How and why I run my own DNS servers
zwischenzugs.com
zwischenzugs.com
The point of running your own email and dns server is so that you are a peer on the network.[1]
This is important and is becoming lost in the current era of Internet adoption.
By many measures the Internet is the largest cultural and commercial force in the world today and by an accident of history, the researchers at (D)ARPA gave us a network that allowed normal citizens to be peers on the network.
Don't lose this.
[1] As opposed to, for instance, the telephone network. You can own your own domain and perform the first level of network interaction on your Internet systems, but the analogy on the phone network (owning your own phone number and controlling the first touch from other networks) by creating a CLEC is administratively and financially ($100k +) impossible.
That is what peering agreements are but I believe in the broader context of the Internet, any routable IP address can, and should be, considered a peer:
"Each layer has one or more protocols for communicating with its peer at the same layer."[1]
[1] TCP/IP Illustrated, Volume 1, p.3
All it takes to be a proper peer on the internet is a public IP address.
Randomly reusing the same limited set of IPv6 addresses would help privacy a little.
Fortunately there is another alternative, which is to get your public address from somewhere other than your local ISP. Some VPN providers offer a static IP or you can set up your own VPN to a VM on any cloud host and forward incoming traffic back over the tunnel.
Also, not available without business class, at least on my ISP, is port 80. You won't be hosting many web properties if Joe user types in yourdomain.com into a browser without the leading https://, which nobody does anywhere. If browser makers defaulted to https, I'm sure the ISP would fix this glaring hole in their non-business class plans promptly.
I use Route53 now with a little cron that periodically updates the record that points at my home IP[3]. Route53 is bulletproof in a way that I'm unable to accomplish on my own.
edit: Route53 is not actually cheaper than this person's setup. That said, $0.50 per hosted zone is a bargain for what you get and there's a volume break to $0.10 after 25 zones. We're talking about global 100% DNS uptime with an SLA[4] for $0.50/mo.
[1]: https://www.petekeen.net/how-i-run-my-own-dns
[2]: https://www.petekeen.net/how-and-why-im-not-running-my-own-d...
It's then just a case of using HAProxy (which is also on the same box) to route to different internal services. I don't host anything important, just time saving things running in docker containers on a separate box. Things like email and personal site always go on cloud hosting or a service, since these need to be up for me.
Make sure your firewall rules are setup well, and look into some logging and monitoring.
My company hosts several hundred domains, and using Route53 was a no-brainer -- even if the hardware is free, monitoring, patching and maintaining those bind servers is much more expensive than route53 even if we had 1000 domains.
If you are using it to "just" host a dumb domain record, you can get that for free at your registrar or with Cloudflare.
This whole "Route53 is cheap" mantra makes no sense unless you are doing something so simple you get it free with 2934902342390 other services.
Do you genuinely not understand I'm talking about a production setup that already exists?
Like, if you think health checks are non-trivial you probably shouldn't be running your own DNS.
I didn't say everyone should quit Route53.
Our last bill showed around 100 million queries last month, so that cost around $40.
We've got a dozen healthchecks, so that's another $6. $0.50 each is essentially free compared to the time it'd cost us to set up the equivalent healthcheck service with bind.
150 domains costs another $25
So our entire bill for 150 domains and a around 3M DNS queries/day is around $75/month.
If it genuinely takes you an hour a month to maintain your own setup, I guess your logic makes sense but for me it doesn't.
You've also basically admitted its alot less than 1k domains.
If I hosted with AWS, it would massively inflate my hosting costs as well. Lol.
If you are using it to "just" host a dumb domain record, you can get that for free at your registrar or with Cloudflare.
# It’s Cheap
There are plenty of cheap & free DNS hosts out there.
# More Control
Every DNS host I've ever used has offered full control of DNS records. If all you've ever experienced is poor shared hosting maybe this looks is something new.
A why not section would be good
* High latency for people who do not live near one of your servers.
