TL;DR

  • Nothing changes for you. Same address, 194.180.189.33 and dnsdoh.art; the same DoH3, DoH, DoT and DoQ; the same four blocklists. No client needs reconfiguring.
  • On the server, four patched programs are gone. Our forks of AdGuard Home, dnsproxy, urlfilter and dnscrypt-proxy were replaced by dnsdist in front of Unbound, both run exactly as their authors release them.
  • Dates (UTC+3): dnsdist took over ports 53 and 853 on 27 September at 19:42. On 4 October at 18:36 Unbound began reaching Cloudflare and Quad9 over DNS over TLS itself, and the old components were removed the same evening.
  • The reason is maintenance, not speed. At about 18 queries a second, speed was never the question. Each upstream release meant carrying our patches across four forks.

This resolver never ran AdGuard Home as released: it ran AdGuardHome-edge, our own fork. AdGuard Home is built for home and office networks, and we had adapted it to a public edge with our own patches, which made every new release a review-and-port job, often ending in "nothing to take". The cost came from keeping copies, not from the software. dnsdist turned out to need only configuration for everything we chose to keep, plus a small compiler of ours that turns the AdGuard-syntax blocklists into a database dnsdist reads.

Before the switch, both front ends ran side by side and a second server asked them the same 19 questions until there were no unexplained differences. The switch itself took 2.4 seconds, but from outside plain UDP was silent for 4.2 seconds and DNS over QUIC for 5.2, and we do not yet know where the extra time went. Two behaviours were not carried over: a reply to malformed queries, and dnscrypt-proxy’s quick failure for domains whose own servers do not answer. One improvement came with the move: DNS cookies are now tied to the real client address.

The full account, written to be readable without a DNS background, with the parity results, the gap measurements, the dnscrypt-proxy comparison and the commands to check every claim yourself, is in moving a public resolver from our AdGuard Home fork to dnsdist and Unbound. The resolver build is public at unbound-edge.

The old code is archived on GitHub, read-only, so earlier articles can still link to it: our forks of dnsproxy, urlfilter and dnscrypt-proxy, and the AdGuardHome-edge specification.