Skip to content

What opdns is

opdns answers DNS for your devices and applies a profile to every query: blocklists, security protections, parental controls, your own deny and allow rules, and rewrites. A blocked name gets a block answer instead of an address, so the ad, tracker or malicious site never loads.

It comes in two parts that share one resolver:

  • The cloud resolver. An anycast network of points of presence (PoPs). Each runs opdns-edge, which identifies your profile and applies its policy, in front of an Unbound recursive resolver on the same machine. Every major transport is supported: plain DNS (UDP and TCP), DNS-over-TLS, DNS-over-HTTPS (HTTP/2 and HTTP/3) and DNS-over-QUIC.
  • The self-hosted node. The same edge and Unbound in one container or binary on your hardware. It can be enrolled (managed from the dashboard, over one outbound connection) or standalone (a config file, no account). See Self-hosted node.

A profile is a policy with a 6-character id, for example abc123. You can have several (one for the family, one for the children’s tablets). The device name is a label you choose per device, carried in the encrypted DNS address, so logs and analytics can tell your phone from the living-room TV. Devices are not registered anywhere: using a new name is enough.

The 2027 beta covers the resolver on all transports, the dashboard and API, blocklists and security lists from free sources, deny and allow lists and rewrites, logs and analytics with per-profile privacy settings, linked IPs with a DDNS updater, and the enrolled self-hosted node. The comparison page lists what comes later and what opdns has declined to build.

  • It does not identify individual devices on plain IPv4 DNS. Use encrypted DNS for per-device names. See Identification.
  • It does not intercept HTTPS, so a blocked site shows a browser error, not a block page. A block page is a Phase 5 decision.
  • It is not a VPN. It sees DNS questions, not your traffic.

Next: create an account and a profile.