DNS Malware Filtering Compared: Quad9 VS Cloudflare VS DNS Filter VS OpenDNS / Cisco Umbrella

Ғылым және технология

Connecting With Us
---------------------------------------------------
+ Hire Us For A Project: lawrencesystems.com/hire-us/
+ Tom Twitter 🐦 TomLawrenceTech
+ Our Web Site www.lawrencesystems.com/
+ Our Forums forums.lawrencesystems.com/
+ Instagram lawrencesystems
+ Facebook Lawrencesystems/
+ GitHub github.com/lawrencesystems/
+ Discord discord.gg/ZwTz3Mh
Lawrence Systems Shirts and Swag
---------------------------------------------------
►👕 lawrence.video/swag
AFFILIATES & REFERRAL LINKS
---------------------------------------------------
Amazon Affiliate Store
🛒 www.amazon.com/shop/lawrencesystemspcpickup
UniFi Affiliate Link
🛒 store.ui.com?a_aid=LTS
All Of Our Affiliates that help us out and can get you discounts!
🛒 lawrencesystems.com/partners-we-love/
Gear we use on Kit
🛒 kit.co/lawrencesystems
Use OfferCode LTSERVICES to get 5% off your order at
🛒 lawrence.video/techsupplydirect
Digital Ocean Offer Code
🛒 m.do.co/c/85de8d181725
HostiFi UniFi Cloud Hosting Service
🛒 hostifi.net/?via=lawrencesystems
Protect you privacy with a VPN from Private Internet Access
🛒 www.privateinternetaccess.com/pages/buy-vpn/LRNSYS
Patreon
💰 www.patreon.com/lawrencesystems
Forum post with the script and details
forums.lawrencesystems.com/t/dns-malware-filtering-compared-quad9-vs-cloudflave-vs-dns-filter-vs-opendns-cisco-umbrella/5072
Part two:DNS Malware Filtering Followup: Comments, Concerns, Cisco Corrections and Conversation
kzread.info/dash/bejne/pXipytp8h8eZp7g.html
Also, The IP visible at the top of the OpenDNS page is not my office IP address.

Пікірлер: 133

  • @LAWRENCESYSTEMS
    @LAWRENCESYSTEMS4 жыл бұрын

    The Forum Post: forums.lawrencesystems.com/t/dns-malware-filtering-compared-quad9-vs-cloudflave-vs-dns-filter-vs-opendns-cisco-umbrella/5072 Part Two:DNS Malware Filtering Followup: Comments, Concerns, Cisco Corrections and Conversation kzread.info/dash/bejne/pXipytp8h8eZp7g.html The IP visible at the top of the OpenDNS page is not my office IP address. Also I did a test with NextDNS and posted the results in my forums

  • @regchan

    @regchan

    4 жыл бұрын

    kzread.info/dash/bejne/m6GgqNebidmeibw.html your ip is visible at the top of the open dns site

  • @macsavant

    @macsavant

    4 жыл бұрын

    The OpenDNS numbers are horrible. Did you configure it to block malware for your IP address? Be certain it's configured for your IP address.

  • @ernestoarellano5012

    @ernestoarellano5012

    4 жыл бұрын

    You need to configure your IP in cisco umbrella for it to apply the policy or use the roaming client. Even if it resolves it will show the block page.

  • @stephanefaure489

    @stephanefaure489

    3 жыл бұрын

    Unfortunatelly you didn't test Cisco Umbrella but only OpenDNS personnal. The Umbrella dashboard, possibilities and filter are way far more different. Do you have a list of you tested domains so I can test it with a proper Umbrella DNS and SIG deployement ? I guess you should probably change the video name to remove Umbrella or make an addon. Have a nice day :)

  • @stephanefaure489

    @stephanefaure489

    3 жыл бұрын

    Sorry I forgot, in your first page of resolution you have a 146.112.61.108, wich is an Open DNS IP, so your request has been redirect to an OpenDNS block page, did you take it in your maths ?

  • @pix_by_joshua
    @pix_by_joshua4 жыл бұрын

    Oh my gosh. Excellent Data Analysis! I'm going back to Quad9 even though the speed is slightly slower (by about 15ms) compared to Cloudflare. Thanks for sharing.

  • @christophersoutherlin2631

    @christophersoutherlin2631

    3 ай бұрын

    That's miniscule. The key benchmark is to stay below 50ms as a performance metric. For my network, Cloudflare was the fastest, but it's not stable and consistent. Upload speed was the most affected.

