What is the most painless yet still private DNS solution?

I used Google’s DNS before switching to Cloudflare, but as I’ve become more privacy conscious I decided I wanted to be as secure and private as I can, so long as it doesnt cause me inconveniences. One of the things I cant understand is what DNS I should use or how to encrypt it.

I’ve heard of OpenNIC, but also of dnscrypt-proxy, Njalla and my VPN’s DNS too and after that I got lost. I just want something that will not track me at all, has great performance and I dont have to think about once its setup. I dont want ISPs to spy on me, since my government (bit of a regime, but im not being persecuted) may want to do some snooping into my hentai search history

I dislike using DoH or DoTLS, because it will ignore my localhosts file, which I used as a blocklists. (cmiiw)

So I use Quad9 dnscrypt proxy instead. (Dnscrypt unfortunately, is not painless to set up).

Cloudflare doesn’t log and they encrypt (HTTPS or TLS).

As for your ISP, worrying about DNS is kind of irrelevant as they can see all your packets. If you’re concerned about them then you have to use a VPN/TOR.

Any Good VPN

Take old laptop, install VPN on it, then install Privoxy and open a port to it (usually 8118). Now run this unit 24/7 to maintain your “pipe” out of your ISP.

Setup all of the browsers in your household to point to your VPN gateway. They’l lget their DNS from it.

Just a quick negative word on ‘Open DNS’. That company began unilaterally censoring the web a few years ago (i.e. porn, media copyright stuff, perhaps even “undesirable political content” by now?).

do you use quad9 dns with dns crypt if so how did you set it up?

Yeah but i already knew the vpn part so i didnt mention it

I wanted to stick with cloudflare for the speed but people seem to have split opinions about it in here

o3o332814979506p93rnorqpq263nnn3339278r8r43s80qn45nq2627p5op2rq9nnq03r7175q6478oo7718o9p62nrsr45356q2p88o326297rr8rr23067p4o2nno

Cloudflare doesn’t log and they encrypt (HTTPS or TLS).

There is essentially no chance Cloudflare hasnt received an NSL at this point given the amount of traffic they “control”. We should assume Cloudflare absolutely logs.

Just configure it with its toml file, use *quad9-dnscrypt-ip4-filter-pri *

Well, you mentioned concerns about your ISP. If you are doing VPN right then your DNS should go through your tunnel.

Thanks for the clarification. I think I knew that, just brain slipped.

CloudFlare means well but at the end of the day, they are a US based company. So at anytime they could turn into a spying company against their will due to NSL’s & Gag Orders. (National Security Letters).

So it’s highly advised to not use US based providers and services. Instead try a European based provider that has no key disclosure laws

Can you explain why you dislike Google’s DNS?

Exactly. I usually visit whoer.net to verify my dns requests are routed through my vpn.

What do you think Google does with the data they collect from people using their DNS?

Google is an advertising & data intelligence company…

Right. Sorry I thought there was something more sinister that you meant.

Good point.