| ▲ | jsrozner 5 hours ago | |
I keep meaning to set this up but haven't. What's the simplest best setup for my own DNS blocker? | ||
| ▲ | drnick1 4 hours ago | parent | next [-] | |
The easiest off-the-shelf option would be a router running OpenWrt. IIRC, it natively uses dnsmasq, and the relevant blacklists can be obtained from here: https://github.com/hagezi/dns-blocklists My own setup is DIY: a Debian box running Unbound (recursive DNS) with the RPZ blacklists from above. This gets rid of the upstream DNS service such as the ISP's completely, and prevents tampering or censorship. | ||
| ▲ | anygivnthursday 2 hours ago | parent | prev | next [-] | |
For a home network network pihole or unbound also supports blocklists (bundled with opnsense for example if you also want a firewall). For Android, I use Rethink with Hagezi blocklists, so they block also when I am on mobile data (it is vpn based). | ||
| ▲ | eevahr 4 hours ago | parent | prev | next [-] | |
For simplicity I highly recommend https://nextdns.io. Supports most devices, and probably most, if not all, well known blacklists. | ||
| ▲ | kuerbel 4 hours ago | parent | prev [-] | |
Hmmm Pihole I guess. Runs on a pi zero (1 or 2 but 2 is better ofc) | ||