#rpz — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #rpz, aggregated by home.social.
-
Black Metal Pestilenz Vol. I
04.10.2025 Bonn / RPZ -
Black Metal Pestilenz Vol. I
04.10.2025 Bonn / RPZ -
Black Metal Pestilenz Vol. I
04.10.2025 Bonn / RPZ -
Black Metal Pestilenz Vol. I
04.10.2025 Bonn / RPZ -
Just added this to one of my Response Policy Zones:
$TTL 300
@ IN SOA localhost. need.to.know.only. (
2018051901; Serial number
60 ; Refresh every minute
60 ; Retry every minute
432000 ; Expire in 5 days
60 ) ; negative caching ttl 1 minute
IN NS LOCALHOST.
*.zip IN CNAME .
substack.com IN CNAME .
*.substack.com IN CNAME . -
Just added this to one of my Response Policy Zones:
$TTL 300
@ IN SOA localhost. need.to.know.only. (
2018051901; Serial number
60 ; Refresh every minute
60 ; Retry every minute
432000 ; Expire in 5 days
60 ) ; negative caching ttl 1 minute
IN NS LOCALHOST.
*.zip IN CNAME .
substack.com IN CNAME .
*.substack.com IN CNAME . -
@iampytest1 I 100% run my own, would be to weird if I didn't, in that way, it is me, who is in control and I can benefit from RPZ zones via (A|I)XFR and be running my own local #blacklist zone (RPZ) for what I might allow or not in contradictions to the general served zones.
What I have on my Workstation (Server when turned on, but that not much these days do to the power prices) and my laptop
1. PowerDNS #Auth server on each for keeping local copies of the RPZ zones
2. PowerDNS #Recursor to handle the #blacklisting via #RPZ
3. PowerDNS #DnsDist in front of the recursor, the benefit's here are many, but mostly because it allow me to use Regex to blacklist commonly subdomains like matomo.$domain.$TIL, that saves me millions of records in the RPZ zones. Also it is setup to know if the laptop is home or alone in the city.
In short, when the laptop is home, it is using the workstations DNS, any other time, it uses it's own resources.
By doing this you also ensures more privacy. The real ➕, how about a response time at 0 msec for every DNS query? except from the first query... and on a modern webpage this can easily be 200 DNS queries.
PS: My RPZ zones is about to be public available again https://0xacab.org/my-privacy-dns/moderators-room/general/-/issues/629
UPDATE:
Fixed some typos and grama -
@Raccoon @JerryMouse
> I feel like I see a lot of servers show up, stick around for a few months
1. Agree, and it is bad for the reasons you mention, BUT, and here is the big BUT(one t only), no matter where I have tried to put up accounts I've either lost them
2. or the instance are #blocked my a hole lot of other instances.
3. They do not blacklist any #Cloudflare instances
> Unless you've got some sort of niche you're going to fill for a bunch of people
1. This is about the the #blacklist niche including #RPZ #DNSFirewall
2. Protecting people against the #cagemafia, not limited to , but such as #Google, #Amazon and #CloudFlare
> you might be better off just putting that time and money into a server you're already established on.
From above, you might see that have not been a possible solution to me, as yourself I do have a "professional" account and a "free fun" account
--------------
Thanks for your input and thought's they are appreciated and don't hesitate to spread more words. -
@hyde Forgot to mention, that #mypdns is not optimized for #PiHole but is targeting systems that can block domains based on wildcard like #RPZ #dnsFirewall -
@hyde Forgot to mention, that #mypdns is not optimized for #PiHole but is targeting systems that can block domains based on wildcard like #RPZ #dnsFirewall -
@Alonely0 @floppy_bv You just need a Linux installation with either Powerdns's #recursor (+dnsdist) or #unbound with #RPZ.
All less than 100mb ram if you uses @mypdns #RPZ #DNS #Firewall zones, you didn't need an entire hardware device, a virtual install is sufficient for most home users, the cool with RPZ over any (dumb) hosts driven system is, is the structure in it and that it do understand how to drop on IP addresses
-
@Alonely0 @floppy_bv You just need a Linux installation with either Powerdns's #recursor (+dnsdist) or #unbound with #RPZ.
All less than 100mb ram if you uses @mypdns #RPZ #DNS #Firewall zones, you didn't need an entire hardware device, a virtual install is sufficient for most home users, the cool with RPZ over any (dumb) hosts driven system is, is the structure in it and that it do understand how to drop on IP addresses
-
@Alonely0 @floppy_bv You just need a Linux installation with either Powerdns's #recursor (+dnsdist) or #unbound with #RPZ.
