An open DNS recursive service for free security and high privacy
Quad9 offers a free, privacy-focused DNS service that blocks malicious hostnames, providing an alternative to ISP or commercial DNS resolvers. Its appeal to the HN crowd stems from its commitment to privacy, open nature, and enhanced security features. This sparked a technical debate on performance, filtering, and the nuances of DNS privacy versus centralized services.
The Lowdown
Quad9 provides a free, open, and secure recursive DNS service designed to enhance user privacy and protection against online threats. By replacing your default Domain Name System (DNS) resolver with Quad9, it actively blocks access to malicious domains before they can reach your devices, mitigating threats like malware, phishing, and botnets.
- Operated by the Swiss-based Quad9 Foundation, a not-for-profit organization focused on a safer and more robust internet for everyone.
- Utilizes threat intelligence from over 25 providers to block more than 670 million malicious requests daily.
- Prioritizes user privacy by never logging IP addresses and designing its platform to be GDPR-compliant from its inception.
- Easy to deploy: users can simply update DNS settings on individual devices or network routers; no sign-up or account data is required.
- Sustained through grants, partnerships with commercial and non-commercial entities, and individual donations.
Ultimately, Quad9 aims to improve internet security and stability, allowing users to engage online with greater confidence and protection against prevalent cyber threats, all while upholding a strong commitment to data privacy.
The Gossip
Performance Perceptions & Ponderings
Users engaged in a detailed discussion about Quad9's latency and performance, comparing it against other prominent DNS providers like Google DNS and Cloudflare. While some commenters reported experiencing slower response times and occasional timeouts, leading them to switch providers, others noted that any perceived difference in speed didn't translate into a noticeable impact on real-world usage. The conversation also delved into how factors such as different Internet Service Providers (ISPs) and specific configurations (like DNS over TLS or DNS with ECS) can influence performance, alongside the trade-offs of running a local recursive resolver versus relying on third-party services.
Filtering, Freedom, and Forensic Fidelity
A significant portion of the discussion centered on Quad9's default practice of blocking malicious domains. Some users expressed surprise or concern that the service's "protection" resulted in filtered responses for certain domains, which they perceived as Quad9 'lying' or exercising control over their DNS queries. This sparked a debate balancing security through automated blocking with user autonomy and the expectation of unfiltered DNS resolution. Commenters also pointed out Quad9's alternative, unfiltered DNS options, and privacy implications of entrusting all DNS queries to a single centralized third party were also raised.
Alternative Approaches & Assurances
Commenters often recommended Quad9 as a trustworthy DNS option, frequently citing endorsements from privacy advocacy organizations like Privacy Guides. The discussion also included mentions of alternative DNS providers such as Cloudflare (1.1.1.1) and Google DNS (8.8.8.8), or the more involved approach of running a personal local recursive resolver. The conversation explored specific configurations and use cases, including enabling ECS (EDNS Client Subnet) for better CDN routing or selecting Quad9's unfiltered IP addresses for users who prefer no domain blocking.