DNS
The resolver sees every domain a device asks for. Listings differ on logging, accounts, and jurisdiction.
2 zero KYC · 1 light KYC
Privacy, evidence, and risk are separate. See the published method.
Change ranking
Choose how to order services. Scores do not change.
How to choose
A DNS resolver answers every domain lookup a device makes, which makes it a complete record of where the device goes. Switching away from the internet provider’s resolver moves that visibility; it does not remove it. The listings differ on exactly the points that matter: whether queries are logged and for how long, whether an account or configuration profile ties queries together, and which jurisdiction the operator answers to.
Encrypted transports such as DoH and DoT keep queries unreadable in transit, and the listed resolvers support them. The connection that follows a lookup still reveals destination addresses to the network, so resolver choice is one layer rather than a complete shield. Filtering of ads, trackers, or malware is a separate property recorded per service.
- The logging policy: aggregate counters, per-query logs, or none, and the retention period.
- Whether use requires an account or profile that groups queries together.
- Jurisdiction and the operator’s structure.
- Transport support and filtering options.
Frequently Asked Questions
What can a DNS resolver see?
Every domain the device asks about, with the requesting address and timing. That is enough to reconstruct browsing patterns, which is why the logging policy is the central field on each record.
Does encrypted DNS hide browsing from the internet provider?
It hides the queries. The connections that follow still expose destination IP addresses, and often server names during the handshake, so the provider retains a partial view.
Is a filtering resolver a privacy tool?
Filtering blocks known tracker and malware domains at lookup time, and it concentrates trust in the resolver doing the filtering. The logging policy and account model decide how that trade lands.