Show HN: Which DNS servers are you pointing to?
which.nameserve.rs
which.nameserve.rs
This isn't a new idea ([2]), but mine supports https (hat tip to Matt Holt's certmagic [3]), is ad-free, and the source is available [4].
Let me know what you think!
[1] https://which.nameserve.rs
[2] http://www.whatsmydnsserver.com/
[3] https://github.com/caddyserver/certmagic
[4] AGPL. It is my first foray into golang. https://github.com/redirect2me/which-dns
If you want to see if a local workstation is pointing to a different public/external DNS server than the rest of your network, it should work.
[1] https://www.cloudflare.com/learning/dns/what-is-recursive-dn...
> How does it work? You make a request to a hostname with a unique prefix. All hostnames resolve to the same IP, but the DNS server records which IP address the query came from. The webserver looks for this record and returns it.
That's a smart way of detecting a user's DNS server - well done!
Is there a way to "fail" the first request and try to force the user's secondary DNS to kick in so that it can be detected too?
I'm not sure failing will do that, but it might reveal interesting things anyway. I'll add it to the to-do list.
It’s pretty easy to implement; somehow don’t respond to a request, but do respond to a second. (If you’re clever you can probably do it without server side state, e.g. encode a deadline in the custom hostname.)
I always use IPleak.net [1]. Works for public IPv4, IPv6, DNS server, Tor/AirVPN exit node, BitTorrent, geolocation, and all kind of browser metadata.
Browsing through comments shows this can do some things IPleak.net can't do such using wget/curl with API.
But please, only light, non-commercial use! It is on the cheapest static IP that I could find with no failover or anything.
It is really easy to run your own copy if you need it for a commercial project.
Now you have me thinking about the economics of api as a service... another rabbit hole.
Page alternately returns WOODYNET @ rrdns.pch.net and CLOUDFLARENET. I like the pch.net info - it's something about Quad9 I didn't know.
In this case, you're seeing WoodyNet IPs and IN-ADDRs because WoodyNet is giving transit to the Quad9 anycast instance you're talking to.
I'm happy to answer any questions you may have about how all this works.
I'd also note that round-robining between two different organizations with radically different privacy practices and security services... um... might not make the most sense? Depending what your goal is, of course. Again, happy to talk about any of this, just let me know if I (or any of the Quad9 or PCH folks) can be of help.
-BillMy resolvers perform queries against the root servers directly and cache results.
It's refreshing to skip all the DNS fuckery that's going on nowadays.
edit: downvoting honest questions?
Donkeyporn's DNS provider, com's DNS provider (0.1% chance it's not already cached), your ISP, transit providers, donkeyporn's ISP, donkeyporn service
To: cloudflare, your ISP, transit providers, donkeyporn's ISP, donkeyporn service
It's not a huge change and it's really about whether you trust CloudFlare more than the service donkeyporn has chosen.
I personally feel that concentrating all the information of "what DNS names are people looking up" into the hands of a few parties (e.g. CloudFlare) makes it much easier to collect and analyze this information.
[1]: Specifically, to reject them, which means sending a TCP reset / ICMP unreachable response back rather than blackholing them.
1: https://datatracker.ietf.org/doc/draft-pauly-add-resolver-di...
I don't use any Apple software or hardware, but if Firefox starts using it I'll start worrying about it.
A better strategy might be to look at the SNI for hostname at least until ESNI becomes prevalent (the one I run supports ESNI already).
And I supply DNS-over-TLS and DNS-over-HTTPS locally. It's really not too difficult.
I run the same setup, local resolver that recurses from the roots, and I don't cache anything other than what my systems actually request. If I hit a new site, I pay the penalty for not having certain information cached.
Hows the DNS server to know what to pre-cache to reduce lookup times?
Even for something that is not in the cache DNS is lightweight and quick, and I have full control over when to flush it, and have logs.
I am not huge fan of the trend of various device manufacturers (looking at you Google, and now Apple too) sending queries over DoH instead of using the local resolver on my network :/
This has been a known problem for decades, people having encouraged in-bailiwick "glue" since at least the turn of the century. If you want to decrease lookup times, add your voice to encouraging this. Experts in the field are nowadays generally persuaded that it is a good thing, which took a saddening amount of persuasion. But everyday administrators still too-often do not get encouraged to use in-bailiwick delegations.
Tip: You can check a specific DNS server with dig and curl:
UUID=$(uuidgen)
dig ${UUID}.which.nameserve.rs @1.1.1.1
curl --silent https://which.nameserve.rs/debug.txt | grep ${UUID}
and then do a ASN lookup on the IP addressNote: the debug page is unofficial, and may change, so don't bake this into anything.
* https://developer.akamai.com/blog/2018/05/10/introducing-new...
One question popped into my head is how do you trust nextdns? or are you doing something so that you do not need to trust it?
How to choose a DNS server? I usually just go with 8.8.8.8/8.8.4.4, I used to always test this with Namebench (https://en.wikipedia.org/wiki/Namebench) and these always turned out as the fastest - but it looks like it hasn't been updated since 2010 - are there any better tools for this, or any considerations in general? I prefer performance over privacy here, I think privacy should be on a different layer.
Can you elaborate which layer?
Is it possible these privacy/filtering DNS services like NextDNS come without a performance hit? Imagine setting it up and forgetting about it, and discovering later that all your DNS queries happened with a substantial lag - it's like realizing you've been driving with a hand brake on
If I'm not mistaken you can use DNSSEC to authenticate, but not encrypt, your DNS requests. For me however, the simpler way was to just use DoT/DoH. I haven't noticed any slowdowns.
If you care about performance, you could check if your system caches DNS responses and configure that cache accordingly.
I run Unbound (a DNS resolver) alongside Pi-hole on a dedicated raspberry pi for my home network.
https://resolve.rs/http/myheaders.html
It says:
> These are the HTTP headers that are being sent my your browser.
Great set of tools, BTW.
for i in `cat dns_list.txt|grep -v '^#'` do qt=`dig @$i archive.is| grep "Query time:" |cut -f2 -d ':'` echo "$i: $qt" done
Is OP threatening to inject harmful code into abusers' script tags, or am I totally misreading this.
You can see the code, so obviously I haven't done anything nefarious. Hopefully just the possibility will be enough of a deterrant.
I'm curious how everyone else is dealing with freeloaders. I'm open to alternative suggestions.
I used to just edit /etc/resolv.conf and add 8.8.8.8 to it but now recent distros have "Do not edit." in resolv.conf and don't tell you what to actually edit. Why do they have to do this to us ... things used to be simple.
Today, you can set up DNS per interface and designate, which DNS accessible via which interface can resolve which zones. So your intranet.company.com can go through specific VPN connection and the rest via your default route, for example.
You can't do that with simple /etc/resolv.conf.
https://wiki.archlinux.org/index.php/Systemd-resolved#Settin...
https://support.mozilla.org/en-US/kb/dns-over-https-doh-faqs...