# OpenNIC privacy rating

Volunteer-run alternative DNS root with public resolvers that answer for both ICANN domains and OpenNIC's own top-level domains such as .libre and .oss.

## Summary

OpenNIC scores 41 out of 100 (grade D) on the DNS resolvers criteria. It meets 1 of 11 criteria: no ads or data sales. It partly meets open source, no trackers or telemetry, TLS configuration, Encrypted DNS, no query logs and DNSSEC validation. It does not meet independent audit, transparency report, tells users about requests and security headers. Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade D.

- Website: https://opennic.org
- Home page trackers: none found
- Category: [DNS resolvers](https://privacyratings.com/dns-resolvers/)
- Grade: D (41/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | Partial | Project tooling is published on GitHub, but each volunteer resolver runs its own setup. | https://github.com/OpenNIC |
| No trackers or telemetry | Partial | The website uses self-hosted Matomo analytics. No third-party trackers. | https://opennic.org/privacy/ |
| No ads or data sales | Yes | Run by volunteers and funded by donations. No ads. | https://opennic.org/ |
| Independent audit | No | No independent audit is published. |  |
| Transparency report | No | No transparency report or government request policy is published. |  |
| Tells users about requests | No | No published policy on notifying users about data requests. |  |
| TLS configuration | Partial | Grade B | https://www.ssllabs.com/ssltest/analyze.html?d=opennic.org&hideResults=on |
| Security headers | No | Grade D (30/100+) | https://developer.mozilla.org/en-US/observatory/analyze?host=opennic.org |
| Modern web standards | Not tested yet | Not tested yet. |  |
| Encrypted DNS | Partial | Some volunteer servers offer DoH or DoT, but support varies by server. | https://wiki.opennic.org/opennic/setup/listserver |
| No query logs | Partial | Each volunteer server sets its own log policy, and some keep no logs or anonymized logs. Not audited. | https://wiki.opennic.org/opennic/setup/listserver |
| DNSSEC validation | Partial | Server operators may enable DNSSEC validation, but it is not required. | https://wiki.opennic.org/opennic/dnssec |

Source: https://privacyratings.com/dns-resolvers/opennic/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/dns-resolvers/opennic.md