  • @Duder_abides
    @Duder_abides4 жыл бұрын

    This is great, and surprising. Thanks for the quality content, really like your videos. Switched all my gear to quad9. Interesting to see Umbrella crap the bed, they sure market the hell out of that.

  • @christianlempa
    @christianlempa4 жыл бұрын

    Thank's man, you're making so nice and valuable content, keep going ❤️

  • @PhrozenN
    @PhrozenN3 жыл бұрын

    Would love to see a followup on this! Maybe make it an annual event?

  • @BrianThomas

    @BrianThomas

    2 жыл бұрын

    Agreed 👍🏾

  • @ohjaysimpson397

    @ohjaysimpson397

    Жыл бұрын

    Yes, it's been awhile. Whats the new DNS we should be using now

  • @goteamgorilla
    @goteamgorilla3 жыл бұрын

    I'm trying out Quad9 on my pi-hole. Thanks for the great review!

  • @brunoejb
    @brunoejb4 жыл бұрын

    This is great info! Will be doing something around it soon...

  • @podcaster_emeritus
    @podcaster_emeritus4 жыл бұрын

    Great video Tom. Thanks for the comparison.

  • @yajnalgibno6536
    @yajnalgibno65369 ай бұрын

    Would be nice to see this test ONCE every year. Thank you BTW for the effort of this video

  • @maokinus
    @maokinus4 жыл бұрын

    For some constructive feedback, it would be great to see the exact config used in each subscription or in an included writeup. Great that you reviewed some but not really complete if you don't do the same for all.

  • @sam_sheridan
    @sam_sheridan4 жыл бұрын

    Really useful great comparison

  • @ldnzz
    @ldnzz Жыл бұрын

    Catching this after 2 years. Wonder how much has changed in that time? And if OpenDNS is still so far behind?

  • @ldnzz
    @ldnzz9 ай бұрын

    Lawrence please can you redo this test. It would be hugely beneficial for everyone. Would nice to see how NextDNS ranks against newer ones such as control d. Etc.

  • @nickrafuse984
    @nickrafuse9844 жыл бұрын

    very nice, thanks for this

  • @doffpv1854
    @doffpv18544 жыл бұрын

    Not really surprise and i started to do this test some months ago ;) Thanks for sharing

  • @lamarchedutemps7427
    @lamarchedutemps7427 Жыл бұрын

    Quad9 all the way, great info ! :-) Subscribed

  • @TerryPullen
    @TerryPullen4 жыл бұрын

    I became a patron today. Thanks, Tom.

  • @LAWRENCESYSTEMS

    @LAWRENCESYSTEMS

    4 жыл бұрын

    Thank you

  • @Knaveofspades6
    @Knaveofspades6 Жыл бұрын

    Hello :-) is this still the same 3 years later? Be good to see an update. Love your videos.

  • @jgelliot
    @jgelliot4 жыл бұрын

    Looks like you missed an IP @ 3:12. You blurred one but missed the other

  • @JDSileo

    @JDSileo

    3 жыл бұрын

    shhhhhhh. Loose lips sink ships

  • @thoughtscribe
    @thoughtscribe4 жыл бұрын

    Very interesting comparison. I did notice that the portal your using for OpenDNS is the free version and not their paid tenant portal. Curious if there is a different level of protection between the 2.

  • @maokinus

    @maokinus

    4 жыл бұрын

    There are a lot more features included in Umbrella the enterprise DNS-Layer protection such as a selective proxy. Indeed this test does use the consumer edition which is OpenDNS branded not Umbrella. If you are curious to see some tests Umbrella the enterprise package check out these tests performed by AV-TEST www.av-test.org/fileadmin/pdf/reports/AV-TEST_DNS_Layer_Protection_Test_Feb_2020.pdf

  • @petethompson1282
    @petethompson1282 Жыл бұрын

    Time to do NextDNS /Cleanbrowsing in this mix and run it generally as a new update

  • @dhill835
    @dhill835 Жыл бұрын

    It would be cool to see an updated test again.

  • @michnl1772

    @michnl1772

    Жыл бұрын

    +1 every year audit

  • @knowbug
    @knowbug4 жыл бұрын

    Did you create an OpenDNS account and create a policy and associate your internet facing IP? By default it doesn't filter suspicious sites.

  • @JuanLopez-db4cc
    @JuanLopez-db4cc4 жыл бұрын

    Cheers from Florida!

