Feature Request: Configurable NXDOMAIN Blocking Response and Additional Security Protections
Hello NextDNS Team,
I would like to submit a security and compatibility feature request concerning blocked DNS responses, along with several additional security improvements.
The most important issue for me is the lack of a configurable NXDOMAIN response for blocked domains.
1. Configurable NXDOMAIN Response for Blocked Domains — High Priority
At present, NextDNS commonly returns:
- A: 0.0.0.0
- AAAA: ::
for blocked domains.
I would strongly request an option allowing users to select the DNS response returned for blocked queries, ideally with at least:
- NXDOMAIN
- REFUSED
- 0.0.0.0 / ::
- optionally a custom/block-page response
The current 0.0.0.0 / :: behavior creates a significant compatibility problem with ASUS routers using dnsmasq DNS rebinding protection.
When a blocked hostname resolves to 0.0.0.0 or ::, dnsmasq may interpret the response as potentially resembling a DNS-rebinding condition and repeatedly generate messages similar to:
“possible DNS-rebind attack detected”
On a security-focused profile that blocks many advertising, tracking, malware, phishing, telemetry and other domains, this can result in a very large number of unnecessary router log entries.
This creates several problems:
- router system-log flooding;
- reduced usefulness of the logs because genuine security events become harder to identify;
- unnecessary dnsmasq rebind-processing and logging activity;
- additional flash/log I/O depending on router configuration;
- avoidable compatibility problems between NextDNS blocking and router-side DNS-rebinding protection.
NXDOMAIN is a much cleaner semantic response for many users because it tells the client that the requested hostname does not resolve, without supplying a synthetic special-purpose IP address that local DNS security logic may subsequently inspect or reject.
I am aware that NextDNS users have requested NXDOMAIN behavior previously, so I would strongly encourage reconsidering this as a configurable Profile option rather than requiring a global behavior change.
For example:
Settings → Blocked Query Response
with choices such as:
NXDOMAIN
REFUSED
0.0.0.0 / ::
Block Page
This would allow users to choose the behavior best suited to their network.
A competing DNS filtering provider already exposes this type of configurable blocked-response behavior, including NXDOMAIN and REFUSED, so it would be very useful to have equivalent or better flexibility in NextDNS.
For my ASUS router environment specifically, lack of NXDOMAIN support is currently serious enough to be a potential deal breaker despite the otherwise excellent new NextDNS security features.
2. Malicious-IP Reputation for DNS Answers
I would also like to request explicit IP-reputation analysis of DNS answers.
To be clear, I am not requesting that NextDNS act as a firewall capable of blocking arbitrary direct IP connections.
Instead, I mean:
domain query → NextDNS receives A/AAAA response → destination IP/network reputation is evaluated → domain can be blocked if it resolves to infrastructure known to be malicious or extremely high risk.
This provides an additional layer against situations such as:
- newly registered malicious domains;
- rapidly rotated attacker-controlled domains;
- malware C2 infrastructure;
- domains that have not yet accumulated their own reputation;
- domains pointing to IPs/networks already associated with malicious activity.
This would complement the newer NextDNS protections such as Fast Flux Networks, DGA protection, AI-Driven Threat Detection and Threat Intelligence rather than replacing them.
If NextDNS already performs this type of IP/ASN/network reputation analysis internally, I would appreciate clarification on its scope.
3. Dedicated Stalkerware / Spyware Infrastructure Protection
I would also strongly support more explicit protection against stalkerware and commercial spyware infrastructure.
Possible implementation options could include:
- a dedicated Stalkerware protection category;
- integration of reputable stalkerware IOC feeds into Threat Intelligence;
- identification of known stalkerware C2/administration domains;
- blocking domains associated with commercial surveillance applications when confidently classified.
There are already established community-maintained stalkerware IOC projects, and this seems like a natural extension of NextDNS's security model.
It would be especially valuable if detections were separately identified in logs so users could distinguish stalkerware activity from ordinary malware.
4. IP Logger / Tracking-Link Protection
I would also like to request dedicated protection against known IP-logging and tracking-link services.
I understand that DNS cannot prevent a legitimate web server from seeing a visitor's public IP address once a connection is made, and NextDNS is not a VPN.
However, NextDNS could still provide useful protection by identifying and blocking:
- known IP-logger domains;
- tracking-link services whose primary function is collecting visitor IP/device metadata;
- disposable IP-logging domains;
- malicious or deceptive shortened URLs associated with IP-logging services;
- newly created domains strongly associated with this activity.
Ideally this could be implemented as either:
- a dedicated security/privacy category, or
- additional intelligence integrated into Threat Intelligence / AI protection.
Why I Am Requesting These Features
The recent NextDNS security additions are very promising, particularly:
- DNS Data Exfiltration
- DNS Payload Delivery
- Fast Flux Networks
- DGA Protection
- homograph and typosquatting protection
- high-risk infrastructure protections
- tunneling/data-drop-related protections
These capabilities are a major reason I am considering NextDNS as the main security DNS resolver for my network.
However, the lack of configurable NXDOMAIN responses creates a practical compatibility problem on ASUS/dnsmasq routers, while malicious-IP reputation, stalkerware infrastructure protection and dedicated IP-logger protection would further strengthen the defensive stack.
My requested priority would therefore be:
- Configurable NXDOMAIN/REFUSED blocked-query response — highest priority
- IP/network reputation analysis of resolved destinations
- Dedicated stalkerware/spyware infrastructure protection
- Dedicated IP-logger/tracking-link protection
The first item is particularly important because it is not simply an additional security feature; it affects interoperability with router-side DNS-rebinding protection and can produce extensive unnecessary router logging.
If any of these capabilities already exist internally but are not exposed in the dashboard or documentation, I would greatly appreciate clarification.
Thank you for considering these requests and for the continued development of NextDNS's security capabilities.
Best regards
Reply
Content aside
-
2
Votes
- 10 hrs agoLast active
- 13Views
-
1
Following