All less than 100mb ram if you uses @mypdns #RPZ #DNS #Firewall zones, you didn't need an entire hardware device, a virtual install is sufficient for most home users, the cool with RPZ over any (dumb) hosts driven system is, is the structure in it and that it do understand how to drop on IP addresses
-
@Alonely0 @floppy_bv You just need a Linux installation with either Powerdns's #recursor (+dnsdist) or #unbound with #RPZ.
All less than 100mb ram if you uses @mypdns #RPZ #DNS #Firewall zones, you didn't need an entire hardware device, a virtual install is sufficient for most home users, the cool with RPZ over any (dumb) hosts driven system is, is the structure in it and that it do understand how to drop on IP addresses
-
@Alonely0 @floppy_bv You just need a Linux installation with either Powerdns's #recursor (+dnsdist) or #unbound with #RPZ.
All less than 100mb ram if you uses @mypdns #RPZ #DNS #Firewall zones, you didn't need an entire hardware device, a virtual install is sufficient for most home users, the cool with RPZ over any (dumb) hosts driven system is, is the structure in it and that it do understand how to drop on IP addresses
-
@nixCraft This is just one more argument for blacklisting any #Alphabet (#Google) domains and stop being abused by any of the #gacemarfia 's You when the number of sheep's in their farms are shrinking; they maybe understand they are on the wrong path of #Privacy
#mypdns #blacklist #RPZ #DNS #Firewall
Alphabet domains (We currently only have 580 domains... Please contribute): https://0xacab.org/my-privacy-dns/matrix/-/milestones/2
-
@nixCraft This is just one more argument for blacklisting any #Alphabet (#Google) domains and stop being abused by any of the #gacemarfia 's
You know, when the number of sheep's in their farms are shrinking; they might understand they are on the wrong path of #Privacy
#mypdns #blacklist #RPZ #DNS #Firewall
Alphabet domains (We currently only have 580 domains... Please contribute): https://0xacab.org/my-privacy-dns/matrix/-/milestones/2
-
Already in the first line of the article you link is false and inaccurate... Trust nothing on this page, they clearly do not know anything about the topic.
> Cloudflare is a prominent player in web security
#Cloudflare do NOT delivers web security, it is the opposed they do...
1. They are 100% MITM
2. They decrypt all connections, any SSL connections are fake simulations of a secure line to the domain you try to conenct to
3. All the decrypted data are collected and sold and used to identify you for manipulation, and this is not only for ads...#privacy #tracking #mypdns #dnsfirewall #RPZ #CrimeFlare #activism #CAGEMAFIA #StaySafe
-
Already in the first line of the article you link is false and inaccurate... Trust nothing on this page, they clearly do not know anything about the topic.
> Cloudflare is a prominent player in web security
#Cloudflare do NOT delivers web security, it is the opposed they do...
1. They are 100% MITM
2. They decrypt all connections, any SSL connections are fake simulations of a secure line to the domain you try to conenct to
3. All the decrypted data are collected and sold and used to identify you for manipulation, and this is not only for ads...#privacy #tracking #mypdns #dnsfirewall #RPZ #CrimeFlare #activism #CAGEMAFIA #StaySafe
-
Already in the first line of the article you link is false and inaccurate... Trust nothing on this page, they clearly do not know anything about the topic.
> Cloudflare is a prominent player in web security
#Cloudflare do NOT delivers web security, it is the opposed they do...
1. They are 100% MITM
2. They decrypt all connections, any SSL connections are fake simulations of a secure line to the domain you try to conenct to
3. All the decrypted data are collected and sold and used to identify you for manipulation, and this is not only for ads...#privacy #tracking #mypdns #dnsfirewall #RPZ #CrimeFlare #activism #CAGEMAFIA #StaySafe
-
@mzar @nlnetlabs #RPZ yes. With access control options instead of defining a view, a tag can be defined (`access-control-tag:`, `interface-tag:`) and used in `rpz: tags:`. https://unbound.docs.nlnetlabs.nl/en/latest/topics/filtering/rpz.html
I am not sure what you want to achieve with NAT64, but Unbound does not support it (yet). #DNS64 on the other hand is an always on module. It does not synthesise for clients that come with the CD bit as per the RFC; maybe that is useful. #DNS
-
@mypdns How come your not tracked?
#privacy #rpz #blacklists #blocklists #online_protection #firewall #mypdns
-
@mypdns How come your not tracked?
#privacy #rpz #blacklists #blocklists #online_protection #firewall #mypdns