# modDNS closed beta - DNS-level ad/tracker blocking by IVPN

**URL:** https://discuss.privacyguides.net/t/moddns-closed-beta-dns-level-ad-tracker-blocking-by-ivpn/36321
**Category:** Project Showcase
**Tags:** software
**Created:** 2026-03-16T15:51:17Z
**Posts:** 88

## Post 1 by @viktorivpn — 2026-03-16T15:51:17Z

Hello everyone in the PG Community,

We’ve been working on standalone privacy tools to complement the IVPN service, and this week we are launching our next project modDNS in closed beta. Extending an invite (with some gifts) to the Privacy Guides community made sense before official announcements.

modDNS is a DNS filtering service that blocks ads, trackers, and malicious domains at the DNS level with granular controls over what gets filtered. You can set it up system-wide on any OS, within IVPN apps, or directly in browsers. It supports DoH, DoT, and DoQ.

What you get in the beta:

- Configurable blocklists: curated combinations or community lists (Hagezi, OISD, AdGuard, StevenBlack, etc.)
- Custom rules: allowlist and denylist specific domains, with allowlist entries overriding active blocklists
- DNS profiles: multiple configurations with unique identifiers for different devices
- Query logging: optional, disabled by default, with configurable retention periods

The codebase is [open source](https://github.com/ivpn/moddns). A security audit by Cure53 was completed before the beta launch, with no high or critical vulnerabilities found across a six-day assessment by four senior testers. The [full report is available](https://github.com/ivpn/ivpn.net/blob/4b393ba29b34ff761a6b049192fcf48fb6ad27bd/src/static/resources/IVP-08-report.pdf).

Registration starts in the IVPN My account area. After completion we discard the association between the IVPN account and the modDNS account. This means we can’t recover modDNS access through IVPN if access is lost. A formalized trustless system for this separation is in development and will be open-sourced by the time we go out of beta.

modDNS is part of a broader direction for IVPN. Mailx for email aliasing is already available in beta and we now operate Portmaster+SPN for application-level firewall controls. We feel that these services fit together naturally into a new profile. No plans to expand into services like calendar, data storage, etc.

What’s coming in the next couple of weeks:

- Ironing out edge case network routing issues and adding more server locations (currently serving from Amsterdam and Toronto)
- Service-level blocking (Facebook, Amazon, Google, etc.)
- Category blocking (adult, gambling, etc.)
- Statistics page

This is a beta, so occasional downtime or rough edges are possible.

## How to get access

modDNS is currently available to IVPN Pro customers with one year or more remaining on their current plan. Check the modDNS tab on your [IVPN account page](https://www.ivpn.net/en/account/) if you are eligible.

If you want to test modDNS but are not an IVPN customer or don’t have a year on Pro, we are giving away five one-year IVPN Pro vouchers. These give you access to both modDNS and Mailx right away.

Requirement: at least [Trust Level 2](https://blog.discourse.org/2018/06/understanding-discourse-trust-levels/) on Privacy Guides forum.  
Just message me, first five receive a voucher in reply. I’ll update this post when they’re gone.

## Feedback

We would like to improve and create an outstanding service, that’s only possible if we have user feedback. DM me here, post in this thread, or email [moddns@ivpn.net](mailto:moddns@ivpn.net). Bug reports, feature requests, blocklist tests, performance notes, all welcome.

A full blog post with additional details will follow.

Looking forward to hearing what you think.

Viktor / IVPN

---

## Post 2 by @ph00lt0 — 2026-03-16T15:52:19Z

We leave the invites to the community but definitely going to try this out.

---

## Post 3 by @bodin — 2026-03-16T16:44:03Z

@viktorivpn I would love to try this out!

---

## Post 4 by @viktorivpn — 2026-03-16T17:06:41Z

Messaged you!

---

## Post 6 by @polyester_apricot650 — 2026-03-16T17:31:23Z

Hi Victor,

Just curious about the origin of the name.

Is this IVPN’s equivalent of NextDNS and AdGuard DNS? If so, how is it better? How will modDNS compete with these services in the future?

---

## Post 7 by @viktorivpn — 2026-03-16T20:32:16Z

> [@polyester_apricot650](#):
>
> Just curious about the origin of the nam

No special meaning, we had a large pool of options and internal voting and discussions surfaced it as the front runner. You can “modify your DNS resolutions” with it:)

> [@polyester_apricot650](#):
>
> Is this IVPN’s equivalent of NextDNS and AdGuard DNS? If so, how is it better? How will modDNS compete with these services in the future?

In short, yes.

How is it better → The biggest thing right now I’d say is trust. We have a great track record in honoring privacy commitments, you can create an (IVPN) account without an email, pay with anon friendly payment options. The service is audited and open source.