* Time to set up
* Cost (lots of cheaper alternatives)
* Some overhead. Running any server that is public facing has some overhead even if it's just installing patches.
Interestingly zwischenzugs.com isn't hosted on authors own DNS (maybe a restriction of wordpress.com?)
That's not true. Typically most dns hosting solutions offer so little control and it is so primitive, that they only treat records as static values, you can't have something like a view{} in bind letting you serve different people by different servers reducing latency and improving availability, say you have one server in America and one in Europe.
> High latency for people who do not live near one of your servers.
See my point above. Dynamically chosen records are fundamental to cheap good latency. And no, anycast is not a silver bullet, you can do pretty good with just dynamic records, you can use them for nameservers too, you know.
>I’ve learned a lot by doing this, probably far more than any course would have taught me.
It is quite obvious that the world needs more people with a deep knowledge of how DNS works. Doing something like this is a quick and effective way to make the world a better place.
I think you're overstating your case here. I found it interesting too, and us geeks like to dabble in many things, but you can never achieve specialized knowledge and expertise through mere tinkering. Using C++ didn't make me a language designer or even an expert on C++.
Entire trades are facing slow extinction for lack of people who bothered to learn. Almost 3/4 of electrical or electronics repairmen are over 45 years old, and 30% of them are over 55 years old [1]. It would be a shame to wake up one day in 2030 and realize there are only a handful of (presumably very well paid) people on earth who know how DNS works.
1: https://www.lincolntech.edu/news/skilled-trades/baby-boomers...
The other day I asked my client to change the negative result TTL of their domain (down from, IMO, very high 86400). Answer: Can't do. Our DNS host won't allow that.
That is easily the most popular host in my country, btw.
Every tried to publish SSHFP records? Infoblox doesn't, seems like many of the wrapped DNS service with a cute website for customers doesn't allow publishing SSHFP records.
The IP addresses for your authoritative servers are going to be stored in the glue record for your zone, which is physically held in the root servers (i.e. not your servers).
Those glue records can't be changed quickly.
Therefore you need to be very sure that your servers' IP addresses are really static.
We run our own DNS (for mostly historical and paranoia about reliability reasons). One of our servers is on a subnet that we own, so that totally under our control. The other is at a provider where I have had a detailed back-and-forth with the support staff about the circumstances under which its IP might change, and how to ensure it won't change, specifically mentioning that we are going to run an authoritative DNS server on their infrastructure (currently IBM/Softlayer, moving to Packet.net soon). I am skeptical that a low-cost provider (DO, etc) can give a strong enough guarantee that the machine's IP address won't change.
Makes Route53 look very attractive for common/garden purposes.
It's of course less efficient and probably you shouldn't do it, but DNS itself doesn't stop you from that.
As for authoritative servers what I did in the past is essentially working together with friends, I was backup name server for their domains and they were backup for mine.
There are also some free public DNS servers as well.
A big problem with free/cheap DNS services is that (as far as I have seen) they do not support either secondaries off their network, nor being a secondary to some other primary. So you end up in an all-or-nothing situation where you either rely entirely on one provider, or you have to host yourself.
Isn't that only the case for gmail (and maybe some others)?
As an aside I'm surprised someone setting up their own dns-server would still be using gmail. I've found running my own email-server to be very useful and satisfying. (0-configuration throwaway addresses, automatic sorting with sieve, personal and professional mail on the same account, etc. etc.)
> personal and professional mail on the same account
This is a self plug, however this is exactly what i made https://ForwardMX.io for, doing all this within Gmail for the lazy :)
My problem with a catch-all was that there is a lot of spam that gets send to various common email addresses such as "admin". Do you maintain a blacklist for your users?
I have a regular expression set as a username in my database of email addresses. (spoilers: it's just somesalt.*."2 or 3 characters" so for example secretsalt.ycombinator.com@mydomain.tld). So I can sign up to any random website by just entering salt.thatwebsite.tld@me as my email. That's the zero-configuration part. Honestly, this is worth paying $9/year for imho :P
The personal and and professional mail together is simply internally forwarding my professional mail to the same imap instance but a different folder :P. It's mostly future-proofing on my part. If I were to get/manage a different domain-name (say a gaming guild or business venture) I could merge those too and not have to set-up 27 different accounts in my email client.
