Post B61vW8m7qnMsEWtCaG by arichtman@eigenmagic.net
(DIR) More posts by arichtman@eigenmagic.net
(DIR) Post #B61vEK4h6IeK484vc8 by star@amazonawaws.com
0 likes, 0 repeats
Fedi, what DNS servers do you use? :neocat: (Please also provide info on whether the DNS server you use has DNSSEC, if you know this info) :boost_requested:
(DIR) Post #B61vPxQb7tZlIqs6M4 by aura@gts.foxsnuggl.es
1 likes, 0 repeats
@star uh, as a recursive resolver or authoritative?
(DIR) Post #B61vPxaAYJERmXLkH2 by star@amazonawaws.com
0 likes, 0 repeats
@aura either!
(DIR) Post #B61vW8m7qnMsEWtCaG by arichtman@eigenmagic.net
1 likes, 0 repeats
@star quad9 DoT. Port forwarding in home router LAN so all regular DNS traffic is trapped and upgraded
(DIR) Post #B61vYX2uaEja5RshIO by alexia@starlightnet.work
1 likes, 0 repeats
@star I use quad9, they do DNSSEC :)as a fallback I just default back to Cloudflare, but most queries I make use Quad9
(DIR) Post #B61vZrTg6WrrkD2EOu by arichtman@eigenmagic.net
1 likes, 0 repeats
@star unbound recursive resolved cause it's what came with OPNsense but looking at bind for authoritative also
(DIR) Post #B61xm93ykP9XfU01Uu by fugi@amazonawaws.com
0 likes, 0 repeats
@star I use adguardhome with unbound as recursive resolver behind it (three deployments, for home and elsewhere)
(DIR) Post #B61xon1r7utuCOGdxQ by aura@gts.foxsnuggl.es
1 likes, 0 repeats
@star coredns, but only because it's easy to write plugins for (for me)(i maintained a homebrew DNS using the same library once)
(DIR) Post #B61xsg198YWzbymyoK by valk@social.treehouse.systems
1 likes, 0 repeats
@star i host my authoritative DNS server with Knot, which supports DNSSEC but it is not configured on my network
(DIR) Post #B61zORWgeOk9t9FkWG by sa7dse@chaos.social
1 likes, 0 repeats
@star I use https://blog.uncensoreddns.org/ and quad9 when on the go. In my own network i just use a local knot-resolver.All 3 options do DNSSEC validation.
(DIR) Post #B61zOylN4p66yFNRUO by theodora@rivals.space
1 likes, 0 repeats
@star desec.io, with DNSSEC ofc :)
(DIR) Post #B620z1t12eFR2Khssi by freya@raru.re
1 likes, 0 repeats
@star I use https://blog.uncensoreddns.org/They only support encrypted DNS, and they do support DNSSEC