This is not a novel service, but an important one in our customers’ (and our) toolkit. We acknowledge the best competitors, including those you named, have pretty mature products. We have a way to go to catch up and then find ways to do even better, we will focus on that in the next 12 months in terms of features and performance. For the time being we won’t offer it as a standalone product, only to IVPN customers.

---

## Post 8 by @viktorivpn — 2026-03-16T20:38:39Z

5 Vouchers are gone, thanks everyone for your interest in testing modDNS!

---

## Post 9 by @p3tsh0p — 2026-03-16T22:27:55Z

Looking forward to testing this. I’ve been trying out NextDNS, AdGuard DNS and ControlD the past couple months to see which works best for me. Each seems to have something I don’t like about them, so it’ll be interesting to see how everything is set up and looks with modDNS.

Also, if I remember correctly, there are going to be pricing changes in Q1 for IVPN? Are you guys planning on ever releasing premade bundles or mix-and-match bundles with your various services?

---

## Post 10 by @Footnote5444 — 2026-03-16T22:39:06Z

Looking forward to trying this when it becomes available for signups. As someone who has tried NextDNS and AdGuard DNS, I hope you will allow for the importing of custom filter lists. Hagezi offers some block lists that are perhaps niche, but are not offered as a default option in your competition.

NextDNS does not allow users to import custom block lists. AdGuard now does, but is capped at 1000 rules total so larger lists are not an option. Not sure about ControlD.

Just wanted to provide my feedback as it is an aspect (user customization control) that seems lacking at times from other DNS services.

---

## Post 11 by @viktorivpn — 2026-03-16T23:14:50Z

> [@p3tsh0p](#):
>
> Looking forward to testing this. I’ve been trying out NextDNS, AdGuard DNS and ControlD the past couple months to see which works best for me. Each seems to have something I don’t like about them, so it’ll be interesting to see how everything is set up and looks with modDNS.

We had the same experience, which was a strong push towards us building modDNS. Looking forward to hear more about what you like about it and what we should change.

> [@p3tsh0p](#):
>
> Also, if I remember correctly, there are going to be pricing changes in Q1 for IVPN? Are you guys planning on ever releasing premade bundles or mix-and-match bundles with your various services?

Yes, this is in the works, we need a bit more time - Mailx and modDNS beta testing phase has to conclude first. We plan to have a VPN-only plan and two bundles replacing our current tiers, but not mix-and-match. Details are not final yet so that’s all I can share at this point.

---

## Post 12 by @fiqiluvo.epileto — 2026-03-16T23:19:19Z

> [@viktorivpn](#):
>
> modDNS is a DNS filtering service that blocks ads, trackers, and malicious domains at the DNS level with granular controls over what gets filtered. You can set it up system-wide on any OS, within IVPN apps, or directly in browsers. It supports DoH, DoT, and DoQ.

On your servers? RTT, traffic is somewhat wasteful. Blocking could be done on a local forwarding DNS server with FakeIP or total empty response.

> [@viktorivpn](#):
>
> Custom rules: allowlist and denylist specific domains, with allowlist entries overriding active blocklists

It’d be cool to see domain sniffing functionality. Such usecase would be more useful for PBR, but i can imagine some people wanting to make their own filtering. So essentially what RethinkDNS offers with its logging or better yet sing-box.

> [@viktorivpn](#):
>
> How to get access

What exactly do you want to be tested? Or is it simply an ad?

---

## Post 13 by @Banter8905 — 2026-03-16T23:21:26Z

> [@viktorivpn](#):
>
> Yes, this is in the works, we need a bit more time - Mailx and modDNS beta testing phase has to conclude first. We plan to have a VPN-only plan and two bundles replacing our current tiers, but not mix-and-match. Details are not final yet so that’s all I can share at this point.

Any update as to when the transition to RAM only servers will be complete?

---

## Post 14 by @viktorivpn — 2026-03-16T23:22:18Z

> [@Footnote5444](#):
>
> NextDNS does not allow users to import custom block lists. AdGuard now does, but is capped at 1000 rules total so larger lists are not an option. Not sure about ControlD.

Thanks for the feedback. We have evaluated this, there are tradeoffs around usability (list processing and omissions), resource abuse, preventing injections etc., it’s not a quick addition. We understand the need for it and it’s on our roadmap, but it’s not prioritised at the moment.

---

## Post 15 by @viktorivpn — 2026-03-16T23:35:09Z

We have a couple of RAM-only servers live, currently:  
[ar1.gw.ivpn.net](http://ar1.gw.ivpn.net) - Buenos Aires, Argentina  
[us-az2.gw.ivpn.net](http://us-az2.gw.ivpn.net) - Phoenix, Arizona, US  
[us-fl2.gw.ivpn.net](http://us-fl2.gw.ivpn.net) - Miami, Florida, US  
The replacement process is not straightforward as our new infra is building on previously untested concepts (we will detail this when we are further along the process). We decided to postpone the continuation of the rollout to focus on projects that bring more day-to-day value to users.

