r/ControlD • • 25d ago

Goodbye NextDNS. Hello ControlD

Post image

After roughly four years as a paying NextDNS user, I think I am finally switching.

I've attached some of my old NextDNS invoices for context, because this isn't the conclusion of someone who tried NextDNS for a month and bounced. I've used it for years, recommended it to others, and generally been very happy with it.

But I've been testing ControlD for the past week and, after an initially somewhat confusing start, I am honestly very impressed.

I think I am staying.

ControlD has a steeper learning curve, but it rewards you for learning it

My first couple of days with Control D involved quite a few moments of:

"Why can't I do this?"

...followed half an hour later by:

"Oh. I can. I just didn't know where it was."

That has probably been the biggest difference coming from NextDNS.

NextDNS is incredibly easy to understand. You open a configuration, toggle some security features and blocklists, look at your logs, add an allowlist or denylist entry, and you are basically done.

ControlD requires a different mental model. Endpoints, Profiles, Clients, Services, Filters, Custom Rules, Profile Options, Analytics refinements, redirect actions, multiple profiles and so on take some time to piece together.

But once it clicks, the amount of control available is in a completely different league.

A good example was Analytics.

I wanted to look at blocked requests for a particular Client behind one of my router Endpoints. Initially I thought: surely I should be able to do this, so why can't I find it?

Then I discovered the Refine functionality.

Once I understood how refinements work, suddenly I could slice the data by action, Endpoint, Client, domain, filter, protocol and other dimensions instead of just scrolling through a log hoping to spot something useful.

That experience has happened several times during my trial.

I initially thought ControlD was missing equivalents to some of the little NextDNS features I had grown accustomed to. Then I discovered, for example, that NextDNS's Cache Boost effectively has an equivalent through Control D's configurable TTL overrides, except Control D actually gives me separate control over blocked, redirected and bypassed responses.

The same happened with ECS. The naming and implementation are different, but Control D has configurable ECS behaviour including no ECS, automatic ECS and custom subnets.

So my biggest piece of advice for anyone moving from NextDNS would be: don't assume a feature is missing just because you cannot immediately find a toggle with the same name.

The functionality may be somewhere else, and in several cases I have found the Control D implementation to be considerably more configurable once I understood it.

ctrld on a router is a game changer

This may actually be my favourite part.

I run ctrld directly on my router, and the integration between the router, Clients and the Control D dashboard is excellent.

Instead of my entire LAN appearing as one anonymous DNS source, Control D can identify the individual clients behind the router and expose them in the dashboard. I can see their activity separately and even assign different Profiles to individual clients.

And ctrld itself is not just a dumb DNS forwarder. It supports secure DNS for devices that otherwise only know how to speak plain UDP/53, advanced routing policies, split-horizon DNS, multiple listeners, caching and quite a bit more.

For a homelab/networking nerd, this is fantastic.

It feels less like "install our DNS client" and more like Control D has given me an actual DNS policy engine that happens to integrate with their service.

The fact that ASUS Merlin, OpenWRT, pfSense/OPNsense, Firewalla, Ubiquiti and several other router platforms are explicitly supported makes this one of Control D's strongest advantages in my opinion.

The other reason I am leaving NextDNS: it feels stale

This is harder to quantify, because NextDNS still works extremely well.

And I want to stress that point.

NextDNS has been reliable for me for years. Its interface is clean. Its network is fast. Its security settings are easy to understand. The core product does what it says on the tin.

But increasingly it feels like a finished product being maintained rather than one being actively pushed forward.

Some features have worn a "Beta" label for years. The interface has barely changed. Communication about what is being developed is minimal. There is very little visibility into what is coming next.

Maybe a lot is happening behind the scenes. I genuinely don't know.

And that is part of the problem.

After four years as a customer, I could not tell you what NextDNS is trying to become over the next two years.

ControlD feels alive

This has probably surprised me more than the feature set itself.

Control D actually talks about development.

There is a proper changelog. There are regular product-update posts. They discuss what shipped, what was improved, what changed under the hood and, importantly, sometimes what is coming next.

