Is that specific? sure, but I'll tell you when I go to set a new system up I'm going to type 8.8.8.8 because it's what comes to my mind.
4.2.2.1
4.2.2.2
For as often as I manually configure DNS (I use DHCP) it's not onerous to look up the IPs of whatever DNS is preferable for your purpose.edit: Depending on who you are this may redirect you to a search portal. Probably best to find an alternate DNS provider.
; <<>> DiG 9.9.7-P3 <<>> thisprobablydoesntexist.com @4.2.2.2
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 12860
;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;thisprobablydoesntexist.com. IN A
;; ANSWER SECTION:
thisprobablydoesntexist.com. 10 IN A 104.239.213.7
thisprobablydoesntexist.com. 10 IN A 198.105.254.11
Contrast that with 8.8.8.8: ; <<>> DiG 9.9.7-P3 <<>> thisprobablydoesntexist.com @8.8.8.8
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 7991
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1
The NXDOMAIN response is proper - the level3 DNS servers are just a faster version of my ISPs goal to garner ad revenue at this point.There is this comment from a few years ago, https://news.ycombinator.com/item?id=7120248 , linking to a blog post which is now only accessible from the Internet Archive, where a VP at Level3 stated they were public.
I use 4.2.2.x and I do get NXDOMAIN from them, and I'm not a L3 customer. I wonder if they respond differently depending on who you are...
; <<>> DiG 9.9.7-P3 <<>> @4.2.2.1 thisprobablydoesntexist.com
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 10665
;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;thisprobablydoesntexist.com. IN A
;; ANSWER SECTION:
thisprobablydoesntexist.com. 10 IN A 104.239.213.7
thisprobablydoesntexist.com. 10 IN A 198.105.254.11
;; Query time: 29 msec
;; SERVER: 4.2.2.1#53(4.2.2.1)
;; WHEN: Fri Mar 30 09:27:39 PDT 2018
;; MSG SIZE rcvd: 77Looks like I ran into that issue and went back to Google.
I just changed DHCP config to 1.1.1.1 :)
; <<>> DiG 9.9.7-P3 <<>> @1.1.1.1 thisprobablydoesntexist.com
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 28530
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1536
;; QUESTION SECTION:
;thisprobablydoesntexist.com. IN A
;; AUTHORITY SECTION:
com. 900 IN SOA a.gtld-servers.net. nstld.verisign-grs.com. 1522427379 1800 900 604800 86400
;; Query time: 33 msec
;; SERVER: 1.1.1.1#53(1.1.1.1)
;; WHEN: Fri Mar 30 09:29:56 PDT 2018
;; MSG SIZE rcvd: 132 # dig +short this-should-be-a-nxdomain.com @4.2.2.2
198.105.254.11
104.239.213.7
They do it a little more cleanly than some other attempts I've seen, but there's still flaws in their approach. In particular, they will generate redirects for NXDOMAIN responses to certain records under domains that do exist: # dig +short why-does-this-resolve.example.com @4.2.2.2
198.105.254.11
104.239.213.7
Specifically, they'll generate a redirect for any record that starts with the letter "w". (No, I'm not kidding. Try it.) Other records generate a real NXDOMAIN. dig @9.9.9.9 icnerd-1e5f.kxcdn.com
icnerd-1e5f.kxcdn.com. 3600 IN CNAME s-us-ca00.kvcdn.com.
s-us-ca00.kvcdn.com. 55 IN CNAME p-ussj00.kxcdn.com.
p-ussj00.kxcdn.com. 55 IN A 209.58.129.70
dig @8.8.8.8 icnerd-1e5f.kxcdn.com
icnerd-1e5f.kxcdn.com. 21599 IN CNAME p-uklo00.kxcdn.com.
p-uklo00.kxcdn.com. 59 IN A 217.146.91.55From their FAQ:
Does Quad9 support DNS over TLS?
We do support DNS over TLS on port 853 (the standard) using an auth name of dns.quad9.net.At least I'm not paying Google to do the same, and I can trust that they'll send the proper results.
isn't that the recommended behavior? otherwise you can do a bunch nasty stuff like rebinding attacks.
https://www.ietf.org/proceedings/52/I-D/draft-ietf-dnsop-don...
Take your 1.1.1.1, 8.8.8.8, 9.9.9.9, maybe your ISP DNS, etc., check against them randomly to try and avoid giving any one of them all of your DNS request traffic, maybe look up the same address on two of them to confirm that you're getting the same destination from both?
That's a DNS service everyone would love to use, right?
I suspect that the whole reason why 8.8.8.8 is a Google DNS server is that they were originally only 4.4.4.4 until someone Chinese pointed out that 4 is an unlucky number. :)
https://www.quad9.net/faq/#Is_there_a_service_that_Quad9_off...
$ dig @9.9.9.10 +dnssec +short verisignlabs.com
72.13.58.64
A 8 2 3600 20180413202737 20180330202737 31485 verisignlabs.com. KrnT9i6qytaYWDZWThBmBwc6anOmawNxJTxmSlpaY3L7Yfupga9FS70l 8nMVp8ggbEtA+CnS9AbNwObkPaYvk3nFpDvo4C+2hg+PECsP1HVTgGxl G3eblfnYAMNfYzLYlfUnSBgM7kLSIXY4rLBxsl01KiPJYezNhmQ53KYf ygs=Use cases are different - Quad9 for "nasty" filtered and 8.8.8.8 for err probably not filtered.
Do it yourself otherwise.