DNS Service
Hixbe provides a comprehensive, secure DNS service offering standard DNS resolution, advanced content filtering, and multiple encrypted DNS protocols. Our enterprise-grade DNS infrastructure ensures fast, reliable, and secure domain name resolution with built-in threat protection and privacy features.Server Details
- Primary Server:
dns.hixbe.com - Secondary Server:
dns2.hixbe.com - Technology: Enterprise-grade DNS infrastructure
- Location: Global (multiple geographic locations)
- Protocols: DNS, DoH, DoT, DoQ
- Security: End-to-end encryption, DNSSEC validation, threat intelligence
Security Features
Advanced Threat Protection
Our DNS service includes multiple layers of security:- Real-time Malware Blocking: Blocks access to known malicious domains
- Phishing Protection: Prevents users from accessing fraudulent websites
- Botnet Detection: Identifies and blocks command-and-control servers
- Zero-Day Threat Intelligence: Integration with global threat feeds
- DNSSEC Validation: Cryptographic verification of DNS responses
Privacy & Encryption
- DNS over HTTPS (DoH): Encrypts all DNS queries using HTTPS
- DNS over TLS (DoT): Provides TLS-encrypted DNS resolution
- DNS over QUIC (DoQ): Ultra-fast encrypted DNS using QUIC protocol
- No Query Logging: Minimal logging with automatic anonymization
- GDPR Compliant: Strict privacy controls and data protection
Performance & Reliability
- Anycast Routing: Global network with optimized routing paths
- 99.9% Uptime SLA: Guaranteed high availability
- Sub-millisecond Response Times: Optimized for speed
- Automatic Failover: Seamless redundancy across multiple data centers
- IPv4/IPv6 Dual Stack: Full support for both protocol versions
DNS Services
Standard DNS (Port 53)
Basic DNS resolution without filtering, providing fast and secure domain name resolution. Server Addresses:- IPv4:
165.101.132.104(primary),165.101.132.105(secondary) - IPv6:
2001:4860:7:402::fd(primary),2001:4860:7:412::fd(secondary)
Malware-Only Filtering (Port 54)
Blocks malware domains while allowing adult content, providing essential security without content restrictions. Server Addresses:- IPv4:
165.101.132.104(primary),165.101.132.105(secondary) - IPv6:
2001:4860:7:402::fd(primary),2001:4860:7:412::fd(secondary)
- Real-time malware domain blocking
- Phishing site protection
- Botnet command-and-control server blocking
- Known malicious host prevention
- Zero-day threat detection
Malware + Adult Content Filtering (Port 55)
Blocks both malware and adult content, providing comprehensive protection for sensitive environments. Server Addresses:- IPv4:
165.101.132.104(primary),165.101.132.105(secondary) - IPv6:
2001:4860:7:402::fd(primary),2001:4860:7:412::fd(secondary)
- All malware protection from port 54
- Adult content website blocking
- Gambling site restrictions
- Pornographic content filtering
- Comprehensive threat intelligence
Encrypted DNS
DNS over HTTPS (DoH)
Secure DNS queries over HTTPS protocol. Endpoint:https://dns.hixbe.com/dns-query
Configuration:
Firefox:
- Go to
about:config - Set
network.trr.uritohttps://dns.hixbe.com/dns-query - Set
network.trr.modeto2(or3for TRR-only)
DNS over TLS (DoT)
Secure DNS queries over TLS protocol. Server:dns.hixbe.com:853
Configuration:
Linux (systemd-resolved):
- Go to Settings → Network & Internet → Advanced → Private DNS
- Select “Private DNS provider hostname”
- Enter:
dns.hixbe.com
- Go to Settings → Wi-Fi → [Network Name]
- Configure DNS → Manual
- Add DNS server:
165.101.132.104 - Enable DNS over TLS
DNS over QUIC (DoQ)
Ultra-fast DNS queries over QUIC protocol. Server:dns.hixbe.com:784
Note: DoQ support depends on client compatibility. Currently supported by some DNS clients and applications.