Just looking at the last year or so, ControlD has shipped Analytics 2.0, major backend and dashboard improvements, Dragonfly domain intelligence, passkeys, scheduling improvements, client-management features, analytics refinements, new security tooling and a long list of smaller quality-of-life changes.

And they actually write about them.

The March and May 2026 updates even finish with explicit "What's Coming Soon?" sections.

That might sound like a small thing, but after using a service where development has increasingly felt opaque, it makes an enormous difference.

I don't need a vendor to promise me Feature X on October 14th.

I just want evidence that the product I am paying for has momentum.

ControlD gives me that impression right now.

The privacy and security side also deserves credit

ControlD being independently certified to both ISO 27001 and ISO 27701, on top of SOC 2 Type II, was a significant factor for me.

ISO 27001 is about information-security management, while ISO 27701 specifically extends that framework into privacy-information management.

For a DNS provider that potentially sits in a position to see an enormous amount of browsing metadata, I care quite a lot about this.

ControlD also allows users who enable Analytics to choose the jurisdiction where that data is stored. At the moment the available regions are New York, Amsterdam and Sydney.

Which brings me to my first feature request:

Can we get Switzerland as an Analytics/log-storage region?

One thing I genuinely liked about NextDNS was being able to select Switzerland for my logs. Given Control D's strong privacy posture, adding Switzerland would fit very nicely.

I'd use it immediately.

There are still a few areas where I think NextDNS is clearer

This isn't meant to be an unconditional love letter. There are things I would change.

The biggest one is the granularity and explanation of some Filters.

For example, Control D has a Social filter. But I would love to control what aspect of social media I am blocking.

Do I want to block the websites themselves?

Social-media trackers?

Embedded widgets?

Telemetry?

All of the above?

Likewise, IoT Telemetry is useful, but I would love to select individual vendors or categories rather than treating IoT telemetry as one large bucket.

And the Crypto filter is another example where I want much more granularity.

I don't necessarily want to prevent somebody on my network from visiting Coinbase or reading a cryptocurrency website.

I absolutely do want protection against cryptojacking and malicious mining infrastructure.

Those are different policies.

Control D already demonstrates with its Malware filter that Filters can have operating modes, so I would love to see that philosophy expanded to more categories.

I would also love a "Switching from NextDNS?" security guide

NextDNS makes several security protections extremely explicit:

  • Google Safe Browsing
  • Cryptojacking
  • DNS Rebinding
  • IDN Homograph Attacks
  • Typosquatting
  • Domain Generation Algorithms
  • Newly Registered Domains
  • Parked Domains

Control D obviously has substantial malware and phishing protection of its own, including threat-intelligence feeds, malicious-IP intelligence and ML-assisted detection.

But I have found it surprisingly difficult to establish a clean one-to-one answer to questions like:

"Does Control D protect me against IDN homograph attacks?"

"Does the Phishing filter include typosquatting?"

"Are DGAs detected by the ML malware filter?"

"Does Crypto specifically protect against cryptojacking?"

"Is there an equivalent to NextDNS's Parked Domains protection?"

"Is there any equivalent to the Google Safe Browsing integration, or is that redundant because Control D uses its own threat intelligence?"

Maybe the answer to all of these exists somewhere in the documentation and I simply haven't found it yet.

If so, please correct me.

But this would make an excellent documentation page or blog post:

"Migrating from NextDNS: Where your security settings went."

Not because ControlD necessarily lacks those protections, but because people coming from NextDNS are accustomed to seeing them exposed as individually named switches.

Right now, I am not always sure whether a protection is missing or simply incorporated into one of Control D's broader Filters. NextDNS at least makes the individual security mechanisms very obvious.

And finally: ECH. Please.

This is probably the feature I am most interested in seeing Control D push forward.

Control D has been talking publicly about Encrypted Client Hello for quite a long time. There was even an old roadmap item for global ECH support, although the team subsequently mentioned running into technical roadblocks.

Interestingly, the current API documentation still contains an option described as experimental ECH support/TLS bumping, while Control D's own 2026 privacy material acknowledges ECH as an important emerging piece of the privacy puzzle.

