Public RDNS Lite

Lighter public DNS resolver using oisd Big for ad, malware, phishing and tracker protection. Fewer blocks than Full, no NSFW filtering.

Overview · Full · Lite · Open

TransportDoH, DoT, Do53
NetworkIPv4 and IPv6
LoggingNone
DNSSECEnforced
TierLite — light oisd Big blocking

Quick Start

Configure your device to use the Lite tier. See Full for strong family-safe blocking or Open for none.

Android 9+ (Private DNS)
lite.public-rdns.com
iOS / iPadOS / macOS (profiles)

lite-dns-dot.mobileconfig (DoT)

lite-dns-doh.mobileconfig (DoH)

Firefox / Chrome / Edge / Brave (DoH)
https://lite.public-rdns.com/dns-query
systemd-resolved (Linux)
[Resolve]
DNS=37.27.125.217#lite.public-rdns.com 2a01:4f9:3070:2feb::217#lite.public-rdns.com
DNSOverTLS=yes
DNSSEC=allow-downgrade
sudo systemctl restart systemd-resolved
resolvectl status
Unbound forwarder (Linux / BSD)
forward-zone:
    name: "."
    forward-tls-upstream: yes
    forward-addr: 37.27.125.217@853#lite.public-rdns.com
    forward-addr: 2a01:4f9:3070:2feb::217@853#lite.public-rdns.com
Windows 11 (DoH)
IPv4: 37.27.125.217     DoH: https://lite.public-rdns.com/dns-query
IPv6: 2a01:4f9:3070:2feb::217   DoH: https://lite.public-rdns.com/dns-query
Routers (plain / DoT)
Primary: 37.27.125.217     IPv6: 2a01:4f9:3070:2feb::217

OpenWrt / pfSense / OPNsense — forward over DoT to lite.public-rdns.com:853.

Command line
dig @lite.public-rdns.com example.com
kdig @lite.public-rdns.com +tls example.com
kdig @lite.public-rdns.com +https example.com

Endpoints

TransportAddress
DoHhttps://lite.public-rdns.com/dns-query
DoTlite.public-rdns.com:853
Plain DNSlite.public-rdns.com
IPv437.27.125.217
IPv62a01:4f9:3070:2feb::217

This resolver publishes _dns.resolver.arpa SVCB records for DDR auto-discovery.

Android

Settings → Network & internet → Advanced → Private DNS → Private DNS provider hostname:

lite.public-rdns.com

Apple (iOS, iPadOS, macOS)

Download a profile from Quick Start (DoT recommended) and install via Settings → General → VPN & Device Management (iOS) or System Settings → Privacy & Security → Profiles (macOS).

Browsers

https://lite.public-rdns.com/dns-query

Browser DoH only protects the browser. For system-wide protection, configure the OS instead.

systemd-resolved and Unbound

[Resolve]
DNS=37.27.125.217#lite.public-rdns.com 2a01:4f9:3070:2feb::217#lite.public-rdns.com
DNSOverTLS=yes
DNSSEC=allow-downgrade
forward-zone:
    name: "."
    forward-tls-upstream: yes
    forward-addr: 37.27.125.217@853#lite.public-rdns.com
    forward-addr: 2a01:4f9:3070:2feb::217@853#lite.public-rdns.com

Windows

Windows 11: Settings → Network & internet → Edit DNS → Manual. IPv4: 37.27.125.217, DoH URL: https://lite.public-rdns.com/dns-query.

Routers

Primary: 37.27.125.217     IPv6: 2a01:4f9:3070:2feb::217

OpenWrt, pfSense, and OPNsense can forward over DoT to lite.public-rdns.com:853.

Transports

curl -s -H 'accept: application/dns-message' \
  "https://lite.public-rdns.com/dns-query?dns=q80BAAABAAAAAAAAB2V4YW1wbGUDY29tAAABAAE" | xxd
kdig @lite.public-rdns.com +tls example.com
dig @lite.public-rdns.com example.com

Blocking

The Lite tier uses the oisd Big list for lighter ad, malware, phishing and tracking protection (no NSFW or gambling blocks). Blocked names are answered with a CNAME to sinkhole.public-rdns.com.

The Lite tier uses the oisd Big RPZ feed from big.oisd.nl. It targets ads, malware, phishing, ransomware, spyware, cryptojacking, and non-essential telemetry — while deliberately avoiding breakage in NSFW, gambling, torrents, shopping, social media, and similar categories.

Test that blocking works

dig @lite.public-rdns.com doubleclick.net
# Expect a CNAME to sinkhole.public-rdns.com → 0.0.0.0 / ::

False positives

Report false positives via oisd.nl. For stronger blocking see Full; for none see Open.

Comparison

Public RDNS LiteCloudflare 1.1.1.1Quad9NextDNSAdGuard
Logs queries?NoYes (24h+)NoConfigurableYes
DNSSEC enforcedYes (hard fail)YesYesYesYes
Family-safe blockingLight (oisd Big)Malware onlyMalware + someConfigurableStrong
NSFW / Gambling blocksNo (by design)NoLimitedPaid tiersPaid tiers
Native tracker blockingModerate (oisd Big)NoNoPaidPaid
QNAME minimisationYesYesYesYesYes
ECS (client IP leak)DisabledEnabledDisabledOptionalOptional
Cost$0$0$0Free tier limitedFree tier limited
Transparent operatorYes (this page)US corpNon-profitFor-profitFor-profit