8.8.8.8 is Google dns and pretty quick. You can also search to find some more privacy focused dns servers (but always remember if you aren’t paying for it you’re the product).
Servers grabbed from here: https://servers.opennic.org/ (OpenNIC itself is kinda barely holding but the servers are pretty good).
Note that your browser will ignore this. Open up Firefox (or derivative), Settings, Privacy and security, DNS over HTTPS, Own settings, Own, and paste something like https://dns1.slowb.ro/dns-query into it. Again, you can grab a server from opennic (look into description for URL). No, you cannot use opennic.glue addresses here.
Now, note that this may still be tampered with, if your ISP/government cares enough. Not in the browser, but system wide yes. In this case, you will have to use dnssec-proxy, route your DNS over I2P/Tor OR run your own resolver. In all of these scenarios, you will have to make sure the program providing it is listening on port 53 (and nothing else is taking it) then just make /etc/resolv.confthis instead:
nameserver ::1
nameserver 127.0.0.1
Obviously, all of this only affects DNS tampering and nothing else.
If you have a spare raspberry pi and don’t mind an afternoon to get everything setup you could do what I have which is adguard home using the OISD block list and any other dns requests get resolved by unbound running on the same hardware so you’re your own dns server.
I would more recommend Quad9 instead of google. It also has some Addblock and anti tracker functionality, it also supports dns sec and dns over https. https://quad9.net/ Here the default dns resolver 9.9.9.9
I’m happily using dnsforge.de. Free ad blocking at the DNS level. Makes silly mobile games incapable of showing their ads as well, as a bonus. Much better environment for my kids, because these ads be TRIPPIN yo.
I’ll have to remember 9.9.9.9 instead of 8.8.8.8 The only reason I remember is someone said 8.x was owned by Amazon the other day and I had to look it up to make sure I wasn’t crazy.
https://support.nordvpn.com/hc/en-us/articles/20094975629585-Change-your-DNS-servers-on-Linux
8.8.8.8 is Google dns and pretty quick. You can also search to find some more privacy focused dns servers (but always remember if you aren’t paying for it you’re the product).
No. Not enough, still often overridden by router or whatever.
Edit
/etc/NetworkManager/NetworkManager.conf:Full file I suggest
And disable/delete “Avahi”.
Restart NetworkManager twice. If you don’t know how, restart the computer twice. No, I don’t know why twice. Now, edit
/etc/resolv.conf:Servers grabbed from here: https://servers.opennic.org/ (OpenNIC itself is kinda barely holding but the servers are pretty good).
Note that your browser will ignore this. Open up Firefox (or derivative), Settings, Privacy and security, DNS over HTTPS, Own settings, Own, and paste something like
https://dns1.slowb.ro/dns-queryinto it. Again, you can grab a server from opennic (look into description for URL). No, you cannot use opennic.glue addresses here.Now, note that this may still be tampered with, if your ISP/government cares enough. Not in the browser, but system wide yes. In this case, you will have to use dnssec-proxy, route your DNS over I2P/Tor OR run your own resolver. In all of these scenarios, you will have to make sure the program providing it is listening on port 53 (and nothing else is taking it) then just make
/etc/resolv.confthis instead:Obviously, all of this only affects DNS tampering and nothing else.
I use NextDNS. I’d pay but don’t exceed the limit of queries. Who has a paid option that are not assholes. (Love that sweet domain filtering)
If you have a spare raspberry pi and don’t mind an afternoon to get everything setup you could do what I have which is adguard home using the OISD block list and any other dns requests get resolved by unbound running on the same hardware so you’re your own dns server.
I would more recommend Quad9 instead of google. It also has some Addblock and anti tracker functionality, it also supports dns sec and dns over https. https://quad9.net/ Here the default dns resolver 9.9.9.9
I’m happily using dnsforge.de. Free ad blocking at the DNS level. Makes silly mobile games incapable of showing their ads as well, as a bonus. Much better environment for my kids, because these ads be TRIPPIN yo.
I’ll have to remember 9.9.9.9 instead of 8.8.8.8 The only reason I remember is someone said 8.x was owned by Amazon the other day and I had to look it up to make sure I wasn’t crazy.