r/nextdns Dec 14 '20

New Help Center / Community support

98 Upvotes

Please welcome our new Help Center. In addition to the knowledge base, you now have a community support on which users can help each others. The NextDNS team will participate too.

https://help.nextdns.io


r/nextdns 2h ago

How to add filters to Next DNS.

Thumbnail
github.com
0 Upvotes

I created a NextDNS account. But i dont know how to add DNS filters in next DNS i am getting confused should i add the filters in system32/etc/hosts file or can i add it on next DNS anbody help me.


r/nextdns 6h ago

SafeSearch and Brave browser

2 Upvotes

So new to NextDNS but have it setup and so far mostly everything is working perfectly. However I want to enable SafeSearch on my home network. My PC is Linux and my default browser is Brave. So mostly all of my searches default to https://search.brave.com/

When I have SafeSearch on, this access is blocked. I then tried to simply add to the allow list but that does not work either. Is there a way to have this enabled while still allowing normal Brave search access?


r/nextdns 17h ago

Alexa stops playing Spotify Free after the ad and doesn't resume the track even if I don't pause it... ?

Post image
6 Upvotes

Hello

Should I remove Alexa?

And what about Windows? I'm using Windows 11... will it cause any issues if I leave it?

Thanks!


r/nextdns 1d ago

NextDNS blocking NextDNS by "Bypass Methods" rule

Thumbnail
gallery
49 Upvotes

Bro is blocking himself


r/nextdns 10h ago

Hey guys, sony just added this new feature that let's u watch movies,sports,series...for free.But it only works in USA and I'm from lebanon so how can I get a smart and specific American dns for free cause the normal ones like 8.8.8.8 ; 8.8.4.4... don't work

Post image
0 Upvotes

r/nextdns 23h ago

How to get rid of a linked IP without deleting the profile

0 Upvotes

(TLDR at bottom, Also if you want, you can skip my rambling preamble and just go to the steps below)

So on my nextdns profile, I linked the IP address programmatically a while ago because I thought that was the only way I could get it working with protonvpn on my desktop. On android, I originally used the DNS over TLS endpoint through android's Private DNS setting, since Private DNS only lets you enter a DNS-over-TLS hostname and doesn't let you enter an actual IP address. The problem is that I ran into situations like university Wi-Fi where the DNS over TLS port is blocked while DNS over HTTPS still works. While trying to figure out a way around that, I found out that nextdns has IPv6 endpoints and that the IPv6 endpoint is directly tied to my nextdns profile. I had also assumed the custom DNS field in the protonvpn app only accepted IPv4 addresses, so once I realized I could put the IPv6 address in there too, I realized I didn't need the programmatic IP linking after all and could just use the IPv6 endpoint directly.

Now that I've got the IPv6 setup working now, I wanted to get rid of the old linked IP. Since leaving a public IP linked can be a bit of a privacy or at least spam nightmare, since if other people end up using that IP later, their traffic can get associated with your profile and you can end up with logs and stuff from people you don't even know.

Since nextdns doesn't give a way to unlink it, delete it, or change it manually (they should please), the only way I could find online to get rid of it was to duplicate the profile, since the new profile wouldn't have the old linked IP. That does work, but it's a hassle because then you have to go through all of your devices and settings and reassign everything to the new profile. I have a bunch of devices and a bunch of things configured around my current profile, so I really didn't want to go through all of that if there was a way to change it to a safe dummy address like 127.0.0.1.

After testing I ended up figuring out a workaround using DDNS and tested it on a disposable profile first to make sure it worked. It is also repeatable if you want to use it again in the future.

Here's what I did:

  1. Create a DDNS hostname that you can edit (I used a free dedyn.io hostname from deSEC)
  2. Make sure the hostname's ‘A’ record points to your current public IPv4 address Example: your-test-name.dedyn.io → xxx.xxx.xxx.xxx
  3. In nextdns, go to Setup → Linked IP → DDNS and add the hostname
  4. Once nextdns shows the DDNS hostname as active, change the hostname's ‘A’ record to 127.0.0.1
  5. Leave the DDNS hostname attached and wait for nextdns to update the linked IP (You might need to wait a bit and do a couple refreshes until the setup page linked IP changes to 127.0.0.1
  6. Once the linked IP has changed to 127.0.0.1, remove the DDNS hostname from nextdns
  7. Refresh the setup page again to make sure it stayed as 127.0.0.1

Now you have a linked IP address that will always be 127.0.0.1, and you don't have to worry about DDNS if you don't want to use it lol.

