Skip to content

Block answers and EDE codes

A blocked query gets the answer your profile’s block mode sets (NXDOMAIN by default), with a TTL of 300 seconds for synthesised records, plus an Extended DNS Error (RFC 8914) saying why.

EDE code Meaning When
17 Filtered your profile blocked it denylist, security list, parental control, blocklist, rebinding
15 Blocked opdns blocked it at operator level a legal order or abuse block, in every profile and on the public path
18 Prohibited refused a profile id that does not exist, a malformed DoT/DoQ server name, or a source blocked for abuse
22 No Reachable Authority upstream timed out the authoritative servers did not answer
23 Network Error upstream transport error

The EDE’s extra text names the list or rule: the list’s name for a list, denylist: <pattern> for your own rule, rebinding: <address> for the rebinding check.

;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN
; EDE: 17 (Filtered): (denylist: *.ads.example)

Tools that show EDE: dig (BIND 9.18 and later), kdig, and the dashboard’s log details. Browsers and most apps ignore it; they see the block mode’s answer.

Operator-level blocks are rare and are published in aggregate in the transparency report. They are answered with 15, never 17, so you can always tell them from your own filtering, and always NXDOMAIN, whatever your block mode. The extra text is a reason code, legal_order, abuse or csam, followed for the first two by a public reference such as legal_order LEGAL-2026-014; it never contains the blocked pattern. Some apply only in the country a court order covers. See the operator blocks and takedowns policy.