  • @jkbobful
    @jkbobful3 жыл бұрын

    You should do another one of these

  • @bogdandubas3978
    @bogdandubas39784 жыл бұрын

    Good start, but I don't think that this test is representable enough. It is possible that Quad9 just happens to use that exact list for constructing block list. Or Quad9 could just concentrate on a specific part of malware domains that is represented in the list used for testing. All in all, this test only increases Quad9's chances to beat other services, but it is to early to state that it's so much better.

  • @StefanoVazzoler
    @StefanoVazzoler4 жыл бұрын

    Would be nice to see nextdns

  • @LAWRENCESYSTEMS

    @LAWRENCESYSTEMS

    4 жыл бұрын

    I did a test of NextDNS and posted the results in my forums. forums.lawrencesystems.com/t/dns-malware-filtering-compared-quad9-vs-cloudflare-vs-dns-filter-vs-opendns-cisco-umbrella/5072

  • @StefanoVazzoler

    @StefanoVazzoler

    4 жыл бұрын

    @@LAWRENCESYSTEMS thank you, I was gonna run it myself later today but you saved me a few minutes. Interesting results...

  • @jcnash02
    @jcnash024 жыл бұрын

    I’m wondering if more of the malware sites would have been blocked by dnsfilter if more categories were used...they might have them under other categories.

  • @LAWRENCESYSTEMS

    @LAWRENCESYSTEMS

    4 жыл бұрын

    Putting malware domains under any other category would not make any sense. I mean would they be under finance since some are ransomware?

  • @reaperhammer
    @reaperhammer2 жыл бұрын

    I don't think you have to sign up to opendns to use it for home use

  • @pedromain
    @pedromain9 ай бұрын

    This need an update. Its been 3 years already. If I may I wish to sugest getting Quad9, NextDNS and Coltrol D antimalware against each other. Cloudflare, Google, OpenDNS are a waste of time, they will be bad at the end anyway.

  • @sergioabrantes
    @sergioabrantes2 жыл бұрын

    it's time for a new video to update the results

  • @johnnybananas1497
    @johnnybananas14974 жыл бұрын

    I'm guessing quad9 comes out on top

  • @QuantumKurator
    @QuantumKurator4 жыл бұрын

    Can you please cover NextDNS?

  • @tomcapote

    @tomcapote

    4 жыл бұрын

    David Hartley Yes, THIS!

  • @LAWRENCESYSTEMS

    @LAWRENCESYSTEMS

    4 жыл бұрын

    I did a test of NextDNS and posted the results in my forums. forums.lawrencesystems.com/t/dns-malware-filtering-compared-quad9-vs-cloudflare-vs-dns-filter-vs-opendns-cisco-umbrella/5072

  • @tyro4416
    @tyro44166 ай бұрын

    Hi everytime i search for my primary and secondary DNS IP ADRESS i have 6 Malwares and i don’t know how to remove it, i have multiplie times searched for malwares on antivirus programs as Malwarebyte / F-Secure and Avast. They don’t find anything. But everytime i go to totalvirus i see my malwares. I need help to remove this please help me out.

  • @xugo91
    @xugo91 Жыл бұрын

    I wish there were something like quad9 but faster. Because I get a few issue in some game because of that

  • @AtikBayraktar
    @AtikBayraktar4 жыл бұрын

    I'm suspecting you didn't go thoroughly into settings for NextDNS. NextDNS has more security and privacy features, plus you select the blacklists yourself and there are many! It should just wipe out others in your test. edit: You also didn't go into advanced settings for OpenDNS? It logs you out and you didn't bother?

  • @ZeroGhostVR
    @ZeroGhostVR3 жыл бұрын

    Open dns is still faster than all in my area

  • @PhilWrightAU
    @PhilWrightAU10 ай бұрын

    Do you have an updated link to the list or a list of lists pf the rogue domains please?

  • @LAWRENCESYSTEMS

    @LAWRENCESYSTEMS

    10 ай бұрын

    no, because all the public lists are also in Quad9 and most other popular DNS systems.

  • @jcritch42
    @jcritch427 ай бұрын

    There is also MDBR & MDBR+ from CIS (Akamai)

  • @drydengeary6860
    @drydengeary68604 жыл бұрын

    Where’s WebTitan?

  • @vikashyadav1872
    @vikashyadav18724 жыл бұрын

    I'm confused which one to use!! Actually I need something that blocks malware, blocks antiphising, doesn't store ip address, deletes all history and does not save any users information. plz suggest me which one to use Quad9, Cloudflare or OpenWatch. Or some other dns which i don't know

  • @winsomenz

    @winsomenz

    3 жыл бұрын

    Use NextDNS or Quad9 if you need malware protection and privacy. Rest are just marketing DNS query farms.

