Guides: Choosing a tier · DNS blocking · Whitelisting

Guides for the YMRTECH VPN service. For the full dossier — the protocol, the resolvers, the key handling and the audit — see the VPN technical page.

Choosing a tier

Every device you add gets its own tunnel and its own tier, and the tier decides one thing only: who resolves your DNS, and whether anything is filtered. The tunnel itself, the gateway, and the speed are identical on all three — no tier is faster, slower, or upsold by bandwidth (up to 1 Gbit/s per connection on every one of them).

Tier DNS For
pipe None set. Your device keeps the resolver it already runs, outside the tunnel. You already run encrypted DNS you trust, or you resolve internal names.
privacy Ours, inside the tunnel. Your device resolves through 172.16.40.1, which forwards upstream over DNS-over-TLS. Nothing is filtered. Everyday privacy: your provider stops seeing which names you look up.
security Ours, with filter lists. AdGuard Home at 172.16.41.1 answers, on its own resolver instance. Phones, tablets and family devices — blocking that works without a browser extension.

What each one hides

Picking and changing one

Choose the tier in the portal when you add the device, in the same form that gives you the configuration file or QR code. One subscription covers three devices, and each device keeps its own choice — a laptop on privacy, a phone on security, a work machine on pipe.

To move a device to another tier, remove it and add it again under the new tier. Each device gets its own tunnel configuration, so switching means downloading a new configuration or scanning a new QR code rather than editing the existing one. Your other devices are unaffected.

What a tier does not do

The price, the device count and what we store are on the VPN service page; what we log, with retention, is on what we log.

Next: DNS ad and tracker blocking.

󰣨 ymrtech@ymrtech | 󰌠 NixOS | 󰍢 UTF-8