Right now my approach is to have a [catch-all]@domain.tld enabled, and then build rules for individual domains i want to blacklist.
However sounds like you figured out a nice setup that works for you. So you are not the target audience anyway :)
Cant say anything against Fastmail tho, except surely we are cheaper as we dont have to provide these kind of interfaces and space.
Yes. Email providers are free to create that kind of rules, and this one looks very specific to gmail.
> As an aside I'm surprised someone setting up their own dns-server would still be using gmail.
Well, be wary of getting contacts about your DNS in an email that depends on your DNS. This is the one place to use a gmail address, not one you control.
The daunting part is just how many options/features the project has - which is what I tried to clear up in my guide.
I know its basically the standard but its a pain to configure and modify. I recently started to work with Haraka and its so much more of a plessure (even thought i am no JS fan, i prefer JS to cryptic/ancient config files)
Just curious if you went through a evaluation process
I have basically no experience with Javascript or web stuff, and the last thing I want to do is figure out some leftpad-style NPM package dependency while my mail server is down. Maybe I'm just an old-school Unix guy at heart though - running a JavaScript interpreter on a privileged port just doesn't sit right with me.
Postfix is a breeze to work with in comparison.
I've setup both multiple times, and have worked with Sendmail since 1994. Postfix config files are much simpler.
To configure sendmail, you have to do extra layers of weirdness, like deal with "m4". That's mental overhead you just don't have with Postfix.
The relative complexity of the files is about the same—my postfix server config is roughly the same number of lines as my sendmail server config. And each line is just a single conf thing. Sendmail isn't really more complicated at all. It's just ugly.
Do you use it together with an imap server (like dovecot)?
This one[1] is similar however, although it's a bit less detailed. Basically: I use postfix with mysql for a user database as my MTA (the postman so to speak) and dovecot for the IMAP client (a smart mailbox equivalent).
edit: it's slightly different from what perlgod wrote (rspamd+ldap vs spamassassin+mysql) but the idea is the same.
Now the tutorial will give you a basic set-up, with spamassassin as a spamfilter. Which already "just-worked(tm)" for me. In addition to what's listed I added the following steps over time:
- First check your ip address on mxtoolbox.com for any blacklists. If you're on any, you could get removed if you ask them or you could ask your hosting provider to give you a different ip.
- get a certificate from let's-encrypt and encrypt all outgoing mail. Rejecting unencrypted mail is not a good idea even if it would be in an ideal world.
- add a blacklist MySQL table and a regex addres to the users table. Postfix has an option for parsing regex IIRC, so you can just set the email-adress to be a regex in the table as you would any other email. Then set the MySQL query in postfix to something like "user in table users AND NOT in table blacklist". This way you can use a unique email for each website you sign up to (say: somesalt.domain.tld@yourdomain.tld) and if you ever get any spam, you will know what website got hacked/sold your info ;P. I have only one website on my blacklist so far, and that was because their unsubscribe link didn't work.
- Install Sieve, this let's you add a sorting-script to your imap, letting you automatically sort incoming mail into different folders using all kinds of regexp. I have for example "personal, work, work/personal (directly to me and not a list), anonymous (throwaway adresses for each website I sign up to), admin (postmaster, cron, etc.), purchases (regex match to anything containing order, shipment, etc. which gets put into a folder which is backed up for longer), Uni, git notifications, and Twitch (because they send a ton of short-lived notifications. Messages in this folder get purged after 2h).
