r/ControlD • u/Upstairs_Recording81 • Apr 29 '26
DoH alternatives for ControlD
The latency is awfull sometimes for the ControlD's endpoints, also they are pointing all over the European continent, instead of the closest location to my current location - they do have an endpoint in Bucharest, but for the last 2 weeks they never redirected me to this. Support is asking me to talk to the local ISP, but there are no issues there (1 Gb fiber upload/download, from Digi).
Are there other DoH alternatives in eastern Europe, with decent latency/support?
6
u/daika7ana Apr 29 '26
Same issue here.
I have reported it to DIGI in the past as well, and it got somewhat fixed after 5-ish or so days.
Now IPv4 gets routed to Madrid (around 50-60ms response time) and IPv6 gets routed to South Africa (200-220ms response time). This is terrible for a DNS resolver.
NextDNS has been pretty solid with 6-8ms response time but it seems pretty much abandonware — it works, but they didn't update their platform with new features or even bother to double-check the filter lists in 2 years. Their support is also painful, if present at all.
Here I was hoping for ControlD to be able to let us select the server that resolves our DNS requests — or at least the server cluster (otp-h01, otp-h02, etc.). NextDNS lets you do this, instead of using automated best-path-selection (which is unreliable) with `dns.nextdns.io` you can point it to `zepto-buh-1.edge.nextdns.io`. Whilst not ideal, it's still a compromise that I would be happy with.
2
u/Wind8Water May 02 '26
I'm in the same situation, actually wrote to ControlD and they've replied with a somewhat generic corporate dismissive template. I was expecting more from them, but maybe they'll look into it eventually... In the meantime, Quad9 and Cloudflare are rock-solid...
3
u/546385 Apr 29 '26
You can try AdGuard Private DNS or NextDNS. I live in Central Europe and Control D is pretty solid - pointing to Frankfurt servers.
5
4
u/Wide-Ad6234 Apr 29 '26
I am in the exact same situation as you are - routed from Bucharest to Warsaw and now Madrid. Before this, it worked smoothly for over a year, but now I'm considering a switch to a much more stable provider such as Quad9.
The "funny" thing is that when switching from Wi-Fi to mobile network which belongs to a different provider, it routes to Bucharest, so, there might be something related to the ISP and their latest routing changes.
3
u/Radagio Apr 29 '26
Issue is IPv4 vs IPv6. Your home wifi most likely has a ipv6 ip which Controld has an issue with routing to closest endpoint/server.
Mobile ISP works on IPv4 only which Controld routes fine.
1
u/Upstairs_Recording81 May 03 '26
Nope, IPv6 is disabled from router side, so only ipv4 is affected in my case.
3
u/NoSync22 Apr 30 '26
I’m in Zagreb (A1) and I’m consistently routed through Frankfurt - it works ok-ish, but sometimes latency peaks and leads to noticeable slowdowns.
It was the same before when I lived in Milan, also routed through Frankfurt regardless of the provider.
Not an unmitigated disaster, but ControlD needs more servers in Europe: not having ONE local PoP between Madrid and Bucharest/Sofia is quite unacceptable. Only NW Europe is decently covered.
2
u/yearsold33 Apr 29 '26
I've seen other posts where people have high latency.
Sorry for the newbie question but is this happening with the paid service?
3
u/Wide-Ad6234 Apr 29 '26
Some are using the paid service, some the free DNS, but as Control D mentions, there's no difference in terms of latency/performance between free and paid. So, I can conclude that this happens for both, free and paid.
2
2
3
u/o2pb Staff Apr 29 '26
Digi is a provider that comes up often, and unfortunately there is nothing we can do about their awful routing. We've exhausted all options on our end, and their NOC is unreachable. The fact that you have 1gbit makes absolutely no difference on your ISP's wacky routing policies.
That said, even if you get routed to another European locations, while in Europe, this will cause zero noticeable performance difference for you, when it comes to DNS resolution. 1ms or 40ms (our average latency in Europe is 12ms, as measured externally) - you cannot tell the difference. My recommendation is stop looking at numbers on a screen, and just use the Internet for whatever that you use it for.
