Page 1 of 1

DNS malware and botnet block lists

Posted: Sat Mar 26, 2022 5:15 pm
by atrasatti
Is it possible to know which blocklists Sonic uses for its DNS servers? In https://help.sonic.com/hc/en-us/article ... ence-Guide it says "These servers enforce DNSSEC and include selective filtering of domains believed to be involved in malware distribution and botnet C&C."

New customer here, happily using Quad9 over dns crypt and wondering if I should switch to plain DNS with Sonic for performance without losing on household safety.

Re: DNS malware and botnet block lists

Posted: Sun Mar 27, 2022 5:54 pm
by js9erfan
atrasatti wrote:Is it possible to know which blocklists Sonic uses for its DNS servers? In https://help.sonic.com/hc/en-us/article ... ence-Guide it says "These servers enforce DNSSEC and include selective filtering of domains believed to be involved in malware distribution and botnet C&C."

New customer here, happily using Quad9 over dns crypt and wondering if I should switch to plain DNS with Sonic for performance without losing on household safety.
I have no idea which blocklists Sonic might utilize but you could always use something like Pi-hole with the blocklist(s) you choose and Sonic as the upstream DNS. I mention this since it sounds like you might already have a Rasberry Pi at your disposal.

Re: DNS malware and botnet block lists

Posted: Mon Mar 28, 2022 10:57 am
by kgc
There's only one blocklist that we use and it's very limited in scope to bot-net command and control systems. Pi-hole is a great solution allowing users to control their own DNS filtering.

Re: DNS malware and botnet block lists

Posted: Tue Mar 29, 2022 10:57 pm
by atrasatti
Thank you @kgc. If I can make a suggestion for a feature request, maybe you could setup something like Cloudflare with a standard DNS with the current, very limited list and another DNS with a more complete block list. Something like Nextdns where customers can pick their own lists or even upload a custom list would be dreamy.

I also use a VPN for privacy and security when I'm traveling and even they, as a small business, recently implemented custom lists with a very easy Web interface