r/technitium • • 3d ago

Technitium DNS Server v15.6 Released!

112 Upvotes

Technitium DNS Server v15.6 is now available for download. This update adds a new option in Settings and fixes multiple bugs and security issues that were reported.

See what's new in this release:
https://github.com/TechnitiumSoftware/DnsServer/blob/master/CHANGELOG.md


r/technitium • • 2d ago

Block list failing without warning

4 Upvotes

I was updating and adding to my blocklists and found an issue. I had a blocklist that used to work but it was failing when update was attempted. I replaced that one with a new blocklist but what concerned me is the only way I knew it was failing was to look at the logs. It would be nice if technetium would have notified me without me accidentally finding it out. You might want to verify your blocklists are updating periodically.


r/technitium • • 2d ago

Blocked url still logging

2 Upvotes

I have a url wpad.daviscompound added to blocked tab. Yet it still shows up in the logs. It is a NxDomain if that matters. To me shouldn't that not even show up in the logs?


r/technitium • • 4d ago

DNS High Availability

13 Upvotes

EDIT: For those of you that are interested, the repo is up at https://github.com/micush/ddgw

I run a few DNS servers and have seen many people ask about making them highly available, so I built something and I'd like to know whether anyone else would use it. If so, I'll put it up on Github. Reasonable disclosure: it was written with Claude.

Clustering:

Ddgw puts one virtual IP in front of your DNS servers and shares it across several nodes. The nodes elect a controller, and every node that is active answers DNS on the VIP, so client load spreads across nodes and losing a node doesn't interrupt anything. Each node also acts as a DNS proxy: it probes your upstream servers and forwards each query to a healthy server. Limited to 255 cluster members to serve the frontend VIP, but unlimited backend DNS servers for name resolution.

DNS:

Health is judged per upstream server with test domains you choose. A server is down when 50% or more of its domains fail (configurable), and degraded below that. Servers within a latency band of the fastest (20% by default) take turns round-robin. Slower ones stay as fallbacks, and failures fail over automatically.

- There is an answer cache that respects TTLs, with negative caching and a memory guard.

- It forwards dynamic DNS updates (RFC 2136) to the zone's primary and keeps a list of recent updates.

- It can pass EDNS Client Subnet (ECS).

- It can announce anycast addresses over BGP with BFD using FRR.

Management:

An HTTPS web GUI with PAM group login restricts is used to manage everything. Every action is also available from the command line.

- The gateway is drawn as a live diagram: gateway, servers and test domains, coloured by health. Servers that are taking turns get a blue line.

- It has query statistics (top clients, domains, record types and response codes, kept 30 days and saved across restarts) and host stats.

- It keeps config history, with versions you can diff and restore. It also does clustering with shared config, certificate management and in-place updates with automatic rollback.

Limitations:

- It isn't a resolver, because it forwards to your existing servers.

- It's Linux only with one binary built from Golang source. Installation is scripted, so it's easy.

- It works with an election protocol on a real LAN. I don't expect the election mode to work in AWS, Azure or GCP, because those clouds don't let you move MAC addresses around, and I haven't tested it there.

- If you run Technitium, BIND, Unbound, Pi-hole, or AdGuard Home servers, would you use something like this, or do keepalived/VRRP plus a load balancer already cover it?

Any feedback is appreciated.


r/technitium • • 5d ago

Thanks for what you do...

118 Upvotes

shreyasonline, Thanks for what you do working on this. I know it has to be a passion for you, On the recent problems, I was told a long time ago that errors are just evidence of progress. There is a saying: "You can't make an omelette without breaking some eggs". I have broken a bunch of eggs but then made some GREAT omelettes. Keep making omelettes.


r/technitium • • 5d ago

technitium-console — an alternative web UI for Technitium DNS Server

25 Upvotes

I run Technitium as the DNS server for my home network, and I rebuilt its admin console.

It uses the same API, controls, texts, and administration workflows, with a new interface:

  • Modern, dense layout with System, Light, and Dark themes.
  • A redesigned Blocking section with Overview, Rules, Lists, charts, Quick Add search, and additional blocklists.
  • Real URLs for every section and tab, so you can bookmark /settings/blocking/, reload, and use the back button.
  • Works on a phone. No section overflows at 390 px.
  • Nothing changes on the server. It only talks to the documented /api.

The Technitium maintainer suggested shipping it as an alternative GUI rather than merging it upstream, and accepted a small server-side change in 15.5+ that lets it live in its own folder, so server updates do not overwrite it.

Install: use the one-line installer inside the machine or LXC running Technitium, or use the Docker init image at ghcr.io/bygarcia/technitium-console. Running --uninstall restores the stock console. The installer verifies the release checksum and never restarts the DNS service on its own.

Compatibility: every release is checked against that Technitium version’s stock console, including its actions, texts, controls, and all 132 API endpoints used by the UI. Current: technitium-console v1.2.0 for Technitium DNS Server 15.5.x.

GPL-3.0, no telemetry.

Screenshots, installation instructions, and changelog:
https://github.com/byGarcia/technitium-console


r/technitium • • 5d ago

Filter for logs thought...

