A private DNS for a cleaner digital experience.

Encrypted, fast, and built with privacy in mind. Our resolver blocks 1,479,825+ domains associated with ads, trackers, malware, phishing, and adult content.

Encrypted DNS
Ad Blocking
Malware Blocking
Tracker Blocking
Phishing Blocking
Gambling Blocking
27.49M queries served
2.44M threats blocked
01 · Endpoints

Choose a Transport Protocol

Encrypted protocols are strongly recommended for maximum privacy.

DNS-over-TLS

DoT

Use a TLS connection to keep your DNS secure.

DNS-over-HTTPS

DoH

Port 443 with HTTP/2 for fast lookups, bypassing ISP blocks.

DNS Server

Plain

Unencrypted DNS (port 53) for universal compatibility.

02 · Filtering

What gets filtered

One profile for everyone. There is no separate family endpoint to remember.

Family safe by default

Pornography, adult and gambling sites are refused for every device pointed at this resolver, alongside malware, phishing and the usual advertising and tracking. It is not an optional mode and there is no setting to turn it on — plug in the address and the filtering is already there.

Counts are the domains each source list contributes to the store, live from the resolver. Blocklists were last rebuilt 4h 30m ago.

Where it stops

Worth being straight about, because this is the part people rely on most:

Something slipping through, or something harmless caught by mistake? Tell me and the lists get adjusted.

Blocklist Sources

6 sources · auto-updated
03 · Check Domain

Domain & DNS Tools

Check blocklist status or run a live DNS query.

$
Try: · ·
04 · Live Traffic

What the resolver is doing right now

Queries / sec 26.8 peak 111 · 60s window
Cache hit 24.8% 17.2K entries cached
Median latency 74.2 ms last 10k queries
Resolver load 2.20% 197 MB resident

Throughput / queries per second

up down last 6 min
0.0 +0.00%
O — H — L — C —
-6m-4m-2mnow

Transport mix / 24h

27.35M queries
DNS over HTTPS13.93M 50.9%
DNS over TLS7.68M 28.1%
DNS over QUIC4.78M 17.5%
Plain DNS · UDP953.6K 3.5%
Plain DNS · TCP5,530 0.0%
Encrypted 96.5% Plain DNS 3.5%

Upstream Health

leastOutstanding
primary-v4-aPRIMARY
191 ms5.64 q/s3.54M
primary-v4-bPRIMARY
215 ms5.47 q/s3.48M
primary-v6PRIMARY
189 ms7.71 q/s5.74M
local-unboundPRIMARY
219 ms2.99 q/s5.61M
fallback-quad9FALLBACK
0.00 ms0.00 q/s0
fallback-cloudflareFALLBACK
0.00 ms0.00 q/s0

Block log / recent

blocking
Time Domain Transport Record Action
Demo data · last 5 events · refreshes every 3s
05 · Setup

Setup

Two minutes, no software to install.

Android 9+ · DNS-over-TLS, system-wide

  1. Open Settings → Network & internet → Private DNS (Samsung: Settings → Connections → More connection settings → Private DNS).
  2. Select Private DNS provider hostname.
  3. Enter dns.aixxycode.id and tap Save.

Android resolves this over DNS-over-TLS on port 853 and accepts a hostname only — an IP address will be rejected.

Verify it works

dig +short @103.42.245.56 doubleclick.net
# 0.0.0.0  → filtering is active

kdig -d +tls @dns.aixxycode.id example.com
# TLS handshake succeeded → DoT is working
06 · Network

Network & Points of Presence

Anycast nodes across the region, with live round-trip latency.

Your Resolver · Live

Which node serves you?

Your IP—
Network (ASN)—
Location—
Serving PoP—

Detecting your network…

§ Route Sheet

Jakarta → Singapore

6.21°S 106.85°E  ·  1.34°N 103.91°E
≈ 880 km 0° EQUATOR Jakarta IDN · JKT 4 ms Singapore SGP · SIN 18 ms
07 · Infrastructure

Infrastructure

Tier 1 Network

Our network consists of the highest quality Tier-1 providers, including Tata Communications, RETN, Orange, Softbank, IIJ, GSL, China Telecom, China Unicom, China Mobile and over 2,000 IX peers.

99.99% Network Uptime

We are proud to guarantee a solid, reliable and proven 99.99% network uptime on all servers.

Low Latency for Local Users

Closer nodes mean faster data. Our Indonesian nodes cut the distance versus servers in Singapore or the US, so sites feel more responsive. Jakarta to a local datacenter averages 1-5 ms, versus 15-30 ms to Singapore and 200 ms+ to the US.

Direct Links to Local Internet Exchanges

Our Indonesian nodes peer directly with IIX, OpenIXP, JKT-IX, BIX, EPIX and other local exchanges. Traffic from Indonesian visitors stays on faster domestic routes instead of detouring abroad - unlike servers in Singapore or elsewhere, where it must cross international links first.

08 · Info

Information

Frequently Asked Questions

Why is a domain blocked?

Domains are blocked if they appear on one of the public blocklists we aggregate (OISD, Hagezi, StevenBlack, Firebog, 1Hosts, and others). These lists target advertising, tracking, malware, phishing, gambling, and adult content. If a domain is incorrectly blocked, please contact us to review and adjust the lists.

How can I whitelist a domain?

There is no self-service whitelist at this time. If a legitimate domain is incorrectly blocked, send an email to hi@aixxycode.id with the domain name and the blocklist that flagged it. We will review and adjust the lists accordingly.

What is DNS-over-HTTPS (DoH)?

DNS-over-HTTPS (DoH) encrypts DNS queries inside regular HTTPS traffic on port 443. This prevents eavesdropping and manipulation by ISPs or attackers. It also makes DNS lookups indistinguishable from other web traffic, improving privacy. DoH is supported by all modern browsers and operating systems.

Do you keep logs of my queries?

No. We do not store query logs or link your lookups to any user or IP address. Only anonymous aggregate counters, such as total queries, cache hit rate and latency, are kept for capacity planning and shown on this page. Your browsing history stays yours.

Which devices and protocols are supported?

Any device that can use a custom DNS works: Android, iOS, Windows, macOS and Linux, plus routers and browsers. Prefer DoH or DoT for encryption, and use plain DNS (port 53) only on older devices. See the Setup section above for step-by-step instructions.

09 · House Rules

House Rules

No query logs

Queries are answered and forgotten. Only aggregate counters — the ones on this page — are kept.

Filtered, not censored

The blocklist targets advertising, telemetry, phishing and malware. Nothing political, nothing editorial.

Best effort

Run by one person on one box. It is stable, but it carries no SLA — do not put a hospital on it.

Fair use

Rate limits apply per source address. Bulk scanning and amplification attempts are dropped at the edge.

10 · Partnership

Partnership & Sponsorship

Interested in collaborating with aixxy-dns? We are open to infrastructure partnerships, sponsorships, and joint projects. Whether you run a network, a community, or a service that aligns with a faster and safer internet, let's talk.

hi@aixxycode.id
Copied to clipboard!