Right now the whole team is working on completing the new service launches and rolling out new pricing. When it’s done we’ll shift our attention back to VPN infrastructure.

In the spirit of transparency, this is a promise from 2025 we did not keep fully as we expected that shift back to happen in Q3 or Q4 last year.

---

## Post 16 by @fiqiluvo.epileto — 2026-03-17T00:10:12Z

Ok, I’ve skimmed through the code and understand the gist of it. I thought that this app will configure DNS filtering on your end for some reason.

- I hope your forwarding DNS isn’t configured to fallback for plain DNS as downgrade attacks will be possible.

- OpenWRT integration is kind of a given for such a project, but I’m unsure about it’s usefulness as iVPN doesn’t offer a VPN client.

I think it’d be a nice additional feature to a VPN client, but integrating it with the other VPN clients without breaking the routing will be painful. (you need to downgrade DoT, DoH or even DoQ to enforce filtering) I think that this product as a standalone thing deserves to be living on a router, but there are already infinitely more capable things that can do PBR filtering and routing such as sing-box out there.

---

## Post 17 by @mongrel306 — 2026-03-17T04:56:50Z

I was just wondering whether the DNS that’s being introduced here will eventually be made the default DNS for all Standard/Pro users?  
Some people say that if your DNS settings stand out, it can make you easier to fingerprint ([ref](https://discuss.privacyguides.net/t/proton-vpn-custom-dns-better/26884/3)). So I’d like to understand the pros and cons of using this feature, especially whether it could make me stand out compared to other IVPN users.

Also, if you can, I’d like to know how modDNS sees the risks of fingerprinting when using custom DNS filters or rules.

---

## Post 18 by @Encounter5729 — 2026-03-17T07:11:08Z

Would it be system-level DNS ? That would be very cool, like Rethink DNS

---

## Post 20 by @viktorivpn — 2026-03-17T09:03:51Z

_note: meant to edit instead of delete, reposting_

> [@mongrel306](#):
>
> I was just wondering whether the DNS that’s being introduced here will eventually be made the default DNS for all Standard/Pro users?

This is not planned, but can be considered (as a baked-in option for example in IVPN apps as a first step). For the foreseeable future this will be an opt-in service available to Pro subscribers, and IVPN DNS and modDNS DNS run separately.

> [@mongrel306](#):
>
> Some people say that if your DNS settings stand out, it can make you easier to fingerprint ([ref](https://discuss.privacyguides.net/t/proton-vpn-custom-dns-better/26884/3)). So I’d like to understand the pros and cons of using this feature, especially whether it could make me stand out compared to other IVPN users.

As with many questions like this, the right answer is “it depends (on your threat model)”. We are aware of this problem and agree with PG recommendation that you should use the VPN provider DNS unless you have a good reason to do so. Using a different DNS does make you stand out vs other IVPN users in this specific consideration, but some of the other users will use modDNS as well.

As Jonah put it you need to decide whether gaining these extra capabilities is worth the tradeoff. We don’t have first-party research and data on “how much better can websites fingerprint you Scenario A vs. Scenario B” to help with evaluating the severity of this issue. If you are concerned about this go with the safer choice.

This is worth adding to our FAQ so will make a note of that.

---

## Post 21 by @viktorivpn — 2026-03-17T10:54:39Z

> [@Encounter5729](#):
>
> Would it be system-level DNS ? That would be very cool, like Rethink DNS

This is a remote resolver, OS-level interception and per-app controls are handled by a separate layer. For that we have Portmaster in our stack, where you can add modDNS as a custom resolver. However, Portmaster is currently available for Windows and Linux only.

---

## Post 22 by @Edward.snowedin — 2026-03-18T03:32:43Z

Here to ask the same thing. Current NextDNS user (and loving it).

---

## Post 23 by @Blackbird — 2026-03-18T07:03:25Z

I’ve been using this myself for a while and I’m really happy with it!

---

## Post 24 by @polyester_apricot650 — 2026-03-18T13:14:25Z

Not sure if I understand the difference. I’m assuming the IVPN app will have to be installed in order to enforce system-wide DNS interception?

---

## Post 25 by @polyester_apricot650 — 2026-03-18T13:17:27Z

This would be a very good differentiator between your product and NextDNS. At this point, it’s still not clear to me what the advantage of modDNS is. NextDNS is also very private, but development seems non-existent.

---

## Post 26 by @polyester_apricot650 — 2026-03-18T13:19:52Z

I agree, but NextDNS also has trust. Feature-wise, what does modDNS have that NextDNS doesn’t? Why should someone pick modDNS over NextDNS?

Q1 is almost over. I’m assuming any price changes will occur in Q2 at the earliest?