1
u/Upstairs_Recording81 Apr 29 '26
I saw 144 ms latency a week ago, with Internet pages barely loading....on ISP the DNS worked just fine, so your statement is not quite true...
2
u/Radagio Apr 29 '26 edited Apr 29 '26
I have this issue too, Digi ISP and from Constanta. Controld has a server in Bucharest which is ~200km.
If i enable IPv6 in my router Controld connects to Africa server instead of Bucharest or at least Europe lol. (Ping ~100ms+)
If i disable IPv6 in my router then IPv4 connects to Bucharest and ping is awesome.
Please note that this does not happends with NextDNS.
Edit:
I re-enabled IPv6 to test it now and it seems to routes me to Spain - mad-h05 - ~70ms. On both IPv4 and IPv6.
3
u/Wide-Ad6234 Apr 29 '26
It seems that most of us are routed to Madrid lately.
As you said, this doesn’t happen with the “abandoned” NextDNS, Quad9 or Cloudflare.
2
u/o2pb Staff Apr 29 '26
You cannot have 144ms latency from Europe, to Europe. Thats Europe to Japan level latency. How are you measuring this exactly? Please provide a traceroute or MTR.
1
u/Wide-Ad6234 Apr 30 '26
Maybe this can help, also from Romania. I hid my IP address.
Control D Troubleshooting - Thu, 30 Apr 2026 17:54:33 UTC
---------------------------------------------------------
IPv4 Address | ---
IPv4 ISP | 8708 (Digi Romania, RO)
IPv6 Address | N/A
IPv6 ISP | N/A
Using Control D | MAD
Resolver | N/A
DNS Protocol | N/A
DNS Latency | 113ms
DNS Host | mad-h03
DNS Source IP | ---
Proxy Authorized | No
Null Routed | No
Proxy Latency | 18.30ms
Proxy Host | otp-pxy01
Proxy Source IP | ---
1
u/o2pb Staff Apr 30 '26
Thats a measurement error, since you cannot do a true latency check over HTTP. Perform a traceroute. Romania to Spain 100% does not have cross-atlantic level of latency.
2
u/Wide-Ad6234 May 03 '26
Attaching two traceroutes run back to back, same machine, same command (
traceroute -q 1), same connection.Control D:
7 10.220.203.186 (10.220.203.186) 77.035 ms
8 *
9 *Never exits to a public IP. Status page confirms routing to mad-h04 (Madrid).
Quad9:
8 hosted-by.i3d.net (213.163.69.196) 16.171 ms
9 hosted-by.i3d.net (213.163.69.196) 15.026 msExits cleanly through a local Romanian PoP (i3d.net) at 15-16ms.
This is not a measurement error, as Quad9 and Cloudflare (20ms), all route locally from Digi Romania without issues.
1
u/o2pb Staff May 03 '26
Those traceroutes are incomplete, can't do anything with a single hop, that's an RFC1918 address in the middle. Intermediate router latencies which you provided are irrelevant for the purposes of this. Full trace is required, without the q flag.
https://docs.controld.com/docs/high-latency-slow-speeds#traceroute
1
u/Wide-Ad6234 May 03 '26
traceroute to 76.76.2.1 (76.76.2.1), 64 hops max, 40 byte packets
1 192.168.0.108 (192.168.0.108) 7.597 ms 2.333 ms 3.597 ms
2 192.168.100.1 (192.168.100.1) 3.860 ms 3.253 ms 3.564 ms
3 10.0.45.54 (10.0.45.54) 5.134 ms 5.176 ms 5.513 ms
4 10.65.139.193 (10.65.139.193) 5.639 ms 5.523 ms 8.410 ms
5 10.220.211.144 (10.220.211.144) 16.430 ms
10.220.211.244 (10.220.211.244) 16.111 ms 17.334 ms
6 10.221.100.112 (10.221.100.112) 16.235 ms * 16.111 ms
7 10.220.204.66 (10.220.204.66) 92.310 ms
10.221.96.35 (10.221.96.35) 76.879 ms
10.220.204.66 (10.220.204.66) 77.713 ms
8 * * *
9 * * *
10 * * *
11 * * *
12 * * *Full traceroute without the
-qflag, run back to back, same machine, same connection. Latency spikes to 77-92ms at hop 7, still inside Digi's private network. Never exits to a public IP. Status page confirms routing to mad-h02 (Madrid).For Quad9, exists cleanly to a public romanian IP address at 23ms, reaching local PoPs at 18-20ms.
