{
  "slug": "control-d",
  "category": "dns-resolvers",
  "name": "Control D",
  "description": "DNS resolver service from ControlD Inc. in Canada, founded by the team behind Windscribe. It offers free filtering resolvers and paid plans with custom rules, over legacy DNS, DoH, DoT and DNS over QUIC.",
  "website": "https://controld.com",
  "source": "https://github.com/Control-D-Inc/ctrld",
  "license": "MIT",
  "platforms": [],
  "jurisdiction": {
    "code": "CA",
    "name": "Canada",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": false,
    "cloud_act": null
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "C",
  "score": 63,
  "coverage": 100,
  "summary": "Control D scores 63 out of 100 (grade C) on the DNS resolvers criteria. It meets 5 of 11 criteria: no trackers or telemetry, no ads or data sales, TLS configuration, Encrypted DNS and DNSSEC validation. It partly meets open source, security headers and no query logs. It does not meet independent audit, transparency report and tells users about requests. It is based in Canada: Five Eyes member. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.",
  "url": "https://privacyratings.com/dns-resolvers/control-d/",
  "markdown": "https://privacyratings.com/dns-resolvers/control-d/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://github.com/Control-D-Inc/ctrld/blob/main/LICENSE",
      "note": "The ctrld client is open source under the MIT license. The resolver service is closed source."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://controld.com/free-dns",
      "note": "The site states no third-party tracking or analytics services are used on the website."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://controld.com/pricing",
      "note": "Funded by paid plans. No ads."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No independent audit is published."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No transparency report or government request policy is published."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published policy on notifying users about data requests."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=controld.com&hideResults=on",
      "note": "Grade A+"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "partial",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=controld.com",
      "note": "Grade B (75/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "encrypted_dns": {
      "title": "Encrypted DNS",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://docs.controld.com/docs/free-dns",
      "note": "The free resolvers are listed with DoH, DoT and DNS over QUIC endpoints."
    },
    "no_query_logs": {
      "title": "No query logs",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://controld.com/free-dns",
      "note": "The free resolvers are stated to keep no browsing history, timestamps or logs. Not audited."
    },
    "dnssec_validation": {
      "title": "DNSSEC validation",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://docs.controld.com/docs/disable-dnssec-option",
      "note": "DNSSEC validation is on by default and can be turned off per profile."
    }
  },
  "tests": {
    "ssllabs": "A+",
    "observatory": "B",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T06:38:26.935Z"
  },
  "last_modified": "2026-10-01T06:56:31Z"
}