Feature Request: Block generic NextDNS endpoint (dns.nextdns.io) to prevent profile bypass in browsers
Hi NextDNS Community & Team,
I've run into a specific bypass scenario in browser settings (like Google Chrome / Mozilla Firefox) that undermines custom NextDNS profiles, and I'd like to suggest a solution or start a discussion on how this can be better handled.
The Problem
When a user goes into Chrome/Firefox settings under Security > Use Secure DNS (DoH), the browser offers a built-in dropdown list of popular DoH providers, including NextDNS.
When selecting "NextDNS" from that browser dropdown:
The browser connects directly to the default global NextDNS DoH endpoint ([https://dns.nextdns.io](https://dns.nextdns.io)) over Port 443.
Because it uses the generic endpoint without a profile ID attached ([https://dns.nextdns.io/XXXXXX](https://dns.nextdns.io/XXXXXX)), it completely bypasses all custom profile rules, blocklists, and parental controls set up on the network/account.
Since it is still resolving via NextDNS's public infrastructure, traffic flows normally, but without any filtering applied.
Even if you enable "Block Bypass Methods" in your NextDNS dashboard, it currently doesn't block queries going to NextDNS's own generic DoH IP/endpoints if a user selects it inside the browser.
Feature Request / Proposed Solution
Could NextDNS introduce a way—either within the dashboard or via DNS resolution logic—to block or restrict queries coming through the generic/unauthenticated dns.nextdns.io endpoints for networks utilizing custom profiles?
Specifically:
Option to treat requests without a valid Profile ID as blocked/unfiltered-deny on networks associated with linked IPs or configured DoT/DoH endpoints.
Or provide recommended Canary/DDR responses to ensure browsers fail back to the local/router-provided DoH/DoT endpoint containing the user's specific Profile ID.
This would prevent users on a network from easily bypassing custom NextDNS profiles simply by selecting the default "NextDNS" option built into modern browsers.
Curious to hear thoughts from the community and the NextDNS team on how this can be better mitigated!
Reply
Content aside
-
1
Likes
- 3 days agoLast active
- 41Views