  • @joelsantoro5221
    @joelsantoro52212 жыл бұрын

    Does someone knows secondary iPV4 adress of DNSFilter?

  • @Szydelski
    @Szydelski4 жыл бұрын

    Pi-Hole is a nice element in DNS filtering :).

  • @-----------------------------

    @-----------------------------

    4 жыл бұрын

    Can't use your pi hole outside your network unless you want to VPN into your network daily on a mobile device.

  • @vgamesx1

    @vgamesx1

    4 жыл бұрын

    Well you can't really use a cloud based DNS either without the use of an app, at least on android you have to change the DNS on each individual network and for the most part you can't change settings for your 3G/4G connection at all and technically you can use pi-hole outside, it's not as if port forwarding is hard you just need a good way to automatically update your IP but of course it generally isn't recommended opening your devices up to the internet, the alternative is using an app such as Netguard which creates a local VPN that allows your device to do its own filtering via hosts file, so again extra work to manually update the lists but otherwise the best option for filtering outside your network.

  • @TheElderOne2003

    @TheElderOne2003

    4 жыл бұрын

    @@----------------------------- I use it on my Note 8 daily without fail. Android has an option for private dns address to be input. Granted one vm instance of with pihole I use is dedicated only for off site devices.

  • @Szydelski

    @Szydelski

    4 жыл бұрын

    @@----------------------------- I'm not saying the pi-hole is ultimate solution for every issue. However I'm actually using solution you suggested.:)

  • @aricmayberry
    @aricmayberry4 жыл бұрын

    Looked like you were signed into an OpenDNS account and not Cisco Umbrella. The Umbrella dashboard is totally different. Cisco has made no improvements to the original OpenDNS service. I did similar testing with OpenDNS a few years back and actually found that the malware filtering was better without creating an account. When I created an account and provided my WAN IP malware was no longer filtered.

  • @jackripper8791

    @jackripper8791

    4 жыл бұрын

    It is not quite true but I worked for Umbrella and I'm not surprised with test results tbh.

  • @johnhanly2948

    @johnhanly2948

    4 жыл бұрын

    I would also be interested in how Cisco Umbrella does.

  • @maokinus

    @maokinus

    4 жыл бұрын

    @@johnhanly2948 Public results here for Cisco Umbrella www.av-test.org/fileadmin/pdf/reports/AV-TEST_DNS_Layer_Protection_Test_Feb_2020.pdf There is also a OpenDNS Prosumer package that provides the Umbrella dashboard to consumers with a limited feature set.

  • @ChrisBarrow1990
    @ChrisBarrow19904 жыл бұрын

    Does anyone know how pi hole compares to these?

  • @bren.r

    @bren.r

    3 жыл бұрын

    Pihole just sits in between your computer and a big name DNS resolver. If we want to talk about performance, clearly a local DNS server is superior. I personally use it to have network wide DOH resolutions.

  • @TwstedTV
    @TwstedTV3 жыл бұрын

    Wow so shocked that Cisco, the #1 networking security company in the world has lousy protection......LOL

  • @YazhShah
    @YazhShah4 жыл бұрын

    Nextdns is underrated

  • @LAWRENCESYSTEMS

    @LAWRENCESYSTEMS

    4 жыл бұрын

    I did a test of NextDNS and posted the results in my forums. forums.lawrencesystems.com/t/dns-malware-filtering-compared-quad9-vs-cloudflare-vs-dns-filter-vs-opendns-cisco-umbrella/5072

  • @Reepix
    @Reepix3 жыл бұрын

    Can someone please summarise? I'm confused, that's a lot info to process spoken really fast... so quad9 is safest?

  • @LAWRENCESYSTEMS

    @LAWRENCESYSTEMS

    3 жыл бұрын

    Just use Quad9

  • @Rick9814
    @Rick98144 жыл бұрын

    Does Quad9 block ads as well or just malware?

  • @DibyaK

    @DibyaK

    4 жыл бұрын

    If you want to block ads, and you are comfortable running your own services at home, then an excellent tool would be something like pi-hole, which you can setup to forward to Quad9.

  • @homemark22

    @homemark22

    4 жыл бұрын

    why not use adguard dns?

