I responded to someone in comments on a post that may not get as much visibility, and wanted to share something that might help some others who are newer to this.
I referenced Quad9 DNS as probably one of the best private DNS you can use, Swiss based, no log, no tracking, no data to sell, etc. They also implement DNSSEC, DoH, DoT, QUIC, ECS (which you may or may bot want), malware blocking, content filtering, and maybe something else I’m forgetting.
Many DNS sinkhole apps, OSes, or systems can actually utilize Quad9 for your resolver while those systems also block ads. Below is my functional list of systems that I’m aware of, though I haven’t tested everything. I believe all are considered FOSS, too. If you don’t have a spare Raspberry Pi laying around, try running in HomeAssistant, Yunohost, ZimaOS (previously CasaOS), or others.
DNS sinkhole (Adblocking) apps:
Feel free to comment and add your own I’m maybe not aware of. I’m no software engineer, but I can read through some code, though not an expert, nor have combed through these personally. Usually I’ve tested/run at the recommendation of others over the years before my ban on Reddit (for shitting on AI).
Hope this helps!!
Firefox with uBO behind a pihole pointing to Quad9 and on a router-level VPN is sufficient for 99% of users. And the 1% know exactly who they are and will harden further.
Regarding your original comment, since it regards DNS censorship, pointing people to Quad9 does not solve anything, as it is not more immune to censorship than others. You want a DNS resolver that cannot be censored as an upstream to Pi-hole and co? Set up unbound
I never understood the point in setting up unbound and pi-hole. Unbound is perfectly able to use all the filter lists you use with pi-hole, so at this point it’s nothing but an additional layer for some fancy webui with stats you never actually look at.
I’m interested as to how you’d setup unbound to use block lists. But I suppose you’d have to set a timer or cron to update them, whereas Pi-Hole does it by itself.