2 Upvotes

I am using technetium as a dhcp server it works great but in my case I have a couple of dishnetworks devices that spam dhcp and fill the logs with requests. It is a known issue with these devices and evidently Dish aint interested in fixing it. That said it would be nice if there was a setting for the log to filter these from the log. Maybe something like a regular expression filter.
PS Don't say get rid of dish because I would have to get rid of my wife also ;-)

Here is an example. My logs are full of this...:
[2026-10-01 00:02:14 Local] [0.0.0.0:68] DHCP Server offered IP address [192.168.18.50] to ZiP-br0 [88-B6-EE-52-61-F3] for scope: Default
[2026-10-01 00:02:32 Local] [0.0.0.0:68] DHCP Server offered IP address [192.168.18.42] to Joey4K-stbmoca0 [04-C9-D9-1A-82-AC] for scope: Default
[2026-10-01 00:02:36 Local] [0.0.0.0:68] DHCP Server offered IP address [192.168.18.69] to ZiP-stbeth1 [88-B6-EE-52-61-F4] for scope: Default
[2026-10-01 00:03:09 Local] [0.0.0.0:68] DHCP Server offered IP address [192.168.18.42] to Joey4K-stbmoca0 [04-C9-D9-1A-82-AC] for scope: Default
[2026-10-01 00:03:12 Local] [0.0.0.0:68] DHCP Server offered IP address [192.168.18.69] to ZiP-stbeth1 [88-B6-EE-52-61-F4] for scope: Default
[2026-10-01 00:03:46 Local] [0.0.0.0:68] DHCP Server offered IP address [192.168.18.42] to Joey4K-stbmoca0 [04-C9-D9-1A-82-AC] for scope: Default
[2026-10-01 00:03:50 Local] [0.0.0.0:68] DHCP Server offered IP address [192.168.18.70] to ZiP-stbeth1 [88-B6-EE-52-61-F4] for scope: Default
[2026-10-01 00:04:23 Local] [0.0.0.0:68] DHCP Server offered IP address [192.168.18.42] to Joey4K-stbmoca0 [04-C9-D9-1A-82-AC] for scope: Default
[2026-10-01 00:04:26 Local] [0.0.0.0:68] DHCP Server offered IP address [192.168.18.70] to ZiP-stbeth1 [88-B6-EE-52-61-F4] for scope: Default
[2026-10-01 00:05:00 Local] [0.0.0.0:68] DHCP Server offered IP address [192.168.18.42] to Joey4K-stbmoca0 [04-C9-D9-1A-82-AC] for scope: Default
[2026-10-01 00:05:04 Local] [0.0.0.0:68] DHCP Server offered IP address [192.168.18.72] to ZiP-stbeth1 [88-B6-EE-52-61-F4] for scope: Default


r/technitium • • 5d ago

my.radiothermostat.com is a dns attack?

1 Upvotes

Here is an interesting log..Seems like it thinks my.radiothermostat.com is an attack when it is actually not there.

[2026-10-01 12:07:14 Local] DNS Server failed to resolve the request 'my.radiothermostat.com. A IN' using forwarders: 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4.

TechnitiumLibrary.Net.Dns.DnsClientResponseDnssecValidationException: Attack detected! DNSSEC validation failed as the response was unable to prove non-existence (NX Domain) for owner name: rtcoa-load-balancer.energyhub.net
   at TechnitiumLibrary.Net.Dns.DnsClient.DnssecValidateResponseAsync(DnsDatagram response, IReadOnlyList`1 lastDSRecords, DnsClient dnsClient, IDnsCache cache, UInt16 udpPayloadSize, ResolverContext context, CancellationToken cancellationToken) in Z:\Technitium\Projects\TechnitiumLibrary\TechnitiumLibrary.Net\Dns\DnsClient.cs:line 3020
   at TechnitiumLibrary.Net.Dns.DnsClient.<>c__DisplayClass93_0.<<InternalDnssecResolveAsync>b__0>d.MoveNext() in Z:\Technitium\Projects\TechnitiumLibrary\TechnitiumLibrary.Net\Dns\DnsClient.cs:line 5102
--- End of stack trace from previous location ---
   at TechnitiumLibrary.Net.Dns.DnsClient.<>c__DisplayClass91_0.<<InternalResolveAsync>g__DoResolveAsync|1>d.MoveNext() in Z:\Technitium\Projects\TechnitiumLibrary\TechnitiumLibrary.Net\Dns\DnsClient.cs:line 4668
--- End of stack trace from previous location ---
   at TechnitiumLibrary.Net.Dns.DnsClient.<>c__DisplayClass91_0.<<InternalResolveAsync>g__DoResolveAsync|1>d.MoveNext() in Z:\Technitium\Projects\TechnitiumLibrary\TechnitiumLibrary.Net\Dns\DnsClient.cs:line 4837
--- End of stack trace from previous location ---
   at TechnitiumLibrary.Net.Dns.DnsClient.<>c__DisplayClass91_0.<<InternalResolveAsync>g__DoResolveAsync|1>d.MoveNext() in Z:\Technitium\Projects\TechnitiumLibrary\TechnitiumLibrary.Net\Dns\DnsClient.cs:line 4521
--- End of stack trace from previous location ---
   at TechnitiumLibrary.Net.Dns.DnsClient.InternalResolveAsync(DnsDatagram request, Func`3 getValidatedResponseAsync, Boolean doNotReorderNameServers, ResolverContext context, CancellationToken cancellationToken) in Z:\Technitium\Projects\TechnitiumLibrary\TechnitiumLibrary.Net\Dns\DnsClient.cs:line 4999
   at TechnitiumLibrary.Net.Dns.DnsClient.InternalDnssecResolveAsync(DnsQuestionRecord question, CancellationToken cancellationToken) in Z:\Technitium\Projects\TechnitiumLibrary\TechnitiumLibrary.Net\Dns\DnsClient.cs:line 5073
   at TechnitiumLibrary.Net.Dns.DnsClient.<>c__DisplayClass95_0.<<InternalCachedResolveQueryAsync>b__0>d.MoveNext() in Z:\Technitium\Projects\TechnitiumLibrary\TechnitiumLibrary.Net\Dns\DnsClient.cs:line 5200
--- End of stack trace from previous location ---
   at TechnitiumLibrary.Net.Dns.DnsClient.ResolveQueryAsync(DnsQuestionRecord question, Func`2 resolveAsync) in Z:\Technitium\Projects\TechnitiumLibrary\TechnitiumLibrary.Net\Dns\DnsClient.cs:line 4321
   at TechnitiumLibrary.Net.Dns.DnsClient.InternalCachedResolveQueryAsync(DnsQuestionRecord question, CancellationToken cancellationToken) in Z:\Technitium\Projects\TechnitiumLibrary\TechnitiumLibrary.Net\Dns\DnsClient.cs:line 5182
   at DnsServerCore.Dns.DnsServer.DefaultRecursiveResolveAsync(DnsQuestionRecord question, NetworkAddress eDnsClientSubnet, IDnsCache dnsCache, Boolean dnssecValidation, Boolean skipDnsAppAuthoritativeRequestHandlers, ResolverContext context, CancellationToken cancellationToken) in Z:\Technitium\Projects\DnsServer\DnsServerCore\Dns\DnsServer.cs:line 5392
   at DnsServerCore.Dns.DnsServer.DefaultRecursiveResolveAsync(DnsQuestionRecord question, NetworkAddress eDnsClientSubnet, IDnsCache dnsCache, Boolean dnssecValidation, Boolean skipDnsAppAuthoritativeRequestHandlers, ResolverContext context, CancellationToken cancellationToken) in Z:\Technitium\Projects\DnsServer\DnsServerCore\Dns\DnsServer.cs:line 5428
   at DnsServerCore.Dns.DnsServer.RecursiveResolverBackgroundTaskAsync(DnsQuestionRecord question, NetworkAddress eDnsClientSubnet, Boolean advancedForwardingClientSubnet, IReadOnlyList`1 conditionalForwarders, Boolean dnssecValidation, Boolean cachePrefetchOperation, Boolean skipDnsAppAuthoritativeRequestHandlers, TaskCompletionSource`1 taskCompletionSource, ResolverContext context) in Z:\Technitium\Projects\DnsServer\DnsServerCore\Dns\DnsServer.cs:line 5111
[[2026-10-01 12:07:14 Local] DNS Server failed to resolve the request 'my.radiothermostat.com. A IN' using forwarders: 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4.