- Set up a r-dns pointer (you said you wanted to try more obscure dns features :D). this is an ip->domain mapping. For me this meant sending a message to my vps provider asking them to do so. p.s. vpsdime has insanely good/fast support. Took them literally less than a minute.
and finally:
- Set up DMARC (DKIM+SPF). Spf is pretty simple. It's simply a dns record which says which ip-adresses are allowed to send mail on your behalf. DKIM is a bit more complicated: It use public-private key encryption (with the public-key in the dns records) to digitally sign various fields (to,from, content, cc, etc. can all be signed separately) of your email to make sure they haven't been tampered with. The daemon set-up is quite easy, but it's easy to mess up the settings. If you're sending sensitive business emails I would set it up (my bank has it for example) but for personal email, I would only set it to sign the bare minimum such as the 'from' field, or nothing at all. Even if you don't sign any fields, having it set up will almost surely prevent you from being put into spam folders by the big providers.
I haven't had any issues so far, except for an overly strict DKIM set-up. Once marking email send to my work's mailing lists as spam when forwarded to gmail. (i.e. me->work list -> someone@work.tld -> someone@gmail.com) which in an ideal world wouldn't cause issues, but my work's mail server was misconfigured causing them to modify the email's envelope without respecting the DKIM signatures.
The other time was when my university email forwarded messages from @intel.com, which has strict security settings too. This was actually an issue when I forwarded from my uni to my gmail before too, but I never noticed because gmail was (as per Intel's configuration) silently discarding any emails I got. I only noticed the problem when I looked at my mail server logs for any rejections. I now have Intel.com whitelisted. (my uni said they'd fix it... 1.5 years ago...).
Having written all this out I noticed two things:
1. Okay, maybe setting up an email server is a bit of work after all... Mine grew organically over a few weekends so I never noticed.
2. When I finally start that blog I've been meaning to do, I should do a clean email-server install and write it up.
[1] https://www.digitalocean.com/community/tutorials/how-to-conf...
I do have some publicly harvestable emails (on github and such), but I've never been spammed on those yet. Only on my personal address which I only give out IRL or occasionally reply with.
The catch-all emails are probably the best anti-spam you can have. The moment I get spam addresed to ycombinator.com@mydomain.tld (which matches a regex), I just blacklist it and move on with my life.
To me that is a bug not a feature
My work email is (was, internship) reasonably quite so it didn't bother me. If it would become annoying i'd just set it to manual sync on my phone.
I wrote up my setup here: https://www.c0ffee.net/blog/dns-hidden-master
I host mostly static IPs, but I also use this setup with shared keys and PFSense's RFC2136 feature to push dynamic DNS updates for my home network.
But your post gave me an idea to try, so anyway, thank you, either it will work or not.
I asked them. It's not a bug, it's a feature!
So you can run your own DNS master server and rely on HE for availability when your server is down or even give preference to the slave DNS, so your users can get the results quick.
So I decided not to go with any free providers anymore and get my own domain instead. So far no regret.
https://news.ycombinator.com/item?id=14856277#14858784
>opie34: A friend and I put together a free dynamic DNS service [1] offering cool custom domains aimed at the Raspberry Pi community (and similar hardware hackers.) It's not strictly a hardware project, but it's a crucial building block for any network-enabled Raspberry Pi project, and we'd love your feedback.
The problem with them however was that they did rack up the price over time and not just a little bit.
In 2006, I had to pay $9.95 for their yearly "Pro" offering. In 2008 the deal became "only $23.00 for 2 years", humm OK. Two years later in 2010 it was "$30 for 2 years", in 2012 the bill became $40.00 and when 2016 came the price was upgraded again... (yet again without any other benefits from a customer point of view)
That's when I figured that it was too much and moved over to he.net. Which still is free and still works great for the dynamic DNS needed.
For static DNS services I also happen to run my own DNS servers, if needed then the he.net services could be moved over to their, but not seeing the need for now.
The DNS servers that I happen to run have nothing to do with dyn's pricing, I was already running those and they are for more serious needs as just dynamic DNS.
Next, I wanted to become independent. Now I can choose my DNS hoster or do it myself, but as long as I keep my domain the migration is easy. (And the custom domain looks much better ;-)
So I have no hard feelings against dyn.com as it was completely okay to stop their free service. Nevertheless, I did not want to be in the same situation again.