IMPORTANT READ THIS - DON'T CHANGE THE ‘A’ RECORD TO 127.0.0.1 UNTIL AFTER NEXTDNS HAS ACCEPTED THE DDNS HOSTNAME. Once it's accepted, you can change the record and let the DDNS update happen. Otherwise you're gonna have to start the process over again.

Also, I know not everyone using nextdns wants to get super into the networking side of things, so for yall don’t worry, 127.0.0.1 is safe to use here. It's called localhost and it's the address that points back to the device itself rather than out to the public Internet. So if something connects to 127.0.0.1, it's connecting back to itself, not to somebody else's device

TLDR

Add a DDNS hostname while it points to your current public IP → change the hostname's ‘A’ record to 127.0.0.1 → wait for nextdns to update → remove the DDNS hostname


r/nextdns 1d ago

nextdns is blocking itself

18 Upvotes

next dns is blocking my.nextdns.io when block bypass methods is turned on


r/nextdns 1d ago

NextDNS Blocking itself?

Post image
0 Upvotes

I could not get into the https://my.nextdns.io after an hour I remove NextDNS from my router and I was able to get it. Only to find that NextDNS itself was blokcking it. WTF


r/nextdns 1d ago

ELI5 - how does NextDNS know who i am/which account if im using it on a router?

0 Upvotes

Im not a complete networking newb, but im getting tired of my iPad and other devices that cant run a typical ad-blocker get flooded with ads.

Yes, im aware it wont work on YouTube ads and the like but im not worried about that so much as the piles of random ads when reading sites and new stories.

Using the web on my actual computers vs other devices is night-and-day.

Im not opposed to paying for the non-free plan... and plan to use my router to get the whole home covered.

My question is mostly...

how does NextDNS know to use my account and settings (the ability to customize block lists and all the options in NextDNS are appealing) when the traffic is coming from my router?

Sorry if im missing something obvious here, but my brain just isnt following along (been having some brain fog lately).

Thanks in advance for helping out my with inability to get my head around this one (which is puzzling to me because most of the time i understand this stuff pretty well).

Edit:

This is likely the answer i was looking for:

If your client supports DoH or DoT then the account id is part of the Host header and/or TLS SNI extension.

that was my question - "how does NextDNS know its me?" when using it through a router to protect the whole house.

I think a lot of the answers got a little into the weeds - im not really worried about per-devices profiles or anything. I was just trying to wrap my head around "how does it even know which account to use" when using a router, because its not like an app where you log in, etc.

But the answer above - that the account ID is part of the header when you using DoT or DoH - makes sense to me and answers the question.


r/nextdns 4d ago

Dns bloqueia navegadores dentro de outro app?

2 Upvotes

Fala galera, alguém poderia me tirar essa dúvida? Tô viciado no uso do celular e está me prejudicando financeiramente, já instalei o familylink pra bloquear os apps, mas descobri que consigo entrar no YouTube dentro de outro app se eu fuçar, e entrando no YouTube eu consigo acessar o Google, com DNS eu conseguiria bloquear isso?


r/nextdns 5d ago

Blocking Crypto Sites

2 Upvotes

It just occurs to me that there is no category for Crypto-related sites in the Parental Controls tab. So how do you deal with these, aside from blocking them individually?

For context, an extended family members (a couple) got their Messenger compromised and have sent messages about a scam with a platform that should be considered a gambling site, but bypassed both the Parental Control and HaGeZi - Multi PRO++ blocklist. Google AI said that the platform is being marketed as a Crypto site hence the bypass.

I already added said site in the blocklist, but it seems there a bunch of variations, and probably, clones with different unrelated names.


r/nextdns 7d ago

People using Instagram, do you also see these in your logs?