I know you can’t share too much details, but given what you have said, will existing IVPN users have access to Mailx and modDNS until their subscription renews? Or will they be asked to pay mid-subscription?

I’m assuming that a future tier including IVPN Pro, Mailx, and modDNS will be more expensive than IVPN Pro is today.

---

## Post 27 by @viktorivpn — 2026-03-18T15:09:46Z

Please bear in mind this is a beta announcement. NextDNS has been in development for like 7 or 8 years. We did not promise we’ll launch this service with clear technical or feature differentiators. As mentioned above, we aim to get there but that takes time.

Trust is a personal thing. Many IVPN users are not doubt will feel more comfortable if we handled their DNS requests instead of NextDNS or ControlD. Further, modDNS is currently free to use and will stay free for IVPN Pro users. That’s another clear benefit. UI/UX is different, I think blocklist handling and custom rules additions are easier to manage, but that’s subjective.

If you are satisfied with NextNDS, have an established setup and you trust them, there is no good reason for you to switch to this service right now, and that’s OK.

---

## Post 28 by @viktorivpn — 2026-03-18T15:15:15Z

As I understand RethinkDNS on Android is primarily a local firewall that enables per-app controls. My interpretation was @Encounter5729 assumed this is a similar product, while it’s closer to NextDNS and co. It depends on what you mean by “system-wide”. But no, you don’t need the IVPN app to use this product for processing all DNS requests on one device, there are setup instructions for popular OS’s.

---

## Post 29 by @polyester_apricot650 — 2026-03-18T21:56:54Z

Hi Victor, I’m sorry if you were offended by my post. I think it’s actually great that you’re launching modDNS. I guess I had this expectation that you were going to launch something that will blow NextDNS out of the water on day one. My bad. I feel like NextDNS has stagnated the last couple of years. It does work, so I guess I can’t complain there, and I do trust their product and yours too. Hopefully, it won’t take modDNS 7-8 years to catch up to NextDNS. I really would love if modDNS becomes a viable replacement for NextDNS.

---

## Post 30 by @polyester_apricot650 — 2026-03-18T22:00:12Z

On macOS, I’m under the impression that something like Little Snitch will need to be installed in order to force all system DNS queries to the DNS service of your choice, let’s say modDNS. So without Little Snitch, how do I ensure all macOS and app queries go through modDNS?

---

## Post 31 by @Catalyst2422 — 2026-03-19T09:38:51Z

I’m trying it out at the moment. No major issues so far. A few minor quibbles, but I want to test it for longer before summing them up.

Has anyone conducted and latency/performance testing against other providers? I’d be particularly interested in testing it against other ad-blocking DNS resolvers and using DoH, DoT etc.

---

## Post 32 by @viktorivpn — 2026-03-19T09:50:42Z

No offence taken, we appreciate the feedback.

---

## Post 33 by @viktorivpn — 2026-03-19T10:47:32Z

Thanks for the note. We are running latency/performance testing internally from multiple residential locations and do monitoring for routing issues. Our current assessment is that the service is acceptable for day-to-day use, but there is a lot of room for improvement on this point. Feedback from users is very valuable at this point.  
Two key things that affect performance:

1. We have two PoP’s in the first stage of beta (Amsterdam and Toronto), we’ll be adding more during beta.
2. We have identified Tier 1 routing issues where requests from NA are getting routed to Europe and vica versa. We are investigating solutions for this.

---

## Post 34 by @mongrel306 — 2026-03-19T11:10:45Z

How do you plan to handle log policies and legal requests for services other than the VPN, like Mailx and modDNS?

With Mailx and modDNS, users can set things up so that they keep email and DNS logs. This is different from the VPN, which doesn’t do that.  
So, I’m curious to know if log requests will be turned down in the same way as for the VPN, or if some logs or info might be shared depending on the situation.

---

## Post 35 by @viktorivpn — 2026-03-19T12:25:29Z

The short answer is we handle requests in a way that fulfils legal requirements, but only to the extent absolutely necessary. These are not services run by anons in an offshore jurisdiction (as with IVPN). This does NOT mean that we flat out refuse requests for information, but we assess the validity and in most cases we can argue on them not being valid. You are right that IVPN is in a better position as we have absolutely zero logs to share on a specific customer or origin IP, even if we were to get a court order on usage data there would be none to share.

what we can do for Mailx and moddns:

1. minimise data collection, eg. modDNS has all logs off by default, Mailx immediately deletes successfully delivered messages, etc. we detail these in the respective privacy policies. if you don’t enable logs in modDNS we only record which blocklists are enabled and total number of queries processed in aggregate (abuse mitigation). for Mailx your aliases are stored.
2. severe the link between the IVPN account information and other services. this not only helps with compartmentalising potential data on usage, but results in no payment information on file for Mailx, modDNS accounts.

