Skip to content

The public resolver path

opdns’s anycast addresses also answer queries that name no profile, like any public resolver (ADR 0018). This keeps “just point at the address” working while you set up a profile, and it is the answer for plain IPv4 queries from a network you have not linked.

  • Resolves unfiltered. No profile, so no lists and no rules. Operator blocks still apply.
  • Keeps no per-query record. Nothing is written, streamed or stored about individual queries.
  • Counts. Aggregate counters per PoP by transport and outcome, with no addresses and no names.
  • Rate-limits in memory. A token bucket per source (IPv4 /32, IPv6 /64) held in memory only, forgotten when idle.

Plain DNS to the IPv4 addresses from an unlinked source, plain DNS to the IPv6 service address, DoH to https://dns.opdns.net/ or /dns-query, and DoT or DoQ to dns.opdns.net itself (or with no server name).

A query that asks for a profile and gets it wrong is refused, never sent here: a well-formed id that does not exist, a DoT or DoQ name under dns.opdns.net that is not a well-formed id, or a server name outside it. See Identification.

Current defaults, which may change without notice (terms, section 4):

Traffic Queries per second per source Burst
Plain DNS, no profile 50 2×
Encrypted transports, no profile 200 2×
Identified profiles 500 2×

Over the limit, UDP queries are dropped and every second one is answered with a truncated response so a real client retries over TCP.

UDP answers are also kept small so the addresses cannot be used to amplify an attack on someone else: an answer to a query that names no profile is at most twice the size of the question (four times for an identified query), never over 1,232 bytes, and a larger one comes back truncated so the client asks again over TCP. ANY over UDP gets the short RFC 8482 answer. Responses are also rate-limited per client network (IPv4 /24, IPv6 /48). A client that uses DNS cookies (RFC 7873) and echoes the server’s cookie is exempt from the size and response limits, since the cookie proves its address. None of this applies to TCP, DoT, DoH or DoQ.

Sources that abuse the service can be blocked on every PoP at once: their plain DNS and DoT queries are refused with EDE 18 and their DoH, DoH3 and DoQ connections closed, whether or not they name a profile.

The public path has no account, no support and no filtering, and may be changed or withdrawn.