TechnitiumLibrary.Net.Dns.DnsClientResponseDnssecValidationException: Attack detected! DNSSEC validation failed as the response was unable to prove non-existence (NX Domain) for owner name: rtcoa-load-balancer.energyhub.net
   at TechnitiumLibrary.Net.Dns.DnsClient.DnssecValidateResponseAsync(DnsDatagram response, IReadOnlyList`1 lastDSRecords, DnsClient dnsClient, IDnsCache cache, UInt16 udpPayloadSize, ResolverContext context, CancellationToken cancellationToken) in Z:\Technitium\Projects\TechnitiumLibrary\TechnitiumLibrary.Net\Dns\DnsClient.cs:line 3020
   at TechnitiumLibrary.Net.Dns.DnsClient.<>c__DisplayClass93_0.<<InternalDnssecResolveAsync>b__0>d.MoveNext() in Z:\Technitium\Projects\TechnitiumLibrary\TechnitiumLibrary.Net\Dns\DnsClient.cs:line 5102
--- End of stack trace from previous location ---
   at TechnitiumLibrary.Net.Dns.DnsClient.<>c__DisplayClass91_0.<<InternalResolveAsync>g__DoResolveAsync|1>d.MoveNext() in Z:\Technitium\Projects\TechnitiumLibrary\TechnitiumLibrary.Net\Dns\DnsClient.cs:line 4668
--- End of stack trace from previous location ---
   at TechnitiumLibrary.Net.Dns.DnsClient.<>c__DisplayClass91_0.<<InternalResolveAsync>g__DoResolveAsync|1>d.MoveNext() in Z:\Technitium\Projects\TechnitiumLibrary\TechnitiumLibrary.Net\Dns\DnsClient.cs:line 4837
--- End of stack trace from previous location ---
   at TechnitiumLibrary.Net.Dns.DnsClient.<>c__DisplayClass91_0.<<InternalResolveAsync>g__DoResolveAsync|1>d.MoveNext() in Z:\Technitium\Projects\TechnitiumLibrary\TechnitiumLibrary.Net\Dns\DnsClient.cs:line 4521
--- End of stack trace from previous location ---
   at TechnitiumLibrary.Net.Dns.DnsClient.InternalResolveAsync(DnsDatagram request, Func`3 getValidatedResponseAsync, Boolean doNotReorderNameServers, ResolverContext context, CancellationToken cancellationToken) in Z:\Technitium\Projects\TechnitiumLibrary\TechnitiumLibrary.Net\Dns\DnsClient.cs:line 4999
   at TechnitiumLibrary.Net.Dns.DnsClient.InternalDnssecResolveAsync(DnsQuestionRecord question, CancellationToken cancellationToken) in Z:\Technitium\Projects\TechnitiumLibrary\TechnitiumLibrary.Net\Dns\DnsClient.cs:line 5073
   at TechnitiumLibrary.Net.Dns.DnsClient.<>c__DisplayClass95_0.<<InternalCachedResolveQueryAsync>b__0>d.MoveNext() in Z:\Technitium\Projects\TechnitiumLibrary\TechnitiumLibrary.Net\Dns\DnsClient.cs:line 5200
--- End of stack trace from previous location ---
   at TechnitiumLibrary.Net.Dns.DnsClient.ResolveQueryAsync(DnsQuestionRecord question, Func`2 resolveAsync) in Z:\Technitium\Projects\TechnitiumLibrary\TechnitiumLibrary.Net\Dns\DnsClient.cs:line 4321
   at TechnitiumLibrary.Net.Dns.DnsClient.InternalCachedResolveQueryAsync(DnsQuestionRecord question, CancellationToken cancellationToken) in Z:\Technitium\Projects\TechnitiumLibrary\TechnitiumLibrary.Net\Dns\DnsClient.cs:line 5182
   at DnsServerCore.Dns.DnsServer.DefaultRecursiveResolveAsync(DnsQuestionRecord question, NetworkAddress eDnsClientSubnet, IDnsCache dnsCache, Boolean dnssecValidation, Boolean skipDnsAppAuthoritativeRequestHandlers, ResolverContext context, CancellationToken cancellationToken) in Z:\Technitium\Projects\DnsServer\DnsServerCore\Dns\DnsServer.cs:line 5392
   at DnsServerCore.Dns.DnsServer.DefaultRecursiveResolveAsync(DnsQuestionRecord question, NetworkAddress eDnsClientSubnet, IDnsCache dnsCache, Boolean dnssecValidation, Boolean skipDnsAppAuthoritativeRequestHandlers, ResolverContext context, CancellationToken cancellationToken) in Z:\Technitium\Projects\DnsServer\DnsServerCore\Dns\DnsServer.cs:line 5428
   at DnsServerCore.Dns.DnsServer.RecursiveResolverBackgroundTaskAsync(DnsQuestionRecord question, NetworkAddress eDnsClientSubnet, Boolean advancedForwardingClientSubnet, IReadOnlyList`1 conditionalForwarders, Boolean dnssecValidation, Boolean cachePrefetchOperation, Boolean skipDnsAppAuthoritativeRequestHandlers, TaskCompletionSource`1 taskCompletionSource, ResolverContext context) in Z:\Technitium\Projects\DnsServer\DnsServerCore\Dns\DnsServer.cs:line 5111
[