Programming Integration
Python
Node.js
Go
Threat Intelligence & Filtering
Advanced Malware Protection
Our DNS service employs enterprise-grade threat intelligence to protect against various cyber threats:- Global Threat Feeds: Integration with leading cybersecurity intelligence providers
- Real-time Updates: Blocklists updated every 15 minutes with latest threats
- Machine Learning: AI-powered detection of emerging threats
- Zero-Day Protection: Proactive blocking of unknown malicious domains
- Cryptojacking Prevention: Blocks cryptocurrency mining malware
Content Security Filtering
For environments requiring content restrictions:- Malware Categories: Viruses, trojans, ransomware distribution sites
- Phishing Domains: Fake login pages and credential harvesting sites
- Botnet Infrastructure: Command-and-control servers and malware hosting
- Exploit Kits: Sites distributing browser and system exploits
- Malicious Downloads: Sites hosting infected files and executables
Adult Content Protection
Comprehensive filtering for sensitive environments:- Pornographic Content: Adult entertainment and explicit material
- Gambling Platforms: Online casinos and betting websites
- Adult Services: Escort services and adult-oriented businesses
- Explicit Media: Sites hosting adult videos and images
Security Response
- Immediate Blocking: New threats blocked within minutes of detection
- NXDOMAIN Responses: Clean blocking without revealing filtering
- Audit Logging: Comprehensive logging for security analysis
- False Positive Handling: Quick resolution of incorrectly blocked domains
- Community Reporting: User-submitted threat intelligence integration
Performance & Reliability
Speed Optimizations
- Anycast Routing: Global network with optimized routing
- Caching: Intelligent DNS caching with TTL respect
- CDN Integration: Fast resolution for popular domains
- IPv6 Support: Full IPv6 compatibility
Uptime & Monitoring
- 99.9% Uptime SLA: Guaranteed high availability
- Global Monitoring: 24/7 monitoring from multiple locations
- Automatic Failover: Seamless switching between servers
- Performance Metrics: Real-time speed and reliability stats
Best Practices
For Applications
- Use Appropriate Filtering: Choose the right filtering level for your use case
- Implement Fallbacks: Always have secondary DNS servers configured
- Monitor Resolution Times: Track DNS query performance
- Handle NXDOMAIN: Properly handle blocked domain responses
For Networks
- Split DNS: Use different servers for different network segments
- Conditional Forwarding: Forward internal domains to local DNS
- DNSSEC Validation: Enable DNSSEC for enhanced security
- Rate Limiting: Implement query rate limits for protection
Security Considerations
- Use Encrypted DNS: Prefer DoH/DoT over plain DNS
- Monitor for Anomalies: Watch for unusual query patterns
- Regular Updates: Keep DNS configurations current
- Access Controls: Restrict DNS server access when possible
Troubleshooting
Common Issues
“DNS server not responding”:- Check network connectivity
- Verify firewall settings (ports 53, 853, 443)
- Try alternative DNS servers
- Clear DNS cache:
ipconfig /flushdns(Windows) orsudo systemd-resolve --flush-caches(Linux) - Check if domain is blocked by filtering
- Verify DNS server configuration
- Test with different DNS servers
- Check network latency to DNS servers
- Verify DNS caching is working
Diagnostic Commands
Test DNS resolution:API Access
For programmatic access to DNS data:Terms of Service
- Free Usage: DNS service provided free of charge
- Fair Usage: Reasonable query limits apply
- No SLA: Service provided “as is” without guarantee
- Logging: Queries may be logged for service improvement
- No Warranty: Service provided without warranty
Support
For DNS service support:- Email: support@hixbe.com
- Status Page:
https://status.hixbe.com/dns - Documentation: Additional guides available
- Community: Join our developer community
DNS over HTTPS
DoH Protocol Specification
DNS over TLS
DoT Protocol Specification
DNSSEC
DNS Security Extensions
DNS Security
DNS Security Best Practices