Block answers and EDE codes
A blocked query gets the answer your profile’s block mode sets (NXDOMAIN by default), with a TTL of 300 seconds for synthesised records, plus an Extended DNS Error (RFC 8914) saying why.
| EDE code | Meaning | When |
|---|---|---|
| 17 Filtered | your profile blocked it | denylist, security list, parental control, blocklist, rebinding |
| 15 Blocked | opdns blocked it at operator level | a legal order or abuse block, in every profile and on the public path |
| 18 Prohibited | refused | a profile id that does not exist, a malformed DoT/DoQ server name, or a source blocked for abuse |
| 22 No Reachable Authority | upstream timed out | the authoritative servers did not answer |
| 23 Network Error | upstream transport error |
The EDE’s extra text names the list or rule: the list’s name for a list,
denylist: <pattern> for your own rule, rebinding: <address> for the
rebinding check.
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN; EDE: 17 (Filtered): (denylist: *.ads.example)Tools that show EDE: dig (BIND 9.18 and later), kdig, and the
dashboard’s log details. Browsers and most apps ignore it; they see the
block mode’s answer.
Operator blocks
Section titled “Operator blocks”Operator-level blocks are rare and are published in aggregate in the
transparency report. They are answered with 15, never 17, so you can
always tell them from your own filtering, and always NXDOMAIN, whatever
your block mode. The extra text is a reason code, legal_order, abuse
or csam, followed for the first two by a public reference such as
legal_order LEGAL-2026-014; it never contains the blocked pattern. Some
apply only in the country a court order covers. See the
operator blocks and takedowns policy.