
Public DNS providers will hide your WAN IP as well as potential extra security. Your browser caches queries as well, remember? OpenDNS offers custom blocking categories with free home account if you are interested. with available DoT straight on the router. You may get overall worse reliability and DNS resolution speed compared to no extra device and built-in Dnsmasq forwarder to always available 10-30ms away huge cache Google, Cloudflare, OpenDNS, etc. I think that it is showing that most dns queries are going via unbound but are not encrypted.įor DNS1 - can I improve this or is this as good as it gets using unbound?įor DNS2 - if I change the nextdns IP to the DNS-over-TLS/QUIC address in the dhcp settings - will this enable dns privacy on the 5-10% of dns queries that do not go through DNS1?

Hi All - I just wanted some advice to see if there is more I could do/consider to increase DNS privacy on my home internet setup.
