymous and hiding from the NSA etc. It's about not making it easy for people to track you.

Why make it easy in the first place? Only time I'm not connected to a VPN is when I checkout on eCommerce/shopping. Otherwise all traffic is tunneled through a VPN.
 
Yes for home use was my question. I use a (free) VPN on demand, but only when I am travelling (and usually only for stuff I need to enter password or passkey/code for).

For corporate use it is more or less standard in the Netherlands for working at home.
If you only want security and with enterprise grade encryption standard, move to cloudflare zero trust. It's free (50 different users with unlimited device for each user) and you can configure it easily with the the Ai help directly available on the website itself. On top of that you get these services for free, and you can selectively enable them on selected users.
Screenshot 2026-09-23 081825.png
Screenshot 2026-09-23 081844.png
 
Last edited:
@Brahman

Yes I normally use Cloudflare Zero Trust free plan. Just switched to NextDNS to try out new protections.

I thought the malware scan was only for paid, but lets continue that in the Cloudflare thread


Thanks (y)
 
Last edited:
  • Like
Reactions: Zero Knowledge
Sorry to somewhat hijack this thread, but making a new thread with a question about NextDNS while this exists would be... Meh to me.

I felt like my connection was a bit slow today, so I wanted to check with dnscheck.tools what it would show. And it was a bit slower than usual but acceptable to me. But I saw this aswell!

Schermafbeelding 2026-09-23 175800.jpg



I mean... what the hell? I have seen Frankfurt before, with NextDNS and with Quad9 but never US. And certainly never both at the same time, and more than half of those give that warning?
 
Sorry to somewhat hijack this thread, but making a new thread with a question about NextDNS while this exists would be... Meh to me.

I felt like my connection was a bit slow today, so I wanted to check with dnscheck.tools what it would show. And it was a bit slower than usual but acceptable to me. But I saw this aswell!

View attachment 300171


I mean... what the hell? I have seen Frankfurt before, with NextDNS and with Quad9 but never US. And certainly never both at the same time, and more than half of those give that warning?
It could be related to how NextDNS can direct queries to different servers depending on routing, availability, or load at a given moment. Sometimes this can cause diagnostic tools to show locations or hostnames that do not match perfectly.

It can also happen when some servers use generic hostnames from the hosting provider where they are running, which may trigger those warnings.

This does not necessarily indicate a security issue; it may simply be related to how the infrastructure is organized. If everything is working normally, it could just be a technical detail reported by the diagnostic tool. 🌐🔎
 
  • Hundred Points
Reactions: Morro
It could be related to how NextDNS can direct queries to different servers depending on routing, availability, or load at a given moment. Sometimes this can cause diagnostic tools to show locations or hostnames that do not match perfectly.

It can also happen when some servers use generic hostnames from the hosting provider where they are running, which may trigger those warnings.

This does not necessarily indicate a security issue; it may simply be related to how the infrastructure is organized. If everything is working normally, it could just be a technical detail reported by the diagnostic tool. 🌐🔎

Thank you, I hope it is that then.
 
  • Like
Reactions: Halp2001
@LinuxFan58

Yes, they are gradually implementing a whitelist.
So they should have added 3 services by now.

Enabled:
  • Free Hosting Domains
  • Decentralized Web Gateways
  • Tunneling Endpoints
  • Residential Hosting
  • High-risk TLDs (I hope I've translated this correctly from my language into English, which often has different nuances,please check it.
  • Non-Trusted Certificates (idem)
  • DNS Payload Delivery (idem)
Disabled:

  • Data Drop Services
@Bot AI

I'd like to know your opinion on the feature I left disabled,would you enable it?
 
Last edited:
  • Like
Reactions: TairikuOkami
English translation: I have enabled Free Hosting Domains, Decentralized Web Gateways, Tunneling Endpoints, Residential Hosting, High-risk TLDs and DNS Payload Delivery. I left Data Storage Services disabled. I would like your opinion on that feature: would you enable it?


I would leave Data Storage Services disabled for now on a general-purpose profile.

That category targets services which malware can misuse for command-and-control or exfiltration, but the services themselves may be legitimate. File sharing, uploads, synchronization and some application functions could therefore break. Since this is still an Early Access feature, its practical false-positive rate is not yet well established.

I would enable it on a tightly controlled device where those services are never needed, or temporarily as a trial while watching the NextDNS log. If it blocks something legitimate, allowlist the specific required domain, not the whole service category.

Your translations are understandable. If these are the labels displayed by NextDNS in English, I would retain NextDNS’s exact wording—apparently Data Drop Services, rather than Data Storage Services. “High-risk TLDs” and “DNS Payload Delivery” are natural English labels.

Sources
 
  • Thanks
Reactions: Sampei.Nihira