> setup a strong root password
You should ideally disable root login over SSH and only allow key-based login. Checkout /etc/ssh/sshd_config for more info on that. I don't think this has been suggested yet.
- unbound (recursive resolver) https://www.unbound.net
- nsd (authoritative server) https://www.nlnetlabs.nl/projects/nsd
This is what I do, which allows me the full gamut of BIND features without exposing those servers directly to any networks (there is a non-routed vlan that nsd/unbound/bind servers use). This is using split-horizon, DDNS from ISC DHCP and DNSSEC, so not a non-trivial setup, but it is also my home network setup so not so heavy duty as to be particularly hard to set up and automate.
I also have a round-robin DNSCRYPT setup hooked into the whole thing for semi-anonymity of queries.
The down side is sometimes wireless hotspots will block all traffic until you hit their portal, including DNS resolution, and some captive portals don't work when you can't resolve the name. I've worked around this by letting NetworkManager poke the DNS settings in, and then my VPN will update the resolv.conf once the VPN is up.
Means I don't end up getting weird DNS responses from clever hotspots or ISPs.
I've used PowerDNS, which was a breeze for me. It's super efficient too. So I set up my DNS on a very cheap VPS on Vultr ($5/month) and everything has been running well.
I do wish PowerDNS had a better web interface, but hey it does the job.
Now, I have a different perspective and believe more people should be owning their own data and servers.
However, I still didn't get around to finding (or writing) a CLI for their DNS offering (it is possible, because acme.sh does it [0] -- maybe I'll just use this as a base?)
Why not? Bind has rate limiting to make it useless for amplification attacks. You can also use smaller than 4k udp response sizes, forcing clients to switch to tcp. Nothing to be afraid of, your dns hosting provider probably does the same thing.
nsupdate (mentioned below) may help also.
[1] https://www.namecheap.com/support/knowledgebase/article.aspx...
1. $$$
2. certbot certonly --dns-route53 [...]
As long as you don't need to change or don't have any issue they are ok as any other domain.
Their interface is horrible, it took me a while until I figured out the right step order to properly set up glue records.
If you have an issue, their support can be hit or miss, I have feeling that they just ignore whenever a ticket is opened and only respond when you follow up. It also doesn't send notification by email when they respond so often it might take days to resolve a simple issue. This is especially bad if they block the service and domain no longer resolves.
TK also doesn't support DNSSEC.
The nice thing is that it is free, but you need to make sure you have a working web server that returns some content otherwise they will block the service.
This restriction doesn't apply if you pay for the domain.
To summarize, it's ok for free service, but if you pay you might as well just use better managed registrar, their price is not better compared to other registrars that have better support and better interface.
1. host them on the cheapest dodgy vps provider you can find 2. host primary and secondary on the same provider 3. use a free throwaway domain registrar 4. use the dns server software with the worst security track record
I mean obviously you can do it if you want to, I'm not stopping you, but to me it's silly.
Setting up DNS servers on low cost VPS providers has some inherenet risks as they tend to attract all kinds of abuse, which can lead to things like mass scale UDP filtering to keep operations online.
When I scaled down my colo footprint I started to move DNS operations to various VPS providers to maintain redundancy, but kept my monitoring in place to perform health checks at 60 second intervals. Finally got annoyed enough with all of the filtering events tripping monitoring that I migrated everything to a hosted DNS provider.
An authoritative server is responsible for answering that same question, but it's been labeled as authoritative for a domain, via the domain registrar system. To see what servers are authoritative for a domain, you can use commands like dig or host; here's an example host command (I'm running OSX, but this should work on any *nix that has it installed):
$ host -t ns ycombinator.com
ycombinator.com name server ns-1411.awsdns-48.org.
ycombinator.com name server ns-1914.awsdns-47.co.uk.
ycombinator.com name server ns-225.awsdns-28.com.
ycombinator.com name server ns-556.awsdns-05.net.