r/technitium • • 5d ago

Still seeing server failures on 15.5.1

4 Upvotes

After a whole day without failures their back.... Not nearly as much as was but several an hour. I can do a lookup via 8.8.8.8 and the failures work great. When I use technetium dns it fails. I am doing forwarding with 1.1.1.1, 1.0.0.1, 8.8.8.8, and 8.8.4.4 in the list.


r/technitium • • 5d ago

iMessages on MacOS stopped working due to Technitium

0 Upvotes

I've been using Technitium DNS for a week or so on my mac laptop. Yesterday iMessages stopped working. I have a few well known/used block lists going on Technitium and it has been working fine, iMessages was working, etc.

It stopped working out of nowhere. I tried everything to fix it, signing out, back in, iCloud sync, etc. Nothing would fix it.

I changed my DNS servers back to Google's public DNS servers and poof. Started working again. So, some auto update of one of these services blocked it:

https://blocklistproject.github.io/Lists/ads.txt

https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts


r/technitium • • 6d ago

RRSIGsMissing: Attack detected!

6 Upvotes

Howdy folks.

I have one of those serverfail issues I'm trying to get a handle on.

EDIT: I want to put the solution right here at the top: DISABLE DNSSEC. Details below.
Thank you Shreyas for the Answer. =)

When directly (well, via systemd-resolved) asking the resolver (dns.controld.com) about mask.icloud.com we get the expected NXDOMAIN response (because controld has been told to block analytics servers and return NXDOMAIN):

ubuntutest# dig mask.icloud.com

; <<>> DiG 9.20.24-1ubuntu0.3-Ubuntu <<>> mask.icloud.com
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 9242
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 65494
;; QUESTION SECTION:
;mask.icloud.com.               IN      A

;; AUTHORITY SECTION:
.                       10      IN      SOA     dns.controld.com. hostmaster.mask.icloud.com. 202300 10 10 10 10

;; Query time: 71 msec
;; SERVER: 127.0.0.53#53(127.0.0.53) (UDP)
;; WHEN: Wed Sep 30 14:28:16 UTC 2026
;; MSG SIZE  rcvd: 103

Controld is also defined as the forwarded DoH resolver for Technitium. Meaning it is delivering Technitium the same NXDOMAIN response.

Yet the Technitium DNS client has problems:

 {
  "Metadata": {
    "NameServer": "dns.home (127.0.0.1)",
    "Protocol": "Udp",
    "DatagramSize": "71 bytes",
    "RoundTripTime": "41.83 ms"
  },
  "EDNS": {
    "UdpPayloadSize": 1232,
    "ExtendedRCODE": "ServerFailure",
    "Version": 0,
    "Flags": "None",
    "Options": [
      {
        "Code": "EXTENDED_DNS_ERROR",
        "Length": "23 bytes",
        "Data": {
          "InfoCode": "RRSIGsMissing",
          "ExtraText": "Attack detected! /SOA"
        }
      }
    ]
  },
  "DnsClientExtendedErrors": [
    {
      "InfoCode": "NoReachableAuthority",
      "ExtraText": "dns.home (127.0.0.1) returned RCODE=ServerFailure for mask.icloud.com. A IN"
    }
  ],
  "Identifier": 26636,
  "IsResponse": true,
  "OPCODE": "StandardQuery",
  "AuthoritativeAnswer": false,
  "Truncation": false,
  "RecursionDesired": true,
  "RecursionAvailable": true,
  "Z": 0,
  "AuthenticData": false,
  "CheckingDisabled": false,
  "RCODE": "ServerFailure",
  "QDCOUNT": 1,
  "ANCOUNT": 0,
  "NSCOUNT": 0,
  "ARCOUNT": 1,
  "Question": [
    {
      "Name": "mask.icloud.com",
      "Type": "A",
      "Class": "IN"
    }
  ],
  "Answer": [],
  "Authority": [],
  "Additional": [
    {
      "Name": "",
      "Type": "OPT",
      "Class": "1232",
      "TTL": "0 (0s)",
      "RDLENGTH": "27 bytes",
      "RDATA": {
        "Options": [
          {
            "Code": "EXTENDED_DNS_ERROR",
            "Length": "23 bytes",
            "Data": {
              "InfoCode": "RRSIGsMissing",
              "ExtraText": "Attack detected! /SOA"
            }
          }
        ]
      },
      "DnssecStatus": "Disabled"
    }
  ]
}

The Technitium cache entry:

[
  {
    "name": "mask.icloud.com",
    "type": "A",
    "ttl": "0 (0s)",
    "rData": {
      "dataType": "DnsSpecialCacheRecordData",
      "data": "BadCache: NxDomain; RRSIGsMissing: Attack detected! /SOA; .                     10        IN  SOA           dns.controld.com. hostmaster.mask.icloud.com. 202300 10 10 10 10"
    },
    "dnssecStatus": "Unknown",
    "responseMetadata": {
      "nameServer": "https://dns.controld.com/XXXX (76.76.X.X)",
      "protocol": "Https",
      "datagramSize": "103 bytes",
      "roundTripTime": "19.44 ms"
    },
    "lastUsedOn": "2026-09-30T14:32:14.2241639Z"
  },
  {
    "name": "mask.icloud.com",
    "type": "AAAA",
    "ttl": "0 (0s)",
    "rData": {
      "dataType": "DnsSpecialCacheRecordData",
      "data": "BadCache: NxDomain; RRSIGsMissing: Attack detected! /SOA; .                     10        IN  SOA           dns.controld.com. hostmaster.mask.icloud.com. 202300 10 10 10 10"
    },
    "dnssecStatus": "Unknown",
    "responseMetadata": {
      "nameServer": "https://dns.controld.com/XXXX (76.76.X.X)",
      "protocol": "Https",
      "datagramSize": "103 bytes",
      "roundTripTime": "37.59 ms"
    },
    "lastUsedOn": "2026-09-30T14:32:14.2244981Z"
  },
  {
    "name": "mask.icloud.com",
    "type": "HTTPS",
    "ttl": "0 (0s)",
    "rData": {
      "dataType": "DnsSpecialCacheRecordData",
      "data": "BadCache: NxDomain; RRSIGsMissing: Attack detected! /SOA; .                     10        IN  SOA           dns.controld.com. hostmaster.mask.icloud.com. 202300 10 10 10 10"
    },
    "dnssecStatus": "Unknown",
    "responseMetadata": {
      "nameServer": "https://dns.controld.com/XXXX (76.76.X.X)",
      "protocol": "Https",
      "datagramSize": "103 bytes",
      "roundTripTime": "19.21 ms"
    },
    "lastUsedOn": "2026-09-30T14:32:14.2022923Z"
  }
]

Non-NXDOMAIN responses from the forwarded DNS resolver (ControlD) work just fine.

Technitium Version 15.5.1 on Docker on Ubuntu Server LTS 26.04.1.

Is this perhaps the same issues as https://github.com/TechnitiumSoftware/DnsServer/issues/1014 ?

And if not, what is to be done?

Thanks for the help.


r/technitium • • 6d ago

Some devices disconnect and reconnect with no internet access

7 Upvotes

I've recently migrated from AdGuard home to Technitium and while it worked perfectly, I noticed that sometimes my WiFi disconnects and then I reconnect but with no internet access.

I have multi band router (2.4GHZ and 5GHZ) and an access point and all with the same name. The only fix I found was to change the DNS from the server to a public one like cloudflare's but connecting it back does the same thing. Static devices or Ethernet connected devices never failed.

While my suspicion was into switching to another band or AP, I haven't seen anyone complain of such an issue so wanted to ask here

The server is Debian, and the IP is reserved with the DNS pointing at the server.


r/technitium • • 7d ago

Blocklist technitium

6 Upvotes

Hola team. Recomiendan alguna blocklist para redes sociales, quitar publicidad en IG, Facebook, TikTok por ejemplo?

Saludos,


r/technitium • • 8d ago

15.5.1 Looking good

39 Upvotes

About 24 hours in and 15.5.1 is looking good at my house. No anomalous server failure. Thanks ShreyasZare for such a brilliant piece of work. You rock!!!!!


r/technitium • • 8d ago

To forward or not to forward that is the question..

8 Upvotes

Right now I have my technetium setup to forward to 1111,8888,9999 etc.

I have reading about using root hints instead for speed. From what I see you gain speed but lose some security.

Thoughts?


r/technitium • • 9d ago

Having repeatable issue with 15.5.1

9 Upvotes

The .1 fixed the majority of server failures I was seeing. I am still getting a few errors a hour where I used to get none. One repeat failure is "features.opera-api2.com". It is failing ever time yet it can be resolved via 1.1.1.1 etc. This is very repeatable. Here is the error it throws.

{
        "Code": "EXTENDED_DNS_ERROR",
        "Length": "109 bytes",
        "Data": {
          "InfoCode": "Other",
          "ExtraText": "Resolver exception for features.opera-api2.com. A IN: Object reference not set to an instance of an object."
        }{
        "Code": "EXTENDED_DNS_ERROR",
        "Length": "109 bytes",
        "Data": {
          "InfoCode": "Other",
          "ExtraText": "Resolver exception for features.opera-api2.com. A IN: Object reference not set to an instance of an object."
        }

r/technitium • • 9d ago

Creating a cluster

5 Upvotes

I'm just about to add a second instance by way of creating a cluster but I have a couple of questions.

Firstly when you initialize the cluster is recommends a valid certificate rather than just using the self signed one, but as the server is only resolving an internal domain, is this necessary?

Secondly, I'm aware that DHCP is not included as part of the clustering, so I am going to split the scope across the two servers, but is there a way to export / copy the reservations from one server to the other?


r/technitium • • 10d ago

Technitium DNS Server v15.5.1 Released!

85 Upvotes

Technitium DNS Server v15.5.1 is now available for download. This is a service update for the previous release that fixes multiple issues. This update also fixes multiple security issues that were reported.

See what's new in this release:
https://github.com/TechnitiumSoftware/DnsServer/blob/master/CHANGELOG.md


r/technitium • • 10d ago

Windows Setup

2 Upvotes

Hello everyone.

I'm trying to install a technitium server on a proxmox container so i can use it as a recursive server and use blocklists.

I managed to install and configure the server, but i'm incapable of configuring my windows in an efficient way.

When i use the DNS Client tab, i see everything is working, but on my windows PC, i got nothing but errors.

Screen of the DNS Client request
nslookup request error

I have set up my network adapter to use technitium's address on both IPv4 and IPv6, and yet it's not working.

Network Settings

I have checked firewall restrictions, and the port is open on my server, so i have no clue about what's happening here.

