# DNS-over-HTTPS / DNS-over-TLS resolver endpoints.
# These are ALWAYS sinkholed (regardless of category) so a browser can't be
# pointed at a remote encrypted resolver to tunnel DNS around /etc/hosts. This is
# the network-layer backstop to the browser policy files written by policies.py.
# Not expanded with subdomains – exact endpoint hostnames only.

# Cloudflare
cloudflare-dns.com
mozilla.cloudflare-dns.com
chrome.cloudflare-dns.com
security.cloudflare-dns.com
family.cloudflare-dns.com
odoh.cloudflare-dns.com
one.one.one.one

# Google
dns.google
dns.google.com
dns64.dns.google

# Quad9
dns.quad9.net
dns9.quad9.net
dns10.quad9.net
dns11.quad9.net

# NextDNS / ControlD
dns.nextdns.io
dns.controld.com
freedns.controld.com

# OpenDNS / Cisco
doh.opendns.com
doh.familyshield.opendns.com

# CleanBrowsing
doh.cleanbrowsing.org

# AdGuard
dns.adguard.com
dns-family.adguard.com
dns-unfiltered.adguard.com
dns.adguard-dns.com

# Mullvad
doh.mullvad.net
dns.mullvad.net

# Misc public resolvers
doh.dns.sb
dns.sb
doh.libredns.gr
doh.tiar.app
dns.alidns.com
doh.pub
ordns.he.net
doh.ffmuc.net
dns.switch.ch
doh.digitalcourage.de
dns.digitale-gesellschaft.ch
