# What lists do Proton VPN's Netshield use?

**URL:** https://discuss.privacyguides.net/t/what-lists-do-proton-vpns-netshield-use/18754
**Category:** Questions
**Tags:** software
**Created:** 2024-06-06T16:55:20Z
**Posts:** 25

## Post 1 by @Zenaida.macroura — 2024-06-06T16:55:20Z

It’s pretty easy to find what IVPN and Mullvad use, but I can’t find what Proton uses.

---

## Post 2 by @anon48875053 — 2024-06-06T17:02:12Z

Nobody knows because Proton doesn’t tell anyone.

---

## Post 3 by @anon63378630 — 2024-06-06T22:10:51Z

I don’t know if I posted it here, but please don’t rely solely on these lists.

Quoting myself:

- Google Safe Browsing goals are blocking threats that are gone within 10 minutes
- Quad9 claims “up-to-the-minute list of threats”
- DNS0 claims “detection-to-protection window to just a few seconds”
- ControlD claims “are rebuilt and deployed every 30 minutes or less”
- Mullvad updates once a week with a tiny list: [History for output - mullvad/dns-blocklists · GitHub](https://github.com/mullvad/dns-blocklists/commits/main/output)

Please use Quad9 or DNS0, layer a browser with uBlock Origin, and Safe Browsing too.

---

## Post 4 by @FlipSid — 2024-06-07T00:06:02Z

Which is one of the reasons I switched to iVPN

---

## Post 5 by @Zenaida.macroura — 2024-06-07T01:05:24Z

Isn’t it not recommended to use a custom DNS with a VPN?

---

## Post 6 by @Zenaida.macroura — 2024-06-07T01:07:35Z

Is it known why they don’t tell anyone? :thinking:

---

## Post 7 by @TigerBanded — 2024-06-07T01:47:51Z

Same

Also Proton VPNs mac app is horrible

Constantly disconnects and dosent have a permanent kill switch

---

## Post 8 by @TigerBanded — 2024-06-07T01:49:20Z

Yes because you are trusting your data with two parties instead of one.

But its a pretty low hit to your privacy as long as you trust your DNS provider.

---

## Post 9 by @Showplace8087 — 2024-06-07T03:43:40Z

Not knowing what lists they use and what is or isn’t being blocked with Protons Netshield is why I use NextDNS along side the VPN. Not a big risk IMO seeing as NextDNS is rather trustworthy.

---

## Post 10 by @stjose — 2024-06-07T05:08:17Z

yeah that’s why I use the WireGuard native app for all my device’s.

---

## Post 11 by @Broken — 2024-06-07T05:52:47Z

I was always under the impression the advice is to always use the native dns blocking with your vpn provider to preserve privacy

---

## Post 12 by @Pragmatic — 2024-06-07T07:07:05Z

Yes, that’s normally the rule. I’ve understood that you shouldn’t use a DNS tier with a VPN because DNS can cause conflicts and lose efficiency.

---

## Post 13 by @wojciechxtx — 2024-06-07T11:38:50Z

> [@TigerBanded](#):
>
> Also Proton VPNs mac app is horrible

Would not say so…

> [@TigerBanded](#):
>
> Constantly disconnects

Have been using it for last 5 month all-the-time, not even once have I been disconnected. So you dont know what you say.  
As of `KillSwitch`, its setting is saved in `UserPrefs.clist` file, so its permanent.

---

## Post 14 by @TigerBanded — 2024-06-07T12:54:03Z

By permanent, I mean it blocks all network traffic even if the VPN isn’t running. Currently, Proton only has the option available on Windows and Android. They have no ETA on it being introduced on Mac’s.

> **[Reddit - The heart of the internet](https://www.reddit.com/r/ProtonVPN/comments/15gxlqc/any_eta_on_when_the_permanent_kill_switch_will/)**

Strange because Mullvad and IVPN both have the option on Mac.

---

## Post 15 by @Showplace8087 — 2024-06-08T03:00:30Z

[That’s what Graphene recommends.](https://grapheneos.org/faq#custom-dns)

TL:DR - “If you’re using a VPN, you should consider using the standard DNS service provided by the VPN service to avoid standing out from other users.”

---

## Post 16 by @Broken — 2024-06-08T11:23:03Z

Yeah thats the advice i saw

---

## Post 17 by @RandomGuyy — 2024-06-16T18:26:40Z

I’m just curious about this: Proton is highly recommended for multiple reasons, including being open source. However we can not see which lists are using for blocking.. That doesn’t feel very transparant? I’m not knowledgeable about this subject but theoretically they could do something harmful right?

---

## Post 18 by @TigerBanded — 2024-06-16T19:03:36Z

Ya, I find it incredibly odd they don’t open source their netshield blocking list. I’ve used it in the past and it seems like a very relaxed list. But I’ve also had sites break in the past when using it and I don’t know if it’s from netshield, my adblocker or something else. If they just revealed their list it would be very easy to look up a possible domain that might be blocked and report it to them as a false positive.

I’ve switched to IVPN since then and they allow you to select from many different community maintained, open source list like Hagezi and 1Hosts with varying degrees of blocking. Much better than Protons approach.

> **[Better tracker blocking controls with AntiTracker Plus](https://www.ivpn.net/blog/better-tracker-blocking-controls-with-antitracker-plus/)**
>
> IVPN AntiTracker is an optional feature of the VPN service that improves privacy protection by blocking requests from unwanted trackers and ads. Before today, AntiTracker operated with one blocklist option - OISD Big.
> With AntiTracker Plus we...

---

## Post 19 by @Showplace8087 — 2024-06-17T03:44:18Z

According to Proton (a year ago) they plan on letting users use custom block lists and a couple comments under that they said they’ll consider making their list public. When we all this happen? Not any time soon I’m guessing.  
[https://www.reddit.com/r/ProtonVPN/comments/149nu60/comment/jo7xhp6/](https://www.reddit.com/r/ProtonVPN/comments/149nu60/comment/jo7xhp6/)

---

## Post 20 by @RandomGuyyy — 2024-06-18T19:10:40Z

@dngray Sorry to tag you in this, but since I saw you worked on the VPN page: do you have any thoughts on this? It’s a bit weird that they are completely open source, but have a hard time sharing these lists (which leave a lot to be improved apparently)?

---

## Post 21 by @anon48875053 — 2024-06-19T06:49:07Z

1. On the VPN Services page, there is no criteria that is even remotely related to these lists or DNS filtering.

2. Most people here probably use a browser that has built-in content filtering, which combined with NetShield is probably sufficient.

3. These lists and DNS filtering still rely on [badness enumeration](https://privsec.dev/posts/knowledge/badness-enumeration/).

---

## Post 22 by @ph00lt0 — 2024-06-21T10:34:15Z

> [@Showplace8087](#):
>
> they plan on letting users use custom block lists

For business suite users they do allow using a custom DNS server for quite a while already: [Proton for Business plans and pricing | Proton for Business](https://proton.me/business/plans) (search for custom dns)

---

## Post 24 by @TigerBanded — 2026-03-11T14:42:40Z

I just noticed this on the NetShield help page: [How to use NetShield Ad-blocker | Proton VPN](https://protonvpn.com/support/netshield)

 ![IMG_0982](https://forum-uploads.privacyguidesusercontent.com/original/3X/c/f/cf46c479cd0ebc0c7e524921c4beaf18cf698ff3.jpeg)

---

## Post 25 by @Footnote5444 — 2026-03-11T23:54:27Z

Glad they finally made the lists they use public. Still beyond annoying they refuse to support custom DoH or DoT server options.