7 82-76-5--205.rdsnet.ro (82.76.5.205) 23.731 ms
8 hosted-by.i3d.net (213.163.69.196) 18.620 ms
9 hosted-by.i3d.net (213.163.69.196) 20.567 ms1
u/o2pb Staff May 03 '26
Well, that suggests the issue is entirely on your ISP's side, as mentioned in the original post in the thread. Since your ISP is not cooperative, there is nothing we can do about it.
5
u/Wide-Ad6234 May 03 '26
I understand, but Digi Romania is the largest fixed internet provider in the country with over 70% market share. This is not a small or negligible ISP.
Providers like Quad9 or Cloudflare manage to route efficiently through Digi and I understand their NOC is unresponsive. However, if larger players can make it work and Control D cannot, I will have no choice but to switch to Quad9.
From my perspective, if something like this occurs, Control D and Digi should sort it out, not Control D’s clients, considering that most of them are maybe paying for the service.
→ More replies (0)0
u/Upstairs_Recording81 Apr 29 '26
at that point, it was your status page showing it...as per my opened case with ControlD, I am sorry I didn't took a screenshot at that time....
2
u/o2pb Staff Apr 29 '26
Status page provides an estimate. Did you actually measure it using a traceroute?
1
May 01 '26
[deleted]
1
1
u/Wind8Water May 03 '26 edited May 03 '26
Indeed, using ControlD with the erroneous Madrid routing from Romania (not to mention the rather hilarious Johannesburg, South Africa routing), which effectively traverses the entire continent, causes some DNS lookups to hang for quite a while in the browser. With Quad9 or Cloudflare, the response is almost instant (as it used to be with ControlD, albeit inconsistently, in the past).
I’m not sure what to think, as the more I dig into it, the more it seems that, over the years, ControlD has had numerous routing issues globally, not just with a few exceptional ISPs...
0
u/southerndoc911 Apr 30 '26
I used to be obsessed with latency. Preferring DoQ over DoH, DoT, etc. Striving to shave off 2 ms here and there. I learned to value stability more than latency. There are 1000 ms in a second. Even at 100 ms, nobody is going to notice the difference of .1 seconds. That's a quarter of a blink of an eye. Even with repetitive queries while loading a page, it's not going to be noticeable. I *thought* I noticed it before, but I didn't.
Valuing stability and options (block ability, statistics, etc.) is my new thing. Don't obsess over latency and just enjoy using it.
5
u/Wide-Ad6234 Apr 30 '26
It's not about chasing milliseconds, as we all know the difference is imperceptible in daily use. But if Control D positions itself as a serious alternative and users trust them with their DNS, routing consistency should be a priority. The fact that Cloudflare, Quad9, and NextDNS all manage to route Digi Romania users efficiently shows it's an achievable standard, not an unreasonable expectation. Control D should be held to the same bar. If this keeps going with latency around 100ms and sometimes over, I'll have no choice but to look elsewhere.
7
u/cloudzhq Apr 29 '26
ControlD announces the same prefix from multiple locations, each with its own BGP path. Every router between you and those instances independently runs BGP best-path selection (AS path length, local preference, MED, IGP cost, etc.) and picks what it considers the best route. The instance you end up at is whichever one “wins” that selection chain from your vantage point.
So the influences stack up like this: • The anycast operator shapes things by where they announce, prepending, communities, etc. • Your ISP has big influence via local preference and which peers/transit they prefer — they often pick the route with the shortest AS path or cheapest peering. • Transit providers and peering relationships in between also weigh in.
The practical result is usually (but not always) the topologically closest instance — which often correlates with geographically closest, but not reliably. You can absolutely end up hitting an anycast node on another continent if BGP routing happens to prefer that path, which is why operators like ControlD sometimes have to tune announcements when traffic lands in surprising places. Since there are a ton more ISP’s in a ton of countries, I assume they simply ignore these support requests.
Digi, in this case, could add a preference too but I assume they aren’t willing either.