1
0
mirror of https://github.com/privacyguides/i18n.git synced 2026-05-25 03:21:25 +00:00
Files
i18n/i18n/zh/dns.md
T
2026-05-14 22:46:54 +00:00

14 KiB
Raw Blame History

title, icon, description, cover, global
title icon description cover global
DNS解析器 material/dns We recommend choosing these encrypted DNS providers to replace your ISP's default configuration. dns.webp
randomize-element
table tbody

Protects against the following threat(s):

Encrypted DNS with third-party servers should only be used to get around basic DNS blocking when you can be sure there won't be any consequences. 加密的DNS不会帮助你隐藏任何浏览活动。

Learn more about DNS :material-arrow-right-drop-circle:{.md-button}

推荐的供应商

These are our favorite public DNS resolvers based on their privacy and security characteristics, and their worldwide performance. Some of these services offer basic DNS-level blocking of malware or trackers depending on the server you choose, but if you want to be able to see and customize what is blocked, you should use a dedicated DNS filtering product instead.

DNS供应商 协议 Logging / Privacy Policy ECS 筛选 Signed Apple Profile
AdGuard Public DNS Cleartext
DoH/3
DoT
DoQ
DNSCrypt
Anonymized1 Anonymized Based on server choice. 正在使用的过滤器列表可以在这里找到。 :octicons-link-external-24: Yes :octicons-link-external-24:
Cloudflare Cleartext
DoH/3
DoT
Anonymized[^2] No Based on server choice. No :octicons-link-external-24:
Control D Free DNS Cleartext
DoH/3
DoT
DoQ
No[^3] No Based on server choice. Yes
:simple-apple: iOS
:material-apple-finder: macOS
Mullvad DoH
DoT
No[^4] No Based on server choice. 正在使用的过滤器列表可以在这里找到。 :octicons-link-external-24: Yes :octicons-link-external-24:
Quad9 Cleartext
DoH/3
DoT
DoQ
DNSCrypt
Anonymized[^5] 可选 Based on server choice. Malware blocking is included by default. Yes
:simple-apple: iOS
:material-apple-finder: macOS

Cloud-Based DNS Filtering

These DNS filtering solutions offer a web dashboard where you can customize the block lists to your exact needs. These services can be used easily across multiple networks.

Control D

Control D logo{ align=right }

Control D is a customizable DNS service which lets you block security threats, unwanted content, and advertisements on a DNS level.

In addition to their paid plans, they offer a number of preconfigured DNS resolvers you can use for free.

:octicons-home-16: Homepage{ .md-button .md-button--primary } :octicons-eye-16:{ .card-link title="Privacy Policy" } :octicons-info-16:{ .card-link title="Documentation" } :octicons-code-16:{ .card-link title="Source Code" }

Downloads

NextDNS

NextDNS logo{ align=right }

NextDNS is a customizable DNS service which lets you block security threats, unwanted content, and advertisements on a DNS level.

They offer a fully functional free plan for limited use.

:octicons-home-16: Homepage{ .md-button .md-button--primary } :octicons-eye-16:{ .card-link title="Privacy Policy" } :octicons-info-16:{ .card-link title="Documentation" } :octicons-code-16:{ .card-link title="Source Code" }

Downloads

When used with an account, NextDNS will enable insights and logging features by default (as some features require it). You can choose retention time and log storage location for any logs you choose to keep, or disable logs altogether.

NextDNS's free plan is fully functional, but should not be relied upon for security or other critical filtering applications, because after 300,000 DNS queries in a month all filtering, logging, and other account-based functionality are disabled. It can still be used as a regular DNS provider after that point, so your devices will continue to function and make secure queries via DNS-over-HTTPS (DoH), just without your filter lists.

NextDNS also offers a public DoH service at https://dns.nextdns.io and DNS-over-TLS/QUIC (DoT/DoQ) at dns.nextdns.io, which are available by default in Firefox and Chromium, and subject to their default, no-logging privacy policy.

Encrypted DNS Proxies

加密的DNS代理软件为 未加密的DNS 解析器提供一个本地代理转发。 Typically, it is used on platforms that don't natively support encrypted DNS.

RethinkDNS

RethinkDNS logo{ align=right } RethinkDNS logo{ align=right }

RethinkDNS is an open-source Android client that supports DoH, DoT, DNSCrypt and DNS Proxy. It also provides additional functionality such as caching DNS responses, locally logging DNS queries, and using the app as a firewall.

:octicons-home-16: Homepage{ .md-button .md-button--primary } :octicons-eye-16:{ .card-link title="Privacy Policy" } :octicons-info-16:{ .card-link title="Documentation" } :octicons-code-16:{ .card-link title="Source Code" }

Downloads

While RethinkDNS takes up the Android VPN slot, you can still use a VPN or Orbot with the app by adding a WireGuard configuration or manually configuring Orbot as a Proxy server, respectively.

DNSCrypt-Proxy

DNSCrypt-Proxy logo{ align=right }

DNSCrypt-Proxy is a DNS proxy with support for DNSCrypt, DoH, and Anonymized DNS.

:octicons-repo-16: Repository{ .md-button .md-button--primary } :octicons-info-16:{ .card-link title="Documentation" } :octicons-code-16:{ .card-link title="Source Code" } :octicons-heart-16:{ .card-link title="Contribute" }

Downloads

警告

The anonymized DNS feature does not anonymize other network traffic.

Criteria

请注意,我们与我们推荐的任何项目都没有关系。 除了 我们的标准标准,我们还制定了一套明确的要求,使我们能够提供客观的建议。 我们建议你在选择使用一个项目之前熟悉这个清单,并进行自己的研究以确保它是你的正确选择。

All DNS products...

Additionally, all public providers...

  • Must not log any personal data to disk.
    • As noted in the footnotes, some providers collect query information for purposes like security research, but in such cases, the data must not be associated with any PII such as IP address, etc.
  • Should support anycast or geo-steering.

  1. AdGuard存储其DNS服务器的汇总性能指标,即对特定服务器的完整请求数、被阻止的请求数和处理请求的速度。 They also keep and store the database of domains requested within the last 24 hours.

    We need this information to identify and block new trackers and threats. We also log how many times this or that tracker has been blocked. We need this information to remove outdated rules from our filters.

    AdGuard DNS: Privacy Policy [^2]: Cloudflare collects and stores only the limited DNS query data that is sent to the 1.1.1.1 resolver. The 1.1.1.1 resolver service does not log personal data, and the bulk of the limited non-personally identifiable query data is stored only for 25 hours.

    1.1.1.1 Public DNS Resolver: Cloudflares commitment to privacy [^3]: Control D only logs specific account data for Premium resolvers with custom DNS profiles. Free resolvers do not retain any data.

    Control D: Privacy Policy [^4]: Mullvad's DNS service is available to both subscribers and non-subscribers of Mullvad VPN. 他们的隐私政策明确声称他们不会以任何方式记录DNS请求。

    Mullvad: No-logging of user activity policy [^5]: Quad9 collects some data for the purposes of threat monitoring and response. That data may then be remixed and shared for purposes like furthering their security research. Quad9不会收集或记录IP地址或其他他们认为可以识别个人身份的数据。

    Quad9: Data and Privacy Policy ↩︎