mirror of
https://github.com/yokoffing/NextDNS-Config.git
synced 2025-11-17 15:43:39 -05:00
196 lines
5.8 KiB
Markdown
196 lines
5.8 KiB
Markdown
***
|
||
|
||
# Security
|
||
### Threat Intelligence Feeds
|
||
 Use Threat Intelligence Feeds
|
||
### AI-Driven Threat Detection
|
||
 Enable AI-Driven Threat Detection
|
||
### Google Safe Browsing
|
||
 Enable Google Safe Browsing
|
||
### Cryptojacking Protection
|
||
 Enable Cryptojacking Protection → :radioactive: *Enabling may cause breakage (unlikely)*
|
||
### DNS Rebinding Protection
|
||
 Enable DNS Rebinding Protection → :radioactive: *Enabling may cause breakage (unlikely)*
|
||
### IDN Homograph Attacks Protection
|
||
 Enable Homograph Attacks Protection
|
||
### Typosquatting Protection
|
||
 Enable Typosquatting Protection
|
||
### Domain Generation Algorithms (DGAs) Protection
|
||
 Enable DGA Protection
|
||
### Block Newly Registered Domains (NRDs)
|
||
 Block Newly Registered Domains (NRDs) → :radioactive: *Enabling may cause breakage*
|
||
### Block Dynamic DNS Hostnames
|
||
 Enable Block Dynamic DNS Hostnames
|
||
### Block Parked Domains
|
||
 Block Parked Domains
|
||
|
||
### Block Top-Level Domains (TLDs)
|
||
```
|
||
agency
|
||
asia
|
||
bar
|
||
bid
|
||
buzz
|
||
cam
|
||
casa
|
||
cc
|
||
cf
|
||
club
|
||
cn (optional)
|
||
cricket
|
||
date
|
||
email
|
||
fail
|
||
fit
|
||
fun
|
||
ga
|
||
gdn
|
||
ge
|
||
gq
|
||
guru
|
||
help
|
||
host
|
||
icu
|
||
info
|
||
ir
|
||
link
|
||
live
|
||
loan
|
||
ltda
|
||
men
|
||
ml
|
||
nagoya
|
||
nf
|
||
okinawa
|
||
online
|
||
ooo
|
||
press
|
||
pw
|
||
recipes
|
||
rest
|
||
review
|
||
rodeo
|
||
ryukyu
|
||
shop
|
||
site
|
||
space
|
||
su
|
||
support
|
||
surf
|
||
tk
|
||
tokyo
|
||
top
|
||
ug
|
||
vip
|
||
wang
|
||
webcam
|
||
website
|
||
win
|
||
work
|
||
ws
|
||
```
|
||
|
||
Allowlist/Exceptions:
|
||
```
|
||
biz
|
||
life
|
||
monster
|
||
pro
|
||
ru
|
||
xyz
|
||
```
|
||
|
||
### Block Child Sexual Abuse Material
|
||
 Block Child Sexual Abuse Material
|
||
|
||
***
|
||
|
||
# Privacy
|
||
### Blocklists
|
||
There seems to be a lot of activity on [Github](https://github.com/badmojr/1Hosts/commits/master?before=fb857882973986a3ac4575cd1d79d9079d363866+35&branch=master&qualified_name=refs%2Fheads%2Fmaster) and [Reddit](https://www.reddit.com/user/badmojr/comments/) in the past months to remove breakage from 1Hosts **Pro** (see [this](https://www.reddit.com/r/nextdns/comments/uxwabr/kind_of_amazed_at_1hosts_pro/ia2gyta/?context=3) and [that](https://www.reddit.com/r/nextdns/comments/v6yiqe/what_filterlists_do_you_recommend/ic51pa8/?context=3)). But if you experience significant breakage due to this list, drop down to 1Hosts **Lite**.
|
||
|
||
NextDNS Ads & Trackers Blocklist
|
||
AdGuard DNS filter
|
||
oisd
|
||
1Hosts (Pro)
|
||
### Native Tracking Protection
|
||
:radioactive: *Enabling may cause breakage (unlikely)*
|
||
|
||
Add these brands according to what devices you use; there is no advantage to adding brands you don't own. However, there’s *not* a strong reason to omit any brands either.
|
||
|
||
Xiaomi
|
||
Huawei
|
||
Samsung
|
||
Amazon Alexa
|
||
Windows
|
||
Apple
|
||
Roku
|
||
Sonos
|
||
### Block Disguised Third-Party Trackers
|
||
 Block Disguised Third-Party Trackers
|
||
### Allow Affiliate & Tracking Links
|
||
 Allow Affiliate & Tracking Links
|
||
|
||
***
|
||
|
||
# Parental Control
|
||
### YouTube Restricted Mode
|
||
 Enforce YouTube Restricted Mode → :radioactive: *Enabling may cause breakage*
|
||
|
||
### Block Bypass Methods
|
||
 Block Bypass Methods → :radioactive: *Enabling may cause breakage*
|
||
|
||
***
|
||
|
||
# Denylist
|
||
(optional) Most of these are blocked under [Block Dynamic DNS Hostnames](https://github.com/yokoffing/NextDNS-Config/edit/main/README.md#block-dynamic-dns-hostnames) (see [here](https://github.com/nextdns/metadata/blob/master/security/ddns/suffixes)).
|
||
|
||
pubnub.com
|
||
ddns.net
|
||
duckdns.org
|
||
hopto.org
|
||
linkpc.net
|
||
myddns.me
|
||
myftp.biz
|
||
myftp.org
|
||
ngrok.io
|
||
no-ip.biz
|
||
no-ip.org
|
||
portmap.host
|
||
portmap.io
|
||
publicvm.com
|
||
sytes.net
|
||
zapto.org
|
||
|
||
***
|
||
|
||
# Allowlist
|
||
if using Facebook and Instagram:
|
||
|
||
graph.facebook.com
|
||
graph.instagram.com
|
||
|
||
breaks CBS News (NextDNS Ads & Trackers Blocklist):
|
||
|
||
production-cmp.isgprivacy.cbsi.com
|
||
***
|
||
|
||
# Settings
|
||
### Block Page
|
||
 Enable Block Page → :radioactive: *Enabling may cause breakage if the NextDNS Root CA is not on your devices*
|
||
### Anonymized EDNS Client Subnet
|
||
 Enable Anonymized EDNS Client Subnet
|
||
### Cache Boost
|
||
 Enable Cache Boost
|
||
### CNAME Flattening
|
||
 Enable CNAME Flattening
|
||
### Web3 (optional)
|
||
 Enable Web3
|
||
|
||
***
|
||
|
||
# Credit
|
||
Forked from the [crssi](https://github.com/crssi/NextDNS-Config#readme) config. Some inputs came from the [scafroglia93](https://github.com/scafroglia93/nextdns-setting]) config while other changes are my own.
|
||
|
||
***
|