I’ve moved from a local resolver with regular block list updating to NextDNS - here’s why I’d recommend it over a diy solution:
1. Easy to turn on and off. My block lists were pretty aggressive and worked beautifully 90% of the time. However, occasionally I’d need to hit a site that was registered in a list that wasn’t immediately obvious. The O’Reilly site is (was) a good example - they were loading a script on their login page at one point that failed because I’d blocked the source. I’ve encountered other site that fail in similar ways. Being able to temporarily disable adblocking (OSX via the app) is tremendously convenient.
2. The blacklists and blocking categories offered by NextDNS are at least as good as what I’d managed to pull together (I was pretty proud of mine), they update frequently, and again it’s very easy to opt-in/opt-out
3. CName cloaking - unless you update your own lists very frequently, there’s a good chance you won’t be as effective at catching third-party trackers masquerading as first parties.
I had fun running a local resolver and updating it from various block list sources with a cron job. I’d add new entries manually as I encountered them, but after a while it got old. Additionally, I wanted the same protection outside of my network. The same setup on a FreeBSD droplet worked well, but was more maintenance. NextDNS does at least as good a job, and it’s way more convenient.
1. Easy to turn on and off. My block lists were pretty aggressive and worked beautifully 90% of the time. However, occasionally I’d need to hit a site that was registered in a list that wasn’t immediately obvious. The O’Reilly site is (was) a good example - they were loading a script on their login page at one point that failed because I’d blocked the source. I’ve encountered other site that fail in similar ways. Being able to temporarily disable adblocking (OSX via the app) is tremendously convenient.
2. The blacklists and blocking categories offered by NextDNS are at least as good as what I’d managed to pull together (I was pretty proud of mine), they update frequently, and again it’s very easy to opt-in/opt-out
3. CName cloaking - unless you update your own lists very frequently, there’s a good chance you won’t be as effective at catching third-party trackers masquerading as first parties.
I had fun running a local resolver and updating it from various block list sources with a cron job. I’d add new entries manually as I encountered them, but after a while it got old. Additionally, I wanted the same protection outside of my network. The same setup on a FreeBSD droplet worked well, but was more maintenance. NextDNS does at least as good a job, and it’s way more convenient.