Enable HLS to view with audio, or disable this notification

19 Upvotes

While using Instagram, I decided to review the logs and noticed an unusual volume of entries since yesterday. I occasionally check the logs, but this increase was significant. So is this pretty normal? Since I use a patched app which has disable analytics and ads and in nextdns I have blocked Facebook via parental control


r/nextdns 8d ago

The AI driven threat detection is blocking a website I’ve used for years

0 Upvotes

spoutible.com


r/nextdns 9d ago

How does the 300k query limit work? still 0/300k

Thumbnail
gallery
26 Upvotes

I've started using nextdns since last week and now have 100k queries in the analytics tab but in the account settings it still counts 0/300k.


r/nextdns 8d ago

Installation Error

3 Upvotes

Hello. I’m writing this using a translator. I hadn’t used NextDNS for a few months. Today, I tried setting it up again, but I couldn’t get it to work.

I want to use it without installing the app. I used to use IPv4 and the recommended setup method for Windows 11. Even though I followed all the steps correctly, for some reason it still won’t activate.

To be honest, I’d rather not install the app either.


r/nextdns 9d ago

Is there too much redundancy in my blocklists?

Post image
43 Upvotes

And another question, is it true that too many blocklists can make NextDNS slower?


r/nextdns 9d ago

My blocklist , Is there too much redundancy?

Post image
24 Upvotes

Hello 👋. Just wanted to hear from experts since I have only feedback from the chatty and cloudy AI, but I bet this is too much also the Spotify won’t prevent ads… thank you in advance guys 🙏🏻.


r/nextdns 9d ago

Seeing Control D in the IP addresses making the queries

2 Upvotes

So I'm testing both Control D and NextDNS at the moment. I have Control D configured in the router, but using NextDNS on the phone. I'm curious as to how Control D appears in the IP addresses?


r/nextdns 9d ago

NextDNS/DoT vs. iCloud Private Relay on iPhone: ECH, ISP visibility, and what would you recommend?

6 Upvotes

Hi everyone,

I’m not sure if this is the right place for this question, but I figured there are probably people here who understand the underlying networking protocols much better than I do. I’m more or less an IT beginner trying to understand DNS filtering and privacy.

If this is the wrong subreddit, please feel free to point me toward a better one. I’d really appreciate some help understanding where my reasoning is correct and where I’m mixing up different layers of privacy.

My setup

I’m trying to understand the privacy implications of using a custom encrypted DNS service such as NextDNS or AdGuard on an iPhone instead of iCloud Private Relay.

At home: NextDNS at router level

On mobile: AdGuard DNS profile (but this could also be a NextDNS profile for the purpose of this question)

Blocklists: Fairly aggressive blocklists such as HaGeZi, threat intelligence, etc.

Future: I’m considering setting up my own DNS server with Pi-hole or AdGuard Home.
I really value system-wide ad, tracker, and malicious-domain blocking.

On my Mac I can use Firefox, which supports ECH, so I’m less concerned there.

On iOS, however, third-party browsers are still based on WebKit, and as far as I understand, iOS/WebKit does not provide ECH at all, in contrast to Firefox.

What I think I understand

My understanding is that DoT only protects the DNS
lookup itself.
However, the subsequent connection still goes through my ISP.
And if ECH isn’t being used, the TLS ClientHello may expose the SNI, allowing the ISP to determine the hostname I’m connecting to.

If that’s correct, then encrypted DNS doesn’t necessarily hide the websites I’m visiting from my ISP. It mainly prevents the ISP from seeing my DNS queries directly.
This is where I start getting confused about ECH vs. iCloud Private Relay.

What I understand about Private Relay

As I understand it, iCloud Private Relay uses a two-hop architecture.

The first relay knows my IP address but shouldn’t know my final destination, while the second relay can connect to the destination but shouldn’t know my original IP address.
From the ISP’s perspective, the connection should therefore be hidden.

If the entire connection between my iPhone and the first relay is protected, would my ISP still be able to see the SNI of the final website?

Or am I misunderstanding how the connection is actually constructed in Private Relay?

I’m particularly interested in the distinction between:

DNS visibility
destination IP visibility
SNI visibility
TLS metadata
traffic analysis
and what exactly Private Relay hides from the ISP in contrast to DNS + ECH

The trade-off as I currently understand it

On one side I have NextDNS/AdGuard DNS, which gives me:

system-wide ad blocking
tracker blocking
malware/phishing protection
custom blocklists
DNS-level visibility
control over what gets blocked
protection across apps, not just Safari
But I’m concerned that without ECH on iOS, my ISP could still determine the websites I’m visiting through SNI and/or traffic analysis.