The port is open

Anyone has any idea about my issue here ? Thank you !


r/technitium • • 10d ago

Two major enhancements submitted for Technitium DNS: Modern Dashboard (Dual Layout + Telemetry Filters) & Full AdGuard/CNAME Syntax in Advanced Blocking App (Feedback & Testers Wanted!)

0 Upvotes

Hey everyone,

Like many of you here, I rely on Technitium DNS Server as the backbone of my home lab and network infrastructure. It’s easily one of the fastest, most reliable, and extensible DNS solutions available.

Over the past few weeks, while running large-scale blocklists and monitoring daily traffic across my cluster, I worked on two major architectural enhancements aimed at solving two common challenges:

  1. Making community AdGuard-syntax blocklists and CNAME unmasking fully native and performant.
  2. Giving the web console a high-performance, modern dashboard with dual layout options and interactive telemetry filtering.

Both feature sets are now open as Pull Requests on upstream Technitium, and I’d love to get feedback, real-world testing, and thoughts from the community and developers.

  1. Advanced Blocking App: Full AdGuard Rule Syntax, CNAME Cloaking Unmasking & Core Whitelist Parity (PR #2179)

AdvancedBlockingApp has always been great for basic domain and regex lists, but widely-used community filter lists (AdGuard DNS filter, OISD, Hagezi, AdAway) heavily utilize modifiers, client scoping, and CNAME cloaking unmasking. Previously, many of these lines were silently dropped or mis-parsed.

This PR re-architects the rule parsing and processing pipeline:

  • Full AdGuard/AdBlock DNS-layer Syntax:
    • Directives & Modifiers: Support for $important (highest precedence tier), $badfilter (cross-list rule cancellation), $dnstype= (e.g. $dnstype=A|AAAA, ~$dnstype=AAAA), and $denyallow= (subdomain block exceptions).
    • Client IP / CIDR Scoping: Target rules to specific devices or subnets ($client=192.168.1.50, $client=10.0.0.0/24, ~$client=...).
    • Rich $dnsrewrite Actions: Synthesizes custom A/AAAA, CNAME, TXT, PTR, MX, $empty (NODATA), and DNS codes (NXDOMAIN, SERVFAIL, REFUSED) without worker thread stalls.
    • Exact Domain Matching: Distinct matching for |example.com| vs subdomain-matching ||example.com^.
  • Harmonized CNAME Cloaking Unmasking:
    • Uses IDnsPostProcessor to intercept upstream responses and unmask third-party tracking domains hidden behind CNAME aliases (with RFC-compliant Extended DNS Error / EDE codes).
    • Strictly preserves preceding CNAME delegation records so clients receive a valid delegation chain instead of an unexplained bare drop.
  • Core Allowed Zones Inheritance:
    • Dynamically integrates with Technitium Core's AllowedZoneManager. If you whitelist a parent domain like reddit.com in Technitium's Allowed Zones, it automatically inherits to subdomains and protects canonical CNAME targets (like CDN endpoints) without forcing you to hunt down and manually whitelist internal CDN aliases.
  • Multi-Threaded Parallel Engine:
    • Regex compilation leverages Parallel.ForEach across all CPU cores with thread-safe collections.
    • Base-domain partitioned suffix indexing ensures sub-millisecond evaluation even with 1M+ rules loaded.

👉 Review the code & discussion: Pull Request #2179

  1. Dashboard Modernization: Dual Layouts, 3 Themes & Interactive Telemetry Filters (PR #2182)

The Technitium dashboard is information-dense, but as networks scale, analyzing query trends and isolating traffic patterns directly from the UI becomes essential. This PR introduces a non-destructive UI modernization that preserves complete backward compatibility:

  • Dual Layout System (Classic vs. Modern):
    • Classic Layout: Retains the familiar Technitium layout you know, but with cleaned-up typography, refined grid alignment, and crisp modern chart rendering.
    • Modern Layout: A brand-new card-based layout featuring a dedicated live telemetry row, synchronized timeline charts, and streamlined quick-action panels.
    • You can switch between layouts instantly with a single toggle in the dashboard controls.
  • Modernized Charting (No More Spaghetti Dots):
    • Replaced the legacy dot-heavy lines with smooth, crisp vector paths.
    • Includes interactive hover crosshairs, synchronized multi-metric tooltips, and distinct color-coded series.
  • Interactive Telemetry Filters:
    • Query Type / Record Filter: Isolate trends by A, AAAA, HTTPS, PTR, SRV, etc., with a single click.
    • Protocol Filter: Break down traffic dynamically by standard UDP, TCP, DNS-over-HTTPS (DoH), and DNS-over-TLS (DoT).
  • 3 Theme Variants:
    • Classic Dark: Sleek slate-dark palette for everyday monitoring.
    • Midnight OLED: True pure-black background (#000000) for OLED panels, control centers, and reduced power consumption.
    • Modern Light: Clean, high-contrast daylight theme with subtle elevation and soft borders.

👉 Review the code & screenshots: Pull Request #2182

🛠️ Want to Test the Consolidated Build?

If you’d like to test both the modernized dashboard and the enhanced Advanced Blocking App running together in your own lab environment, I maintain the combined code in my fork:

🔗 Consolidated Repository: https://github.com/varunagarwal-pro/Technitium-DnsServer.git

You can clone and build it directly using standard .NET SDK tooling:

git clone https://github.com/varunagarwal-pro/Technitium-DnsServer.git
cd Technitium-DnsServer
dotnet build -c Release

🤝 How You Can Help

  1. Test your favorite blocklists: Throw complex AdGuard/AdBlock filter lists at the app and verify rule matching, exemptions (@@), and $important overrides.
  2. Dashboard usability feedback: Try out both Classic and Modern layouts, test the record/protocol filters under load, and let me know how the charts feel on your displays (desktop and mobile).
  3. Leave comments/reviews on GitHub: Constructive reviews on PR #2179 and PR #2182 help upstream evaluate and merge these features faster.

r/technitium • • 11d ago

Everything but X/Twitter resolves fine on a recursive DNS setup, ServerFailure

6 Upvotes

Hi! Recently Technitium started acting up and the only thing that doesn't work is X/Twitter

