4 posts tagged dns, newest first.

A no-log policy is only meaningful when the exceptions are named. What this service records, what it does not, how each part is tested — and the four things a tunnel cannot protect you from.
The three VPN tiers differ in exactly one thing — who resolves your DNS, and what that resolver can see. What each tier actually changes, and what it costs you.
Signing a zone your own resolvers answer converts a soft failure into a hard one: a validating resolver returns SERVFAIL, and the name dies everywhere at once.
A filtering resolver has no test mode: your test query is answered by real policy, and often by an exemption that hides the policy from you.
󰣨 ymrtech@ymrtech | 󰌠 NixOS | 󰍢 UTF-8