Add OpenNIC DNS Servers

I'd love to see OpenNIC servers added to the default list, it's been around since 2000 and it's relatively popular among privacy-minded techies :wink:

There's a lot of DNS servers available since it's a community project, but I think it'd make the most sense to add the main Anycast servers:

  • 185.121.177.177 2a05:dfc7:5::53
  • 169.239.202.202 2a05:dfc7:5353::53

Edit: see my post below.

More info at https://www.opennic.org/

I did see that post, and I think we reasonably meet all the requirements.

The two servers I mentioned do technically log, in the sense that they cache queries and responses in a redis database for performance across all nodes, but that seems like a reasonable limitation and all logs are anonymized (no user data retained).

We also have DNSSEC, but not using the default trust anchors (like I mentioned in my other post).

I really don’t think these are major issues (especially if you’d be willing to work with us on DNSSEC), since it’s essentially impossible to find a DNS server that doesn’t log in some form (caching). If they are, let me know, and I’ll see if we can work something out.

I personally think it’d be beneficial for you to start endorsing open-source services with aligned values vs servers from the likes of Google, OpenDNS, etc.

1 Like

Hello JonahAragon, there are servers that don't keep logs. Have a look at https://servers.opennic.org/ and take a closer view at the 'flags':
blue⚑ Anonymized logs
violet⚑ No logs kept
yellow⚑ DNScrypt
white⚐ Whitelisting
black⚑ Blocklist
When you click on a server specific data about the habit is shown. For most servers with a blue flag for example: Retained 12 hours \n DDoS protection

I think the mayor obstacle in implementing opennic is the fact that you should pick the DNS Server with the closest location. So using the custom entries for your own specific choice may be the way to use the services together anyway.