Why are some DNS resolvers not mentioned? can the article be improved?

looking at the page about dns resolvers DNS Resolvers - Privacy Guides I find the recommandations it gives confusing:

  • It is not obvious why the list of recommanded providers is sorted the way it is
  • “Encrypted DNS will not help you hide any of your browsing activity.” whut? why would you say that? missing clarification.
  • no mention of setting your home router to an encrypted private filtering dns would also help you controll all devices in your home network (assuming they have the router set as dns server)
  • next dns and rethink dns are not in the listwt the top
  • dns4eu is not mentioned at all
  • list the dns services which failed one or more criteria wnd mention why they failed

so what are the differences between dns4.eu, adguard, nextdns and rethinkdns?

The domain is still visible to eg. your ISP or LAN because it is sent in plaintext during the TLS handshake. Encrypted Client Hello (ECH) solves this but is not widely adopted by websites/services. I have some stats here: https://divested.dev/misc/ech.txt

1 Like

They are different from Mullvad, Cloudflare, etc because:

For NextDNS:

>These DNS filtering solutions offer a web dashboard where you can customize the block lists to your exact needs, similarly to a Pi-hole.

For RethinkDNS:

>Encrypted DNS proxy software provides a local proxy for the unencrypted DNS resolver to forward to.

This is not something Privacy Guides usually does.

yup am aware that ech is needed for privacy, but than encrypted dns does help hide your visits to the few domains which already support ech right? (for those who do not wish to use a vpn because those aint free) so choosing encrypted dns querries adds some privacy, and sets you up for the future.

as to privacy guides not listing things which aren’t recommanded, that’s a shame as there is something to be learned by understanding ‘why not’. and it leaves people wondering if the article might just be an incomplete consideration.

VPNs and DNS have different use cases. You cannot replace using one with the other.

Cloudflare, they’re basically the only one making ECH available right now.
You can do it manually but it is quite an arduous process, so adoption is basically non-existent.
You could also argue that ECH is only really beneficial for domains that share an IP with others such as what CF offers.

1 Like

But i wouldnt trust Cloudflare tho, we need other privacy friendly providers implementing that