DNS resolvers
OpenNIC privacy rating
Volunteer-run alternative DNS root with public resolvers that answer for both ICANN domains and OpenNIC's own top-level domains such as .libre and .oss.
Summary
OpenNIC scores 41 out of 100 (grade D) on the DNS resolvers criteria. It meets 1 of 11 criteria: no ads or data sales. It partly meets open source, no trackers or telemetry, TLS configuration, Encrypted DNS, no query logs and DNSSEC validation. It does not meet independent audit, transparency report, tells users about requests and security headers. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade D.
Score 41 out of 100. How scoring works
Criteria
-
Partial
Open source Weight 3 of 3
Is all the source code needed to run the product public?
Project tooling is published on GitHub, but each volunteer resolver runs its own setup.
-
Partial
No trackers or telemetry Weight 3 of 3
Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?
The website uses self-hosted Matomo analytics. No third-party trackers.
-
Yes
No ads or data sales Weight 2 of 3
Is the product funded without advertising, ad targeting or selling user data?
Run by volunteers and funded by donations. No ads.
-
No
Independent audit Weight 2 of 3
Has an independent security or privacy audit been published within the last three years?
No independent audit is published.
-
No
Transparency report Weight 2 of 3
Does the provider regularly publish how many government and legal requests it receives and how it responds?
No transparency report or government request policy is published.
-
No
Tells users about requests Weight 1 of 3
Does the provider promise to tell users about requests for their data, unless a court forbids it?
No published policy on notifying users about data requests.
-
Partial
Encrypted DNS Weight 3 of 3
Are DNS over HTTPS and DNS over TLS supported?
Some volunteer servers offer DoH or DoT, but support varies by server.
-
Partial
No query logs Weight 3 of 3
Are queries stored without IP addresses, and is this independently audited?
Each volunteer server sets its own log policy, and some keep no logs or anonymized logs. Not audited.
-
Partial
DNSSEC validation Weight 1 of 3
Does the resolver validate DNSSEC?
Server operators may enable DNSSEC validation, but it is not required.
Automated tests
-
Partial
TLS configuration Weight 2 of 3
Does the website pass the Qualys SSL Labs test with a grade of A or better?
Grade B
-
No
Security headers Weight 1 of 3
Does the website pass the Mozilla HTTP Observatory test with a grade of A or better?
Grade D (30/100+)
-
Not tested yet
Modern web standards Weight 1 of 3
Does the website score 90% or higher on the Internet.nl website test?
Not tested yet.