Filtering DNS that can keep your logs at home.

opdns is a filtering DNS resolver, like NextDNS or ControlD, with one difference: a node you can run at home. It is the same resolver on your own hardware, and the place your query logs can live instead of our cloud.

Join the beta waitlist Read the docs

opdns@edge:~$ in development; public beta planned for 2027

Filtering. Your logs. Your node.

Filtering

Ads, trackers and malware are blocked before anything loads. A blocked name gets a block answer instead of an address.

Blocks:

  • ads and trackers, from public blocklists you pick
  • malware and newly registered domains
  • parental controls: categories and services from free lists; schedules come later
  • your own deny, allow and rewrite rules

Set up with:

  • DNS-over-HTTPS, DNS-over-TLS or DNS-over-QUIC, with a device name in the address
  • a per-profile IPv6 address for plain DNS
  • a linked IPv4 address, kept current by a DDNS updater
  • a generated configuration profile for Apple devices
DoH
https://dns.opdns.net/profile-id/device
DoT, DoQ
device-profile-id.dns.opdns.net

Your endpoints Setup guides

Logs you control

Each profile says where its query logs go, and whether there are any.

Where logs go:

Cloud
Stored by opdns until your retention runs out, 1 to 90 days.
Your node
Sent down to your node, not stored in the cloud. Held until the node acknowledges them, 7 days at most.
Both
A copy in each place.
None
Discarded when they reach our control plane.
Logs off
No record leaves the PoP. The profile gets hourly counters only.

Also per profile:

  • client IP logging off, applied on the PoP
  • domain logging off, applied on the PoP
  • retention from 1 to 90 days

Queries with no profile:

  • answered unfiltered, like a public resolver
  • no per-query record; counters without addresses or names
  • rate limits held in memory only

A query sent to opdns is still seen by the PoP that answers it, and a record bound for your node crosses our log stream on the way.

Where each setting applies The public path

A node at home

opdns-node runs the fleet's resolver code, the edge's listeners and policy engine with its own Unbound, in one container or a static binary. A Raspberry Pi, a home server or a NAS will do.

What it does:

  • keeps filtering with the last profile and lists it received when the internet or opdns is down
  • logs the queries your devices send it in its own SQLite file; they never reach us
  • shows up in the same dashboard, which reads its logs over the node's outbound link

What we see from it:

  • its id, versions, uptime, last sync, log file size and public IP address
  • dashboard results in transit, relayed through our servers with TLS on each hop, and not stored

The beta ships the enrolled mode, managed from the dashboard. A standalone mode, with no account and a config file, exists and grows after the beta.

Self-hosted node Logs on your node

One dashboard for the cloud and the node.

The dashboard is being restyled to match this site. Screenshots follow once it is; until then these frames say what each page shows.

Three paths a query can take.

Your devices reach the nearest opdns PoP by anycast. What happens to the log record depends on the profile, and a device at home can skip the cloud entirely.

Three paths: cloud logs, logs sent to your node, and queries answered at homeYour devices reach the nearest opdns PoP by anycast. The PoP filters the query and resolves allowed names with its own Unbound. Logs off and client IP off apply on the PoP. The log record then goes either to the cloud log store, for the cloud or both destinations, or to a queue for your node, kept until the node acknowledges it and at most 7 days, which is delivered over the node's outbound link. The dashboard reads cloud logs from the store, and node logs from the node through the link, relayed and not stored. Devices at home that query your node directly are answered and logged by the node and never touch the cloud.opdns control planeYour networkYour devicesphone, laptop, routerAnycast PoPopdns-edge + Unboundfilters, then resolveslogs off: no record leavesclient IP off: removed hereCloud log storedestination cloud or bothQueue for your nodeuntil acked, 7 days at mostDashboardapp.opdns.ioDevices at homepointed at the nodeopdns-noderesolver + SQLite logslink, opened by the nodereads relayed,not storednever touches the cloud
query to opdnslog recorddashboard readquery at home
Cloud logs
The PoP filters and answers. The record is stored in the cloud for the cloud and both destinations.
Logs to your node
The same answer. The record is queued and delivered over the link your node opened.
At home
Devices pointed at your node are answered and logged there. Those queries never touch the cloud.

Architecture and the log model

Against NextDNS and ControlD.

What opdns adds:

FeatureopdnsNextDNSControlD
Self-hosted node, same resolverYesNoNo
Query logs on your own hardwareYesNoNo
Resolver and control-plane source publishedYesNoNo
DNS-over-QUICYesNoYes

Where opdns is behind:

  • no apps or CLI forwarder until after the beta; setup uses the operating system's own settings
  • thinner parental controls, and no schedules yet
  • no choice of cloud log region yet; keeping logs on your node is the answer for now
  • no per-device names on plain IPv4 DNS, by design; use encrypted DNS

The full feature tableCompetitor entries are checked against their public documentation before launch.

Source available. Free for personal use.

The whole repository, resolver, control plane, dashboard and node, is published under the Source First License 1.1 at the beta. Read it, build it, change it, and run the node at home for free.

Needs a commercial licence:

  • a business, school or other organisation self-hosting the node
  • an IT contractor deploying it for clients
  • offering opdns or a fork as a service

Source-available, not open source, and it does not convert to an open-source licence later.

What the licence allows

Beta in 2027.

opdns is in development and nothing is live yet. The public beta is planned for around March 2027.

In the beta:

  • the resolver on every transport, over an anycast network
  • the dashboard and the API
  • logs and analytics with the per-profile settings above
  • linked IPs with a DDNS updater
  • the enrolled self-hosted node

Signups for the beta open later.

Until then, the repository on GitHub is where releases will be announced. It becomes public at the beta.

When signups open, the address you give will be used only to email you about the beta. This page loads nothing from other sites and sets no cookies.