Public RDNS Open

Completely unfiltered public DNS resolver. No blocking of any kind — maximum compatibility for all domains.

Overview · Full · Lite · Open

TransportDoH, DoT, Do53
NetworkIPv4 and IPv6
LoggingNone
DNSSECEnforced
TierOpen — no blocking

Quick Start

Configure your device to use the Open tier. See Full for strong family-safe blocking or Lite for light oisd protection.

Android 9+ (Private DNS)
open.public-rdns.com
iOS / iPadOS / macOS (profiles)

open-dns-dot.mobileconfig (DoT)

open-dns-doh.mobileconfig (DoH)

Firefox / Chrome / Edge / Brave (DoH)
https://open.public-rdns.com/dns-query
systemd-resolved (Linux)
[Resolve]
DNS=37.27.125.213#open.public-rdns.com 2a01:4f9:3070:2feb::213#open.public-rdns.com
DNSOverTLS=yes
DNSSEC=allow-downgrade
sudo systemctl restart systemd-resolved
resolvectl status
Unbound forwarder (Linux / BSD)
forward-zone:
    name: "."
    forward-tls-upstream: yes
    forward-addr: 37.27.125.213@853#open.public-rdns.com
    forward-addr: 2a01:4f9:3070:2feb::213@853#open.public-rdns.com
Windows 11 (DoH)
IPv4: 37.27.125.213     DoH: https://open.public-rdns.com/dns-query
IPv6: 2a01:4f9:3070:2feb::213   DoH: https://open.public-rdns.com/dns-query
Routers (plain / DoT)
Primary: 37.27.125.213     IPv6: 2a01:4f9:3070:2feb::213

OpenWrt / pfSense / OPNsense — forward over DoT to open.public-rdns.com:853.

Command line
dig @open.public-rdns.com example.com
kdig @open.public-rdns.com +tls example.com
kdig @open.public-rdns.com +https example.com

Endpoints

TransportAddress
DoHhttps://open.public-rdns.com/dns-query
DoTopen.public-rdns.com:853
Plain DNSopen.public-rdns.com
IPv437.27.125.213
IPv62a01:4f9:3070:2feb::213

This resolver publishes _dns.resolver.arpa SVCB records for DDR auto-discovery.

Android

Settings → Network & internet → Advanced → Private DNS → Private DNS provider hostname:

open.public-rdns.com

Apple (iOS, iPadOS, macOS)

Download a profile from Quick Start (DoT recommended) and install via Settings → General → VPN & Device Management (iOS) or System Settings → Privacy & Security → Profiles (macOS).

Browsers

https://open.public-rdns.com/dns-query

Browser DoH only protects the browser. For system-wide protection, configure the OS instead.

systemd-resolved and Unbound

[Resolve]
DNS=37.27.125.213#open.public-rdns.com 2a01:4f9:3070:2feb::213#open.public-rdns.com
DNSOverTLS=yes
DNSSEC=allow-downgrade
forward-zone:
    name: "."
    forward-tls-upstream: yes
    forward-addr: 37.27.125.213@853#open.public-rdns.com
    forward-addr: 2a01:4f9:3070:2feb::213@853#open.public-rdns.com

Windows

Windows 11: Settings → Network & internet → Edit DNS → Manual. IPv4: 37.27.125.213, DoH URL: https://open.public-rdns.com/dns-query.

Routers

Primary: 37.27.125.213     IPv6: 2a01:4f9:3070:2feb::213

OpenWrt, pfSense, and OPNsense can forward over DoT to open.public-rdns.com:853.

Transports

curl -s -H 'accept: application/dns-message' \
  "https://open.public-rdns.com/dns-query?dns=q80BAAABAAAAAAAAB2V4YW1wbGUDY29tAAABAAE" | xxd
kdig @open.public-rdns.com +tls example.com
dig @open.public-rdns.com example.com

Blocking

The Open tier performs no blocking — every name resolves if it exists in the global DNS. No RPZ feeds are loaded. If you need protection, use the Full or Lite tier instead.

Comparison

Public RDNS OpenCloudflare 1.1.1.1Quad9NextDNSAdGuard
Logs queries?NoYes (24h+)NoConfigurableYes
DNSSEC enforcedYes (hard fail)YesYesYesYes
Family-safe blockingNoneMalware onlyMalware + someConfigurableStrong
NSFW / Gambling blocksNoneNoLimitedPaid tiersPaid tiers
Native tracker blockingNoneNoNoPaidPaid
QNAME minimisationYesYesYesYesYes
ECS (client IP leak)DisabledEnabledDisabledOptionalOptional
Cost$0$0$0Free tier limitedFree tier limited
Transparent operatorYes (this page)US corpNon-profitFor-profitFor-profit