  • @bren.r

    @bren.r

    3 жыл бұрын

    @@homemark22 privacy

  • @homemark22

    @homemark22

    3 жыл бұрын

    @@bren.r Cares about your privacy Protecting your personal data is our top priority. With AdGuard, you and your sensitive data will be safe from any online tracker and analytics system that may attempt to steal your data while surfing the web. - that was from their website

  • @chuckhalo

    @chuckhalo

    2 жыл бұрын

    @@homemark22 yeah that doesn’t help

  • @mrf_71
    @mrf_71 Жыл бұрын

    Can you please make a video about RethinkDNS?

  • @LAWRENCESYSTEMS

    @LAWRENCESYSTEMS

    Жыл бұрын

    I don't use it or plan to. We use pfblocker and ublock.

  • @mrf_71

    @mrf_71

    Жыл бұрын

    @@LAWRENCESYSTEMS do you have a video on pfblocker?

  • @mrf_71

    @mrf_71

    Жыл бұрын

    @@LAWRENCESYSTEMS so if you don't use a product you won't make a video?

  • @LAWRENCESYSTEMS

    @LAWRENCESYSTEMS

    Жыл бұрын

    @@mrf_71 I don't have time to test every tool on the market so I pick ones that are interesting or complementing.

  • @catsdgs
    @catsdgs4 жыл бұрын

    Cloudflave?

  • @LAWRENCESYSTEMS

    @LAWRENCESYSTEMS

    4 жыл бұрын

    Hahha, thanks and fixed

  • @Mangold108
    @Mangold108 Жыл бұрын

    Ciao. MAke sense since I am using Surfshark VPN to use also Surfshark DNS? or it is no need? thanks

  • @LAWRENCESYSTEMS

    @LAWRENCESYSTEMS

    Жыл бұрын

    I still prefer Quad9, even when I am using a privacy VPN.

  • @Mangold108

    @Mangold108

    Жыл бұрын

    @@LAWRENCESYSTEMS huh! better then cloudflare?

  • @LAWRENCESYSTEMS

    @LAWRENCESYSTEMS

    Жыл бұрын

    I think so.

  • @shadow.banned
    @shadow.banned3 жыл бұрын

    You're telling me that Cloudflare let ALL of the malware through? Yeesh...

  • @petethompson1282
    @petethompson12823 жыл бұрын

    be nice if you checked the adult content filtering too... malware is one but family safety is another.

  • @Allltha8matters
    @Allltha8matters2 жыл бұрын

    Need 2022 comparison please

  • @LAWRENCESYSTEMS

    @LAWRENCESYSTEMS

    2 жыл бұрын

    Still using Quad9

  • @Allltha8matters

    @Allltha8matters

    2 жыл бұрын

    @@LAWRENCESYSTEMS quad9 is too slow here in India/Asia, and cloudflare zero trust DNS filtering seems to be improved a lot. so a new 2022 comparison video would be awesome

  • @swiftypopty1102

    @swiftypopty1102

    Жыл бұрын

    @@Allltha8matters It's work just fine for me in SEA

  • @Kingpingamer
    @Kingpingamer5 ай бұрын

    this video need a 2024 update

  • @LAWRENCESYSTEMS

    @LAWRENCESYSTEMS

    5 ай бұрын

    There is a new version here kzread.info/dash/bejne/gImIlq1spM6fftY.html

  • @robertstan7243
    @robertstan72434 жыл бұрын

    Only 1 issue with your videos: you talk too fast and a lot of words are not understandable by me or by the auto subtitle. Please, slow down just 5% and try to pronounce every at least technical word correctly. Love ya

  • @clausdk6299
    @clausdk62994 жыл бұрын

    Your methodology might give a lot of wrong results. Using "dig" will not always give the right IP. Many malware sites have a low TTL on their A records and change the IP multiple times. Also sometimes they use Cloudflare first > and send the user to another site/IP afterwards. And as we know Cloudflare is awesome if you want to host malware sites, since Cloudflare rarely blocks sites or take them down.

  • @clausdk6299

    @clausdk6299

    4 жыл бұрын

    I wonder how many of those IP's belongs to Cloudflare....

  • @maokinus

    @maokinus

    4 жыл бұрын

    @@clausdk6299 Good point @8:15 the results show around line 16 or 17 IP address 146.112.61.108. The entire address block of 146.112.0.0 is registered to Cisco Umbrella. talosintelligence.com/reputation_center/lookup?search=146.112.61.108

  • @rjnickolparmar4214
    @rjnickolparmar42143 жыл бұрын

    talk less show more performance... don't talk walk the talk