---

## Post 36 by @anon17897338 — 2026-03-19T15:26:06Z

Love this idea as you have the perk of having customizable DNS without having to trust another party. Wish more VPNs would do this. Will this be exclusive to iVPN subscribers? Im mainly asking because this combined with Portmaster could be a really interesting workflow

---

## Post 37 by @viktorivpn — 2026-03-19T15:39:07Z

> [@anon17897338](#):
>
> Will this be exclusive to iVPN subscribers?

Yes, for the foreseeable future. If you want to combine Portmaster with modDNS we are working on an IVPN suite plan that will include both (release date and details not finalised).

---

## Post 38 by @Litigated — 2026-03-21T10:33:07Z

Hi @viktorivpn

Having reviewed the modDNS Privacy Policy policy, I have a few questions I would be grateful if you could address.

It is presently unclear whether modDNS operates under its own Terms & Conditions, or whether those of IVPN apply by extension. IVPN’s current Terms & Conditions make no reference to modDNS (or Mailx). Could you clarify whether modDNS will have its own Terms & Conditions, or whether IVPN’s will govern by extension?

Furthermore, under the section “What information is logged about DNS activity?”, paragraph (b), the policy sets out the data points logged, which include the timestamp of the query, the requested domain or IP address, the decision and its trigger, the client IP address, and the device identifier where configured.  
The same paragraph confirms that users have full control over the retention period, which may be set between a minimum of one hour and a maximum of one month, with a default of one hour. It further confirms that any logs exceeding a newly configured timeframe are immediately deleted upon a change to that setting, and that users may permanently delete all stored query logs at any time via the dashboard.  
However, the paragraph does not expressly state what occurs to logged data upon the expiry of the applicable retention period in the ordinary course, that is, absent any manual deletion or reconfiguration by the user. It can reasonably be inferred from the section “How do you respond to legal requests for data?” that logs are deleted at the end of the retention period; however, a consumer may not reasonably make such inference across separate sections of a policy that is, in all likelihood, incorporated into the contractual terms. I would be grateful if you could confirm if the Privacy Policy will be amended, prior to modDNS exiting beta, to state in plain terms that query logs are automatically and permanently deleted from your systems upon expiry of the user-configured retention period.

---

## Post 39 by @viktorivpn — 2026-03-21T14:23:15Z

modDNS has its own ToS, IVPN one is not applicable:

> **[modDNS](https://app.moddns.net/tos)**

Thanks for the request for clarification on the privacy policy, your note makes sense, we will review and modify as deemed necessary.

---

## Post 40 by @Toranja — 2026-03-22T13:43:29Z

Hi Viktor I’m a pro customer since years but I cannot find the option to apply for it. Can you advice please?

---

## Post 41 by @viktorivpn — 2026-03-22T13:56:26Z

You need at least 1 year _remaining_ time on your account.

You have two options:

1. We will roll out invites to all Pro customers in the coming weeks, so you can start testing then
2. Message me here and we’ll see what we can do to enable it for you, for that you’ll have to reveal your Safe reference ID

---

## Post 43 by @Rasta — 2026-03-22T17:48:12Z

@viktorivpn I have a question about the link between IVPN pro and modDNS. If the IVPN account is used to create a modDNS account, how to you account for the time of subscription between them. Does it default to the remaining time on your IVPN account, or something else? Then come renewal time, do you have to somehow relink modDNS to IVPN to verify the new account balance? With the accounts being disconnected I’m not sure how access to one can result in access to the other.

---

## Post 44 by @Toranja — 2026-03-23T12:04:32Z

> [@viktorivpn](#):
>
> Message me here and we’ll see what we can do to enable it for you, for that you’ll have to reveal your Safe reference ID

I’d like to apply sooner but my remaining account time is less than 1 year anyway I’ll extend it for sure. My safe reference ID I’m able to provide by PM or by private email if you want. Please let me know.

---

## Post 45 by @viktorivpn — 2026-03-23T12:31:27Z

Hi @Rasta

During beta the severing of that link is “manual”, there is not account recovery method and there is no renewal. This is possible as everyone who signs up during beta will have access to the service as long as it’s in beta, there is no enforced expiry, even if the IVPN account expires.

This will change when we exit beta, we have developed a system we call Zero-link access, which uses an HSM server to track IVPN subscription states through a manifest and distribute them to additional services without passing on the account ID. IVPN never directly communicates user identities to Mailx/modDNS/Portmaster systems, and the services never needs to know which IVPN user corresponds to the service account. This ensures that renewals/expiry is synced (daily batch to avoid correlation possibility), but IVPN Account ID’s are not revealed to services. Zero-link access is in internal testing phase, and we will release documentation and code once ready and in production.

---

## Post 46 by @viktorivpn — 2026-03-23T12:32:06Z

DM me the safe reference if you are OK with sharing and i’ll look into it.

