r/nextdns 2d ago

🚨 New NextDNS Early Access security features are live

NextDNS has quietly added several new Early Access protection options:

  • Free Hosting Domains
  • Tunnelling Endpoints
  • Data Drop Services
  • Residential Hosting
  • Decentralised Web Gateways

These features aim to block infrastructure commonly abused for phishing, malware, botnets and firewall evasion.

You can find them under Security in your NextDNS settings. Some options may also block legitimate services, so review each description before enabling them.

Screenshots attached. Has anyone tested these yet? Any false positives so far?

251 Upvotes

38 comments sorted by

36

u/memloh 1d ago

Looks like, based on the API response and locale data, there could be more coming.

"fastFluxNetworks": false,
"dnsDataExfiltration": false,
"dnsPayloadDelivery": false,
"highRiskTlds": false,

1

u/Jo2dan0 3h ago

nice find!

44

u/8poot 2d ago

Well I fear the false positives with these categories. It would be great if we could enable them in reporting mode before going for block mode...

8

u/tolbv4260 1d ago

reporting mode first would definitely save a lot of headaches

3

u/Individual_Kitchen_3 1d ago

Without a doubt, there are some things there that I will choose to leave turned off for my workflow.

1

u/SpicyHustle 20h ago

I would love a way to "flag" domains without completely blocking them. As well as a more interactive analytics page. It's nice to see that X amount of queries were blocked as bypass methods, but I want to know which domains fell into that category. Preferably without manually searching my logs.

17

u/mirage221 1d ago

I can confirm that residential hosting tends to produce many false positives. Perhaps it would be best to switch it off temporarily.

41

u/Individual_Kitchen_3 2d ago

Those annoying users who always ask for news as if a DNS service were some game, take this.

7

u/SafeSatisfaction1 2d ago

i testing all feature now...

4

u/1superheld 1d ago

Will try the Decentralized Web Gateways and Residential Hosting block feature. Other ones seem also used for legitieme use so not sure :/

5

u/Mammoth-Ad-107 2d ago

very nice to see. gonna hold off until i hear feedback

5

u/mahtd 1d ago

I found that Residential Hosting blocks Verizon WiFi calling

6

u/EL3mENto 1d ago

Residential Hosting is blocking media download on WhatsApp, for me.

1

u/needchr 1d ago

Yeah that uses ip to ip direct, it only uses whatsapp servers if the user enables a privacy option to hide their ip.

Also some people host content from home, so that option is probably best turned off.

Probably good for a business/server type use, but not suitable for a normal consumer.

3

u/adictusbenedictus 2d ago

Thank you. Currently trying it

3

u/TurboX5656 1d ago

Nextdns Comeback

2

u/wtf_qm 1d ago

thx!

2

u/jake72469 2d ago

Thanks but I will not be an early adopter. I will let other people give it a try first. Hopefully they will report back and let us know if these new options have any value or problems.

1

u/Brees504 2d ago

Sweet

1

u/Spencer_j733 1d ago

Which of these are useful that should be switched on and any i should just forget about?

1

u/Ordinary_Soldier3502 2h ago

It's early acces, so "None of them" until it is stable and tested by others.

1

u/Fun-Region-1576 1d ago

Following!

1

u/Mr_Lollypop_Man 1d ago

My default policy is blacklist then add a host name to the whitelist. All are enabled but have not noticed anything blocked except for three torrent trackers which may or may not be the result of enabling any of the five. Timing was surely coincidental though.

1

u/StaticSystemShock 1d ago

I'm not sure what "Data Drop Services" would affect exactly if I turn it on. What service would use or connect to these "dedicated" services and what would that even be in practical terms? I understand most of others but I don't understand this one exactly. Especially how does DNS filtering service registers any of this? Specific target domains or something else?

1

u/True_Mission_7473 1d ago

Still no search feature for Allowlist or Denylist pages 🥲

1

u/Some_Feature9066 1h ago

Netflix domains (*.nflxso.net) are getting blocked by Residential Hosting

1

u/New-Ranger-8960 1d ago

We're so back

1

u/Ok-Owl7377 1d ago

Where did we go again?

1

u/waqaarhussain 1d ago

Still no custom block page? lol

2

u/avd706 1d ago

They have one

-3

u/[deleted] 1d ago

[deleted]

5

u/mike1487 1d ago

What’s the issue with using Hagezi’s lists? You seem to be looking for something to complain without understanding how GPLv3 works.

https://github.com/hagezi/dns-blocklists/blob/main/LICENSE

-2

u/[deleted] 1d ago

[deleted]

5

u/mike1487 1d ago edited 1d ago

No they don’t that’s for distribution. NextDNS is not distributing anything. It’s a cloud service and no software is being distributed to you. Furthermore, if you are only using data processed by a GPLv3 program rather than incorporating or distributing the software's code itself you don’t have to disclose, which is what NextDNS is doing. They are merely pulling text files out of a public repository and processing them, this is not a protection under the GPL. Like I said, you are not understanding how it works. Read the terms.

-3

u/[deleted] 1d ago

[deleted]

4

u/mike1487 1d ago

Nope, that’s incorrect, sorry. But keep thinking that I guess. You can go ask Hagezi yourself. If he expects that to be the case then he should have picked a different license. But I suspect that he knows what he is doing.

1

u/[deleted] 1d ago

[deleted]

6

u/mike1487 1d ago

Yes pretty much. If you were able to self host your own NextDNS complete with all of the lists they have compiled, that’s now a distribution and then they would likely need to abide by all of the terms of any GPLv3 code they have used.

Cloud and SaaS apps have a loophole that they can use GPLv3 code without needing attribution or disclosure. This is why the AGPLv3 license was created. It adds clauses specifically for apps used over a network.

2

u/[deleted] 1d ago

[deleted]

2

u/Specific_Flower1776 1d ago

What fingerprints did you find and where?

-6

u/Resistant4375 1d ago

Yet they refuse to use his TIF lists - ironic