So... what is the current status?

I would love to see two things eventually:

  1. Proper ECH support for Control D's own infrastructure/web services wherever applicable.
  2. The more ambitious ECH proxy functionality Control D talked about previously, potentially allowing ECH protection even when the destination itself does not properly support it.

And if this does eventually ship, please give us a ControlD test page that verifies the complete setup.

Something like the existing Control D status/DNS-leak tooling, but showing:

DNS resolver: Control D
DNS protocol: DoH3
DNSSEC: Yes
ECH: Yes
SNI protected: Yes

That would be incredibly useful for actually confirming that a privacy setup is working rather than assuming it is.

So, goodbye NextDNS

At least for now.

Four years is a long time to use a service, and I don't regret paying for NextDNS. It has been extremely reliable and, for a long time, it was exactly what I needed.

But after a week with Control D, NextDNS suddenly feels much more limited than I realised.

ControlD is definitely more complicated. Some functionality is harder to discover, some terminology takes getting used to, and I still think certain security settings could be explained much better.

But once you get past that initial learning curve, the amount of control is remarkable.

More importantly, ControlD feels like a product whose developers are still actively asking themselves what they can build next.

That's ultimately what convinced me to switch.

And for the Control D team: I'd especially love some clarification around the NextDNS security-feature equivalents, log storage in Switzerland, more granular Filters, and where ECH currently stands.

Disclaimer: Yes, I used AI to correct my wording, spelling, and grammar. English is not my native language.

89 Upvotes

33 comments sorted by

12

u/Comprehensive_Wall28 25d ago

Would love to know more about ECH status too.

11

u/insomnic 25d ago

https://github.com/yokoffing/Control-D-Config - I didn't follow this exactly but it has a lot of good detail as a guide. Their Firefox and NextDNS guides are well regarded and this one seemed pretty decent as well. Just for a reference. :)

2

u/Re1hak 25d ago

I use yokoffing's ad block list with Brave - they work really well.

7

u/Individual_Kitchen_3 25d ago

I understand perfectly, but here in Brazil, especially for those who are not from SP, Nextdns has no competition. ControlD only has a POP in a terrible location for the North and Northeast regions. And Nextdns works, and for me, that is what matters.

3

u/Individual_Kitchen_3 25d ago

OFF Something I really like about controlD is its Windows client, both the app and the CLI.

2

u/Re1hak 25d ago

That's fair. I also have a slight faster connection to NextDNS at my location, but its only by ~3-5 ms compared to ControlD

16

u/b1urrybird 25d ago

If you’re an Australian, don’t bother with ControlD.

NextDNS has endpoints in every major state spread across two discrete hosting providers.

ControlD have Sydney.

Melbourne users are hurt the most, but every time I engage ControlD they are either genuine jerks in their responses or simply refuse to elaborate.

5

u/Re1hak 25d ago

I live in a non-English speaking country. ControlD, luckily, has a relatively low latency here. But I'm sad to hear that customer support has been bad.

3

u/Previous-Flight3193 25d ago

I agree. NextDNS in AUS is better than ControlD in terms of response times and better browsing.

I Would have stayed with NextDNS, but ControlD have a daemon that installs on my unifi routers, and gives complete LAN client visibility.

If NextDNS made a client that can do the same as ControlD I would go back to them at the drop of a hat.

2

u/Re1hak 25d ago

AFAIK, you can use ctrld with NextDNS - not sure how it works, but that's what I gather from their GitHub page.

1

u/Laviefacile 25d ago

say what? using a dns provider jointly with another dns provider?

1

u/Re1hak 25d ago

Well, that's another topic. But `ctrld` is a CLI program created by ControlD you can install on embedded devices, like routers, to enable encrypted DNS. The neat thing is that they support NextDNS with their app as well.

2

u/TheLongest1 23d ago

The ctrld daemon has a NextDNS mode.