---

## Post 47 by @Toranja — 2026-03-23T12:57:46Z

> [@viktorivpn](#):
>
> DM me the safe reference

I’d like to do that but honestly I didn’t find that function here, sorry I’m new here. How to find it?

---

## Post 49 by @Toranja — 2026-03-23T14:23:52Z

Tried that before asking, there is no option for that, see

 ![screen](https://forum-uploads.privacyguidesusercontent.com/original/3X/e/b/ebeca9c5e147a0c947a5460ad6782dcf0f4819e7.png)

---

## Post 50 by @lamtrinhdev — 2026-03-23T14:35:31Z

Dear @Toranja ,

I can see the send message option ( you can refer attached screenshot).

I think the problem can be your Trust Level of you that is “New User”. I think that is limited for sending message.

Thanks,

Lam

 ![Screenshot_20260323-092812](https://forum-uploads.privacyguidesusercontent.com/original/3X/6/1/6156c56294fe7c0522afa49cd6467f83651dde85.png)

 ![Screenshot_20260323-092800](https://forum-uploads.privacyguidesusercontent.com/original/3X/2/4/2483bd1afdd0614bee1d5cc29390619604ed8779.jpeg)

---

## Post 51 by @any1 — 2026-03-23T14:41:44Z

~~Might be because you are a fairly new account and need a higher trust level~~

Didn’t see that this was already mentioned above :sweat_smile:

---

## Post 52 by @Toranja — 2026-03-23T14:50:24Z

Thanks obvisiously it is the case

---

## Post 53 by @mongrel306 — 2026-03-23T15:33:57Z

Will modDNS, like IVPN, eventually allow users to log in using only the account number?

Since none of our competitors’ DNS services have implemented this yet, I hope it will become possible after the beta version.

---

## Post 54 by @Anonymous582 — 2026-03-23T15:49:31Z

I think you should send email to @viktorivpn . It is the quick option for you @Toranja .

---

## Post 55 by @Toranja — 2026-03-23T16:18:28Z

I was about to do that :+1:

---

## Post 56 by @viktorivpn — 2026-03-23T22:13:31Z

Yes that would make sense. The biggest drawback is since you cannot recover your modDNS account with your IVPN account ID and payment info, if you lose your modDNS account ID you have zero recovery options. This is not untenable, but far from ideal, so it’s not an easy tradeoff.

---

## Post 57 by @lumes — 2026-03-24T01:31:28Z

This looks very interesting :eyes:!!

- Will moddns be restricted to only iVPN users in the future?
- How’d this be compared to NextDNS?

Personally, I’d love to use a service like this which feels more transparent compared to NextDNS and has a generous Paid Plan too, I’m willing to pay :).

---

## Post 58 by @viktorivpn — 2026-03-24T10:37:31Z

Thanks @lumes !

1. Only IVPN users for the time being, even after beta ends. Long-term plans include offering it as a standalone service, but I can’t give timeframes on this.
2. Compared to NextDNS, quotes from earlier:

> [@viktorivpn](#):
>
> How is it better → The biggest thing right now I’d say is trust. We have a great track record in honoring privacy commitments, you can create an (IVPN) account without an email, pay with anon friendly payment options. The service is audited and open source.
> 
> This is not a novel service, but an important one in our customers’ (and our) toolkit. We acknowledge the best competitors, including those you named, have pretty mature products. We have a way to go to catch up and then find ways to do even better, we will focus on that in the next 12 months in terms of features and performance. For the time being we won’t offer it as a standalone product, only to IVPN customers.

> [@viktorivpn](#):
>
> Trust is a personal thing. Many IVPN users are not doubt will feel more comfortable if we handled their DNS requests instead of NextDNS or ControlD. Further, modDNS is currently free to use and will stay free for IVPN Pro users. That’s another clear benefit. UI/UX is different, I think blocklist handling and custom rules additions are easier to manage, but that’s subjective.
> 
> If you are satisfied with NextNDS, have an established setup and you trust them, there is no good reason for you to switch to this service right now, and that’s OK.

---

## Post 59 by @viktorivpn — 2026-04-02T08:40:02Z

Quick update on progress.

Note to beta testers: Blocklists have changed significantly and your set up might be affected, please review your list settings.

We have released a major update yesterday, added or improved:

- Categories blocking - Gambling, Crypto, Adult content, etc.
- Services blocking - Facebook, Apple, Amazon, etc. known domains and services
- Removed redundant blocklists (HaGeZi mini and medium alternatives)
- Light theme
- Privacy Policy wording regarding logs deletion after retention period (additional emphasis on purging)

We plan to roll out new invites for IVPN Pro customers next week.

Thanks for your testing and feedback.

