Router DNS

Hi all,

I’m using my old Fritz box 3390 as router, but I would like to ask you some advices for the best setup.
With my personal phone and notebook I use Mullvad vpn, so I’m covered, but with my professional notebook and smart tv not. Thus, I would like to understand the best way to put a security layer. I was thinking about DNS, but I’m stuck in which one to pick up, considering that my router support only plain dns (ipv4), and I would not link every time my device to see analytics etc.

I also tried public dns (those suggested here), but they don’t work very well for me.

Now I’m considering to flash my Fritzbox os, installing openwrt (I don’t want unstable os because I use internet every day to work), or if there are other solutions to install cloud dns (now I’m not considering to buy raspberry etc at the moment) that not imply to link every time my devices, but once installed it’s done.

Thank you very much in advance.

You could use dns0.eu within the EU or Quad9 if outside the EU.

https://techblog.nexxwave.eu/public-dns-malware-filters-tested-in-2024/

Thank you.
2 questions:

  • I set up dns0.eu, but checking with dns leak test I return, beside dns0.eu, also google user content from USA. Why that? Its happen only with this provider
  • DNS0 cover only maliocious domains or also tracking one? Because checking by their site it seems that they work only with the first type

Yes, you’re right. It does that and only that, though if you use their KIDS version, you can block ads but not trackers.

If you need ad and tracker blocking capabilities, NextDNS is a good option as you can customize everything (btw, dns0.eu is made by the same creators of NextDNS)

restart the rooter and check again, are you in EU?

easy to test, try to ping top ad and tracking domains like

doubleclick.net

Maybe I’m misunderstanding your post, but is it true/possible that people outside the EU cannot access dns0.eu?

I have no idea, that’s why i asked the OP if they are from the EU.
The service has servers only in EU though, so it would be impractical to use because of the high response times outside of it.

You ask for something rather impossible imho. If you want added security either upgrade to a router that supports doh or get a dns server on an rpi.

And then just pick any dns provider from the website that fits your needs.