The public resolver path
opdns’s anycast addresses also answer queries that name no profile, like any public resolver (ADR 0018). This keeps “just point at the address” working while you set up a profile, and it is the answer for plain IPv4 queries from a network you have not linked.
What it does
Section titled “What it does”- Resolves unfiltered. No profile, so no lists and no rules. Operator blocks still apply.
- Keeps no per-query record. Nothing is written, streamed or stored about individual queries.
- Counts. Aggregate counters per PoP by transport and outcome, with no addresses and no names.
- Rate-limits in memory. A token bucket per source (IPv4 /32, IPv6 /64) held in memory only, forgotten when idle.
Which queries take it
Section titled “Which queries take it”Plain DNS to the IPv4 addresses from an unlinked source, plain DNS to the
IPv6 service address, DoH to https://dns.opdns.net/ or /dns-query, and
DoT or DoQ to dns.opdns.net itself (or with no server name).
A query that asks for a profile and gets it wrong is refused, never sent
here: a well-formed id that does not exist, a DoT or DoQ name under
dns.opdns.net that is not a well-formed id, or a server name outside it.
See Identification.
Limits
Section titled “Limits”Current defaults, which may change without notice (terms, section 4):
| Traffic | Queries per second per source | Burst |
|---|---|---|
| Plain DNS, no profile | 50 | 2× |
| Encrypted transports, no profile | 200 | 2× |
| Identified profiles | 500 | 2× |
Over the limit, UDP queries are dropped and every second one is answered with a truncated response so a real client retries over TCP.
UDP answers are also kept small so the addresses cannot be used to
amplify an attack on someone else: an answer to a query that names no
profile is at most twice the size of the question (four times for an
identified query), never over 1,232 bytes, and a larger one comes back
truncated so the client asks again over TCP. ANY over UDP gets the short
RFC 8482 answer. Responses are also rate-limited per client network (IPv4
/24, IPv6 /48). A client that uses DNS cookies (RFC 7873) and echoes the
server’s cookie is exempt from the size and response limits, since the
cookie proves its address. None of this applies to TCP, DoT, DoH or DoQ.
Sources that abuse the service can be blocked on every PoP at once: their plain DNS and DoT queries are refused with EDE 18 and their DoH, DoH3 and DoQ connections closed, whether or not they name a profile.
The public path has no account, no support and no filtering, and may be changed or withdrawn.