---

## Post 60 by @Toranja — 2026-04-04T11:50:12Z

Hi, I’ve tested modDNS and I discovered it works only in Firefox and Chromium browsers, Installing it as described on your website for Linux in `/etc/systemd/resolved.conf`it blocks all internet traffic and in GOS I wasn’t successful either under Android STEP 5 Select Private DNS provider hostname and STEP 6 inserting `xxxxx.dns.moddns.net`gives me the error message incorrect https page. What do you recommend to fix it?

---

## Post 61 by @lamtrinhdev — 2026-04-04T14:30:26Z

Wow. It is cool. Just subscribed IVPN Pro and waiting for next week with modDNS @viktorivpn ^\_^.

---

## Post 62 by @viktorivpn — 2026-04-07T14:06:45Z

Hi @Toranja - can you share more info on your Linux distribution + version so we can look into that aspect?

Regarding GOS / Android - I run this setup without issues, and just re-tested it. I turned on Android Private DNS and entered the DNS-over-TLS address gathered from Setup in modDNS and it works. You need to type in or copy exactly, trailing spaces are common errors. If you still see errors it could be your network blocking port 853. Can you test DoT from another provider?

---

## Post 63 by @Toranja — 2026-04-08T08:46:10Z

Yes I’ll send you a PM with the Linux system details. As for GOS I’ll check later

---

## Post 64 by @viktorivpn — 2026-04-08T11:55:08Z

Invites are extended - IVPN Pro subscribers with at least 1 month remaining on their account can access the modDNS beta starting today. Get started via the modDNS tab in your account dashboard: [https://www.ivpn.net/en/account/](https://www.ivpn.net/en/account/)

---

## Post 65 by @chr99 — 2026-04-08T12:40:51Z

Fantastic news, thanks a lot @viktorivpn !

---

## Post 66 by @lamtrinhdev — 2026-04-09T03:33:54Z

Amazing, @viktorivpn .

---

## Post 67 by @Bhaelros — 2026-04-24T18:02:26Z

Any ETA on IPv6, Germany POPs, DoH/3 and DNSSEC support?

---

## Post 68 by @viktorivpn — 2026-04-26T20:04:29Z

IPv6 - on the roadmap, we are currently working on adding more PoPs and fixing routing on the infra side, then we’ll switch to ipv6 support. no ETA.

Germany PoP - right now we have 2 PoPs Amsterdam and Toronto. We are working on adding 5-6 new end points in different Geos first (US, SE Asia, Sydney, etc.). Frankfurt makes sense as a future addition, but not prioritised right now.

DoH/3 - this is in our backlog, but has not been prioritised, how soon it’s added will depend on number of requests.

DNSSEC - it’s supported, but we encountered a bug in sdns that causes insecure assessment, it is being resolved → [Fix: DNSSEC - extract isZoneSecure and restore probeName stripping by MaciejTe · Pull Request #450 · semihalev/sdns · GitHub](https://github.com/semihalev/sdns/pull/450)

---

## Post 69 by @Catalyst2422 — 2026-04-26T20:22:28Z

> [@viktorivpn](#):
>
> PoPs

Some more would be appreciated please

---

## Post 70 by @Bhaelros — 2026-05-05T22:30:03Z

I think for the first time I would be thankful that there is less security feature available. DENIC messed up complete .de domain and DNS queries only work without DNSSEC now. Half of the Germany’s web sites are not working at the moment, thanks to DENIC.

> **[Reddit - Please wait for verification](https://www.reddit.com/r/de/comments/1t4rqki/de_domains_down_its_not_you_its_denic/)**

> **[DENIC Status](https://status.denic.de/)**
>
> Current system status. View active incidents or upcoming maintenance. Subscribe to receive status notifications.

---

## Post 71 by @Blackbird — 2026-05-07T10:19:38Z

Something just went wrong @viktorivpn - the VPN kicked me out of multi-hop claiming I don’t have a Pro subscription. The client itself still shows 1.5 years of subscription left. I’ve logged out and restarted my computer several times.

---

## Post 72 by @Bhaelros — 2026-05-07T11:00:25Z

> **[Reddit - Please wait for verification](https://www.reddit.com/r/IVPN/comments/1t65pvi/comment/okf8qoz/)**

> Multi-hop is still available and included in the Pro plan.
> 
> We are in the middle of rolling out major upgrades for IVPN accounts, including new services available for Pro plans. During this rollout process we made an error which disabled Multi-hop in IVPN apps. We are working on the fix, it will be resolved today. Apologies.

---

## Post 73 by @asd99898h4 — 2026-05-07T19:27:03Z

since this seems to be standalone dns, you might want to look into also providing dnscrypt-proxy resolvers & anonymous relays as well. not resource nor bandwidth intensive whatsoever. arguably better than DoH since there are a few fundamental flaws there.

