NextDNS API
nextdns.github.io
nextdns.github.io
* https://github.com/AnalogJ/lexicon
For CLI and Python.
Such a utility is handy if you want to use the dns-01 method for ACME/Let's Encrypt via DNS aliasing:
* https://dan.langille.org/2019/02/01/acme-domain-alias-mode/
* https://github.com/acmesh-official/acme.sh/wiki/DNS-alias-mo...
* https://news.ycombinator.com/item?id=28256326 (2020)
Deep dive on how ACME DNS validation works:
* https://www.eff.org/deeplinks/2018/02/technical-deep-dive-se...
Some folks have also written 'minimalist' DNS servers for DNS validation (delegate to a sub-domain that you control if your provider does not have an API):
* dnscontrol - https://stackexchange.github.io/dnscontrol/
* octodns - https://github.com/octodns/octodns
NextDNS is essentially Pi-hole-as-a-service, and its APIs are not focused on managing DNS in the traditional sense. Instead, they provide visibility into NextDNS's lookup/block analytics, managing settings, etc.
If you do aliasing, you can serve the DNS challenge from the server you want and that you fully control. You don't need to interface with your registrar, you just add an NS record once (manually).
You need lexicon if you want to serve the challenge from your registrar instead, and lexicon is the tool that will allow you to talk to many registrars.
Say I own example.com, but because it lives on a DNS server that does not have an API, or changes to the company's domain need to go through change control, I cannot easily change it.
But I want an ACME/LE cert for foo.example.com, which could be an internal-only service so http-01 is not available.
So I can set up a CNAME/alias at _acme-challenge.foo.example.com and point it to (e.g.) foo.example.org. Now I also own example.org, but because it's not the 'main' domain the controls on it are less onerous.
So when I request "foo.example.com", it finds the CNAME and heads over to "foo.example.org", where I've update the ACME nonce dynamically. The CNAME setup is a one-time thing, and can go through the 'regular' steps initially, and can then just be left alone.
Or, instead of a entire new domain (example.org), I can delegate things to a sub-domain (dnsauth.example.com) as well.
I have never paid a cent for it. I still don't understand how they can make money... unless I'm actually the product being sold (which I was always under the impression that they didn't sell or share user data). Who knows.
I assume a number of people are paying for it. easier than running a pihole locally.
The 300k is super easy to hit in a house with a few devices in it.
I noticed that some apps/devices would continue querying pretty aggressively after being blocked, and this seemed to eat through the available queries pretty quickly.
But $20/year is such a great deal IMO it was an insta-buy for me.
For comparison, my account has roughly 3.5M queries over the past 30 days, and 298k of those are to a single domain :P.
The documentation seems to be missing instructions on how to obtain an API key.
2. You can now automate a lot of things. Example: block twitter/fb/social media after 9pm for everyone.
drill facebook.com @8.8.8.8
;; ->>HEADER<<- opcode: QUERY, rcode: NOERROR, id: 34092
;; flags: qr rd ra ; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;; facebook.com. IN A
;; ANSWER SECTION:
facebook.com. 300 IN A 157.240.21.35Now can we just get an easy way in the GUI to import/export our custom blocklists / allow lists ? And bulk adding/removing things to both would be nice as well through the GUI.
So when I hit issues with NextDNS where my block list is too strict or it has to be amended but want to hit another website rather than wait for the allow list to update.
I launch YogaDNS so my DNS servers are temporarily changed, rather than disable NextDNS. Then I disable YogaDNS a few moments later when I expect my settings in NextDNS have updated/refreshed.
You still have the same problem, you have to remember to disable YogaDNS but I find it to be a lot easier, turning on and off the YogaDNS app.
> …or add a domain to the Denylist by POST‘ing at: https://api.nextdns.io/profiles/:profile/denylist
So I assume the same can be done for allowlists.
NextDNS is great, but occasionally breaks things depending on the blocklists enabled, so I was toying with the idea of building a utility that would show the last n blocked domains with an easy option to click-to-add a specific domain to the allow-list.
As far as I can tell, the API has what's needed.
What you're looking for is a DNS hosting service with an API that can be used from an ACME client. I use LuaDNS for that, their service is excellent and you can store your zone files in git (and auto-update DNS with a webhook on push).