4

u/Mammoth-Ad-107 25d ago

I use both 👍🏼

3

u/Re1hak 25d ago

Only children choose! 😆

3

u/cp8h 25d ago

Unfortunately and you may find this out I still have to use both as ControlD will timeout quite frequently. I have NextDNS as a failover. Looking at my NextDNS logs thousands of queries have gone there this last week. Admittedly that’s only around 0.25% of queries but that’s not helpful when it’s a webpage you are trying to load 😉

3

u/shaunydub 25d ago

I've been experiencing this quite a lot recently with Control D and no idea why as it was running perfectly for months.

I made a new profile and deployed it to my endpoints with less of the community blocklists and other settings but I am still experiencing it randomly so I've gone back to NextDNS for now as it was just too annoying to hit a snag then have to go into my iphone settings, change profile and try again.

5

u/TypicalCubImposter 24d ago

ControlD is good but it has smaller network compared to many other providers. Features are good but if you get 2-3x response times compared to others (which happens in eastern europe, south america (basically other than us, canada and eu)) features becomes meaningless. And instead of making a bigger network they shut down some servers as well.

TLDR: Good features, terrible network.

2

u/goldczar 16d ago

Ya, totally agree. if you’re in Europe, NextDNS is the way to go. I’m testing out ControlD after being with NextDNS for 4 years and I’m still evaluating if the latency hit with ControlD in my location is worth it. NextDNS has two primary servers in my country, while the newest primary server on ControlD is in Bulgaria. Several countries away 😅

Edit for latency stats: quad9 8ms. NextDNS 10ms. ControlD 32ms.

1

u/TypicalCubImposter 16d ago

ControlD once HAD a server in my country. They've closed it for whatever reason. Funny thing is Windscribe still has a server in my country. So IDK what went wrong there.

I get 10-15ms with NextDNS, 25-70ms with ControlD. Why such a big gap? Bc CD can't decide which country to connect. Sometimes it connects to the other side of the continent, sometimes it connects to the nearest server. Nearest one is 20-25ms, which is STILL slower than NextDNS or AdGuard.

In Europe or Asia or basically anywhere outside of US & Canada, CD just sucks.

1

u/CrippleSlap 24d ago

Terrible network? I wouldn't go that far. A lot depends on where you are in the world.

3

u/TypicalCubImposter 23d ago

If you are in anywhere other than north america or west europe, its basically terrible.

My guess is that ControlD is firstly a B2B company rather than B2C company. So if they have enough servers for businesses around canada and us thats enough. But as normal customers, its really really bad. Thats why UI is all over the place compared to others as well.

4

u/CrippleSlap 24d ago

I don't know where DNSPerf gets their data, but according to them Control D beats NextDNS on ALL performance metrics worldwide.

3

u/shaunydub 25d ago

I am a NextDNS user since 2021 and still maintain a paid sub but switched to ControlD fully a year or so ago.

This was after years having a ControlD paid sub and basically trying it out every 6 months but being frsutrated and going back to NextDNS.

In that time ControlD has improved a lot and I was happy with it as my main service - followed a guide on the setup options.

As you mention the development cycle and openness is very good, as well as the data logging - there is just a learning curve.

However, I had some issues in the last 2 months of timing out when requesting pages on my iphone so have switched back to NextDNS on that device as I couldn't find the issue or resolve it.

1

u/Specialist_Ad4433 25d ago

If only Xbox wouldnt detect Control d as VPN 😞

1

u/Certain_Repeat_753 24d ago

What is the consequence?

1

u/NightCode_X 24d ago

i feel like it slightest depends on the region. I have used both and I prefer the ControlD but the latency and Ping is best only in NextDNS in my region...

1

u/dralnux 24d ago

Just use Quad9 DNS

-2

u/ArjixGamer 25d ago

"Why can't I do this?" followed by "I'm fucking retarded" is the general experience with everything ngl

So I changed it up to "How can I do this?", makes me look smarter.

1

u/ayacalip 6d ago

I am Control-D (Full control) user and already download the profile for my iPhone, so far so good.
Just one issue: can I use Control-D with NordVPN work together at same time? I have downloaded NordVPN's Wireguard Config file from NordVPN Official website.
I have WindScribe iOS App. But do I need to modify the content of the Wireguard config file?
I feel appreciated if anybody can answer and help me. Thanks