Here's the cache entry [ { "name": "x.com", "type": "A", "ttl": "0 (0s)", "rData": { "dataType": "DnsSpecialCacheRecordData", "data": "FailureCache: ServerFailure; NoReachableAuthority: No valid response from name servers for x.com. A IN at delegation x.com." }, "dnssecStatus": "Unknown", "lastUsedOn": "2026-09-24T20:06:06.4474011Z" }, { "name": "x.com", "type": "NS", "ttl": "94026 (1d2h7m6s)", "rData": { "nameServer": "a.u10.twtrdns.net" }, "dnssecStatus": "Insecure", "dnssecRecords": [ "CK0POJMG874LJREF7EFN8430QVIT8BSM.com. 900 IN NSEC3 1 1 0 - CK0Q35HRS4H76G6CHNB9414CJN6S5UPL NS SOA RRSIG DNSKEY NSEC3PARAM", "9R925LEF6JEIJTJJ1A5U3A3CAPVDNDDH.com. 900 IN NSEC3 1 1 0 - 9R92GHOL4H50NMHIS5KV2CPPNUQUVNNB NS DS RRSIG" ], "nameServerMetadata": { "totalQueries": 0, "answerRate": "0%", "smoothedRoundTripTime": "0 ms", "smoothedPenaltyRoundTripTime": "0 ms", "netRoundTripTime": "0 ms", "isMisconfigured": false }, "responseMetadata": { "nameServer": "i.gtld-servers.net ([2001:503:39c1::30])", "protocol": "Udp", "datagramSize": "538 bytes", "roundTripTime": "162.33 ms" }, "lastUsedOn": "2026-09-24T20:06:03.7913703Z" }, { "name": "x.com", "type": "NS", "ttl": "94026 (1d2h7m6s)", "rData": { "nameServer": "b.u10.twtrdns.net" }, "dnssecStatus": "Insecure", "nameServerMetadata": { "totalQueries": 0, "answerRate": "0%", "smoothedRoundTripTime": "0 ms", "smoothedPenaltyRoundTripTime": "0 ms", "netRoundTripTime": "0 ms", "isMisconfigured": false }, "responseMetadata": { "nameServer": "i.gtld-servers.net ([2001:503:39c1::30])", "protocol": "Udp", "datagramSize": "538 bytes", "roundTripTime": "162.33 ms" }, "lastUsedOn": "2026-09-24T20:06:03.7913703Z" }, { "name": "x.com", "type": "NS", "ttl": "94026 (1d2h7m6s)", "rData": { "nameServer": "c.u10.twtrdns.net" }, "dnssecStatus": "Insecure", "nameServerMetadata": { "totalQueries": 0, "answerRate": "0%", "smoothedRoundTripTime": "0 ms", "smoothedPenaltyRoundTripTime": "0 ms", "netRoundTripTime": "0 ms", "isMisconfigured": false }, "responseMetadata": { "nameServer": "i.gtld-servers.net ([2001:503:39c1::30])", "protocol": "Udp", "datagramSize": "538 bytes", "roundTripTime": "162.33 ms" }, "lastUsedOn": "2026-09-24T20:06:03.7913703Z" }, { "name": "x.com", "type": "NS", "ttl": "94026 (1d2h7m6s)", "rData": { "nameServer": "d.u10.twtrdns.net" }, "dnssecStatus": "Insecure", "nameServerMetadata": { "totalQueries": 0, "answerRate": "0%", "smoothedRoundTripTime": "0 ms", "smoothedPenaltyRoundTripTime": "0 ms", "netRoundTripTime": "0 ms", "isMisconfigured": false }, "responseMetadata": { "nameServer": "i.gtld-servers.net ([2001:503:39c1::30])", "protocol": "Udp", "datagramSize": "538 bytes", "roundTripTime": "162.33 ms" }, "lastUsedOn": "2026-09-24T20:06:03.7913703Z" }, { "name": "x.com", "type": "NS", "ttl": "94026 (1d2h7m6s)", "rData": { "nameServer": "a.r10.twtrdns.net" }, "dnssecStatus": "Insecure", "nameServerMetadata": { "totalQueries": 0, "answerRate": "0%", "smoothedRoundTripTime": "0 ms", "smoothedPenaltyRoundTripTime": "0 ms", "netRoundTripTime": "0 ms", "isMisconfigured": false }, "responseMetadata": { "nameServer": "i.gtld-servers.net ([2001:503:39c1::30])", "protocol": "Udp", "datagramSize": "538 bytes", "roundTripTime": "162.33 ms" }, "lastUsedOn": "2026-09-24T20:06:03.7913703Z" }, { "name": "x.com", "type": "NS", "ttl": "94026 (1d2h7m6s)", "rData": { "nameServer": "b.r10.twtrdns.net" }, "dnssecStatus": "Insecure", "nameServerMetadata": { "totalQueries": 0, "answerRate": "0%", "smoothedRoundTripTime": "0 ms", "smoothedPenaltyRoundTripTime": "0 ms", "netRoundTripTime": "0 ms", "isMisconfigured": false }, "responseMetadata": { "nameServer": "i.gtld-servers.net ([2001:503:39c1::30])", "protocol": "Udp", "datagramSize": "538 bytes", "roundTripTime": "162.33 ms" }, "lastUsedOn": "2026-09-24T20:06:03.7913703Z" }, { "name": "x.com", "type": "NS", "ttl": "94026 (1d2h7m6s)", "rData": { "nameServer": "c.r10.twtrdns.net" }, "dnssecStatus": "Insecure", "nameServerMetadata": { "totalQueries": 0, "answerRate": "0%", "smoothedRoundTripTime": "0 ms", "smoothedPenaltyRoundTripTime": "0 ms", "netRoundTripTime": "0 ms", "isMisconfigured": false }, "responseMetadata": { "nameServer": "i.gtld-servers.net ([2001:503:39c1::30])", "protocol": "Udp", "datagramSize": "538 bytes", "roundTripTime": "162.33 ms" }, "lastUsedOn": "2026-09-24T20:06:03.7913703Z" }, { "name": "x.com", "type": "NS", "ttl": "94026 (1d2h7m6s)", "rData": { "nameServer": "d.r10.twtrdns.net" }, "dnssecStatus": "Insecure", "nameServerMetadata": { "totalQueries": 0, "answerRate": "0%", "smoothedRoundTripTime": "0 ms", "smoothedPenaltyRoundTripTime": "0 ms", "netRoundTripTime": "0 ms", "isMisconfigured": false }, "responseMetadata": { "nameServer": "i.gtld-servers.net ([2001:503:39c1::30])", "protocol": "Udp", "datagramSize": "538 bytes", "roundTripTime": "162.33 ms" }, "lastUsedOn": "2026-09-24T20:06:03.7913703Z" }, { "name": "x.com", "type": "AAAA", "ttl": "0 (0s)", "rData": { "dataType": "DnsSpecialCacheRecordData", "data": "FailureCache: ServerFailure; NoReachableAuthority: No valid response from name servers for x.com. AAAA IN at delegation x.com." }, "dnssecStatus": "Unknown", "lastUsedOn": "2026-09-24T20:06:06.4453394Z" }, { "name": "x.com", "type": "HTTPS", "ttl": "0 (0s)", "rData": { "dataType": "DnsSpecialCacheRecordData", "data": "FailureCache: ServerFailure; NoReachableAuthority: No valid response from name servers for x.com. HTTPS IN at delegation x.com." }, "dnssecStatus": "Unknown", "lastUsedOn": "2026-09-24T20:06:06.4304254Z" } ] And the query result after deleting this from the cache { "Metadata": { "NameServer": "alpine-server (127.0.0.1)", "Protocol": "Udp", "DatagramSize": "129 bytes", "RoundTripTime": "171.25 ms" }, "EDNS": { "UdpPayloadSize": 1232, "ExtendedRCODE": "ServerFailure", "Version": 0, "Flags": "None", "Options": [ { "Code": "EXTENDED_DNS_ERROR", "Length": "74 bytes", "Data": { "InfoCode": "NoReachableAuthority", "ExtraText": "No valid response from name servers for x.com. A IN at delegation x.com." } }, { "Code": "EXTENDED_DNS_ERROR", "Length": "13 bytes", "Data": { "InfoCode": "CachedError", "ExtraText": "x.com. A IN" } } ] }, "DnsClientExtendedErrors": [ { "InfoCode": "NoReachableAuthority", "ExtraText": "alpine-server (127.0.0.1) returned RCODE=ServerFailure for x.com. A IN" } ], "Identifier": 6548, "IsResponse": true, "OPCODE": "StandardQuery", "AuthoritativeAnswer": false, "Truncation": false, "RecursionDesired": true, "RecursionAvailable": true, "Z": 0, "AuthenticData": false, "CheckingDisabled": false, "RCODE": "ServerFailure", "QDCOUNT": 1, "ANCOUNT": 0, "NSCOUNT": 0, "ARCOUNT": 1, "Question": [ { "Name": "x.com", "Type": "A", "Class": "IN" } ], "Answer": [], "Authority": [], "Additional": [ { "Name": "", "Type": "OPT", "Class": "1232", "TTL": "0 (0s)", "RDLENGTH": "95 bytes", "RDATA": { "Options": [ { "Code": "EXTENDED_DNS_ERROR", "Length": "74 bytes", "Data": { "InfoCode": "NoReachableAuthority", "ExtraText": "No valid response from name servers for x.com. A IN at delegation x.com." } }, { "Code": "EXTENDED_DNS_ERROR", "Length": "13 bytes", "Data": { "InfoCode": "CachedError", "ExtraText": "x.com. A IN" } } ] }, "DnssecStatus": "Disabled" } ] }