---

## Post 74 by @viktorivpn — 2026-05-07T20:46:11Z

thanks, this is in our backlog and will look into it

---

## Post 75 by @polyester_apricot650 — 2026-05-25T03:06:02Z

Does modDNS support DoH and DoQ?

Is it possible to use modDNS at the router level? Any plans to work with router makers to add modDNS support?

---

## Post 76 by @Bhaelros — 2026-06-12T19:16:58Z

It supports DoH, DoT and DoQ. No support for DoH3 as of now.

Router setup is like below.

 ![image](https://forum-uploads.privacyguidesusercontent.com/original/3X/5/e/5ef1209e55b73f7cf84239c3f8497d9f79a31547.png)

---

## Post 77 by @polyester_apricot650 — 2026-06-16T02:22:30Z

What’s the difference between DoH and DoH3?

---

## Post 78 by @Bhaelros — 2026-06-17T07:22:50Z

DoH3 is using QUIC protocol in the backend, faster, more resistant to packet loss and supports multiple streams.

> **[What is DNS over TLS (DoT), DNS over Quic (DoQ) and DNS over HTTPS (DoH & DoH3)?](https://help.nextdns.io/t/x2hmvas/what-is-dns-over-tls-dot-dns-over-quic-doq-and-dns-over-https-doh-doh3)**
>
> DNS is an old protocol lacking all forms of security. Yet, it is one of the most fundamental protocols of the Internet. DoT and DoH are improvements to add transport security to the DNS protocol by…

> **[Quad9 | A public and free DNS service for a better security and privacy](https://quad9.net/news/blog/quad9-enables-dns-over-http-3-and-dns-over-quic/)**
>
> A public and free DNS service for a better security and privacy

---

## Post 79 by @polyester_apricot650 — 2026-06-17T08:07:19Z

And how does DoH3 differ from DoQ?

---

## Post 80 by @Bhaelros — 2026-06-17T08:17:15Z

Major difference is DoQ uses UDP 853 and DoH3 uses TCP 443, using HTTP headers. It is less prone to blocking while maintaining speed and latency benefits for QUIC protocol.

> **[DoH3, DoQ und DoT: Was sich Ende 2025 ändert](https://www.captaindns.com/de/blog/doh3-doq-dot-2025-latest)**
>
> Detaillierte Analyse von DoH3, DoQ und DoT Ende 2025: Verbreitungsstand, Auswirkungen auf DNS-Architekturen, Performance, Sicherheit, Empfehlungen.

> **[Reddit - Please wait for verification](https://www.reddit.com/r/Adguard/comments/y269w4/doq_vs_doh3_advantages_and_disadvantages)**

---

## Post 81 by @Linus_Sex_Tips — 2026-06-17T15:38:58Z

Another benefit of DoH3 vs DoQ is that if you’re using a custom resolver (as is the case with moddns, control d, nextdns, etc. custom profiles), your identifier is visible to network observers in the case of DoQ/DoT since it’s passed as a subdomain (like [abc123.dns.controld.com](http://abc123.dns.controld.com)). On the other hand, DoH/DoH3 passes it as a URL path segment which is encrypted (like [https://dns.controld.com/abc123](https://dns.controld.com/abc123)) and an observer would only see you connecting to [dns.controld.com](http://dns.controld.com)

---

## Post 82 by @polyester_apricot650 — 2026-06-19T12:02:13Z

Are there any plans to add servers in Vancouver, Seattle, San Francisco, and Los Angeles?

I’m praying and crossing my fingers that this will happen, but site redirection like Control D? I would love for modDNS to do this and be a viable Control D competitor.

---

## Post 83 by @kim — 2026-06-29T12:54:27Z

Dear @viktorivpn ,

Do we have any planning for seperate subscription for Mailx only and modDNS only?

---

## Post 84 by @viktorivpn — 2026-06-29T13:26:00Z

LA and an east-coast US end-point is in progress and should be added soon. Seattle/Vancouver is on the list for a second round of expansion (no ETA). Will pass on your request about site redirection, it won’t be prioritised in the near future but we will evaluate it.

---

## Post 85 by @viktorivpn — 2026-06-29T13:28:14Z

yes it is planned, but we have a long list of additions (+ infra/routing improvements for modDNS) before we take that step, so I cannot give you timeframes on this.

---

## Post 86 by @polyester_apricot650 — 2026-06-30T03:33:56Z

Control D needs some serious competition, and they’re less than ideal because they’re Canadian. I hope some redirection will be added because that’s what NextDNS is missing!

Is there a daemon or some software that will be developed for a router where all connected devices will be automatically shown on my account, where I can see the statistics?

---

## Post 87 by @Linus_Sex_Tips — 2026-06-30T14:23:36Z

What is the refresh interval for the filter lists? I.e., how often are the sources checked for updates?

---

## Post 88 by @viktorivpn — 2026-06-30T15:10:20Z

Mostly hourly, some daily, depends on list/source.