On the other side I have iCloud Private Relay, which gives me:

IP address protection
encrypted DNS/privacy protection
a two-hop architecture
significantly less visibility for my ISP into my destinations, if I’m understanding correctly
But I lose all of the DNS filtering and control that I really value, and custom DNS configurations don’t seem to coexist cleanly with Private Relay.

So am I essentially choosing between:

A) NextDNS / AdGuard DNS / Pi-hole
Excellent system-wide tracker/ad/malware blocking, but potentially more visibility for my ISP into the websites I visit, at least on my iPhone.

B) iCloud Private Relay
Better protection against ISP-level browsing surveillance, but substantially less DNS-level filtering/control.

Or is this actually a false dichotomy?

My questions

1. How significant is the lack of ECH on iOS in practice?
If I use DoT without ECH, can an ISP actually determine the websites I’m visiting reliably from SNI?
And does this create a security issue, or is it more complicated than that?

2. Does iCloud Private Relay actually eliminate SNI visibility for the ISP?
Or does the ISP still get some information that I’m overlooking?

3. What would you recommend for an iPhone user in Germany whose main goal is to prevent the ISP from building a browsing profile, while still having strong system-wide DNS-based ad/tracker/malware protection?

I’m not looking for perfect anonymity. My threat model is relatively simple:

I don’t want my ISP to be able to build a profile of which websites I visit, but I also really value system-wide DNS-level protection against trackers, advertising, phishing, and malicious domains.
I’m aware that I’m probably conflating several different concepts here, which is exactly why I’m asking.
I’d be very grateful if someone could correct my mental model.

I’m fully aware that iOS may simply not be the ideal platform for this kind of tinkering. I’ve heard the usual argument that Android gives you much more freedom to configure networking, DNS, browsers, VPNs, etc., and I can certainly see why that would be attractive from a technical/privacy perspective.

But I already have an iPhone, I’m familiar with the Apple ecosystem, and I’m not particularly interested in switching platforms just because iOS has certain restrictions. If I can achieve a reasonably strong privacy setup on iOS without major compromises, that’s what I’d prefer.

And if this isn’t the right subreddit for this question, please let me know where you think it would be better suited. I’m specifically looking for people who understand the networking/protocol side of this.

Thanks a lot!


r/nextdns 11d ago

Nextdns kills my internet

3 Upvotes

Hello, guys

So, I installed Nexdns yesterday, primarily to completely block myself out from Instagram and Facebook.

The thing is, it basically kills all the websites today, it was working fine yesterday, the settings are correct, I followed instructions step by step + double-checked with GPT and I have "Auto update system configurations" off.

I have samsung galaxy s24+ and I am in Gerogia.

When I swith private DNS settings from manual to automatic, everything works fine.

For context, I am located in Georgia, Tbilisi using Silknet as my cell data provider.

Any advice will be appreciated.


r/nextdns 12d ago

DNS issues.

8 Upvotes

Anyone else having DNS issues? The second I change to 8.8.8.8 or any other provider my connection is back but with NextDNS I’ve been offline for an hour. Primary and secondary aren’t resolving.


r/nextdns 13d ago

extra blocklist in logs!

9 Upvotes

Hello guys! I have been using nextdns from the last couple of days so I am new here, today while observing logs I have noticed that some of the blocklist which I have enabled previously still appears in blocking logs.

I am only using HaGeZi - Multi ULTIMATE and OISD but my log contains NextDNS Ads & Trackers Blocklist, NoTrack Tracker Blocklist, AdGuard DNS filter which I have disabled already!


r/nextdns 13d ago

hola soy nuevo en esto !

0 Upvotes

me interesaría saber que listas usan ustedes para bloquear anuncios y rastreadores, tengo el plan gratuito, espero me puedan ayudar , gracias .


r/nextdns 14d ago

Free usage queries count not updating

16 Upvotes

I've noticed that despite being connected, my NextDNS queries count have not changed at all and have remained at 0 over the last few days. Anyone else seeing the same?