nftables
Kernel-level packet filtering. Blocks malicious IPs and rate-limits abusers before they reach our stack.
We operate an open infrastructure stack. Below is the detailed technical breakdown of how we protect, filter, and secure your DNS queries.
Kernel-level packet filtering. Blocks malicious IPs and rate-limits abusers before they reach our stack.
Stateless content filtering. Acting as a pure DNS firewall to block ads and trackers without local caching.
Recursive logic engine. Orchestrates query flow and manages the persistent Redis cache via high-speed Unix sockets.
In-memory key-value store. Serves cached DNS responses in sub-millisecond latency using direct socket memory.
Secure upstream transport. Encrypts queries and enforces DNSSEC validation with root servers.
We strictly block these sources at the network edge.
This lists reflects our current
dns-guard configuration.
Domain-based blocklists that filter ads, trackers, malware, and phishing at the DNS level. These work after traffic passes the firewall.