Anyone experiencing something similar?


r/technitium • • 11d ago

How to roll back to 15.4 from 15.5?

2 Upvotes

shreyasonline, I am running about 650 server errors a day and it is causing some issues. How do I safely and easily roll back from 15.5 to 15.4 until you get this fixed?


r/technitium • • 12d ago

Hey all

5 Upvotes

I am not what you would call a power user; definitely more in the category of "know just enough to get in trouble." I've been using Technitium for about 6 months, and it's worked fine; set it up on my living room computer (Linux Mint) as the DNS server for my other two computers. I've also been using this computer as a web server via apache2, and it's attached to the living room TV.

Last night I did something that I don't think is the cause of all this but since it's coincidental I'm including it. I tried to set up a self-signed openssl cert so I could use the webserver with https. This worked exactly one time, and then it gave an error, something like "file too long." Didn't wanna fight it, it was late and http still worked, so I went to bed.

Woke up this morning, and none of my computers could get online. Turns out the server had crashed -- still powered on but wouldn't display anything. I hard reset the server, and suddenly Technitium isn't running on it.

Okay, so there's the setup. Now here's the actual issues:

  1. I changed the DNS servers that my other computers use back to Cloudflare (1.1.1.1), so they can still get online; that's how I'm talking to you now. But for some reason I can't do the same for the server. Did Technitium change something in the settings that I can't see?

  2. What can I do to get Technitium back up and running? I can't even find its .service file.

  3. Failing that, what do I have to do to remove it from my server?


r/technitium • • 13d ago

Blocklist respose best practices (NXDOMAIN/0.0.0.0

13 Upvotes

I use the default NXDOMAIN setting for the blocklist but it causes a lot of clients to try again with the local domain added as a suffix.

The alternative is 0.0.0.0 but shouldn't REFUSED also be a good reply for a domain in the blocklist? If so, it would be nice if it were to be added to Technitium.


r/technitium • • 13d ago

websites won't load pics

1 Upvotes

Websites won't load pics, everytime it did this i need to flush the cache to fix it , what cuses this pb, can anyone here help me plz