HaGeZi DNS: Free, Non-Commercial EU Public DNS Servers
Python
584
1 commits
updated Oct 3, 2026
HaGeZi DNS offers free, non-commercial public DNS resolvers designed and operated by a private individual for the European community. It provides robust DNS-based blocking of ads, trackers, scam, phishing, fake, and malware domains, helping users achieve greater privacy and security online at zero cost.
[!NOTE] This document covers technical setup and usage. For the full privacy policy, EU/Digital Services Act (DSA) compliance disclosure, and the glossary of legal terms, see PRIVACY.
version.bind and id.server queries are refused for security hardening.[!NOTE] IP-based blocklists (used for firewall-level abuse prevention) may occasionally contain false positives. If you believe your IP is being blocked incorrectly, contact support@hagezi.org, or reach the operator privately via Matrix or Signal. Please use one of these rather than the public support chat, since sorting out an IP block means sharing your IP address. See PRIVACY for the legal basis of this processing.
HaGeZi DNS employs a balanced blocking strategy to deliver robust privacy and security while minimizing unnecessary restrictions. It offers effective protection without excessive blocking, making it ideal for most users. This balance is achieved with the following blocklists:
| Blocklist | Link | Blocks |
|---|---|---|
| HaGeZi Multi Pro | Link | Ads, tracking, analytics, metrics, telemetry |
| HaGeZi TIF (Threat Intelligence Feeds) | Link | Phishing, malware, scam, fake, cryptojacking |
Blocklists are regenerated every 4 hours and updated on the servers immediately afterward.
[!IMPORTANT] No intentional censorship beyond privacy, ad, and security filtering. If a domain seems to be blocked incorrectly, or you believe a domain should be blocked, submit a report via the blocklist repository's issue tracker or contact support@hagezi.org. You can also use the official public Matrix support chat. See PRIVACY for the full content-moderation and DSA compliance disclosure.
[!NOTE] A separate DNS server is available that uses only the HaGeZi TIF list, blocking exclusively phishing, malware, scam, fake, cryptojacking, and other harmful domains.
0.0.0.0. Blocked domains resolve to 0.0.0.0 instead of REFUSED/NXDOMAIN or 127.0.0.1, so connections fail immediately without local timeouts or retries in many apps, reducing unnecessary traffic.NXDOMAIN: this signals to Firefox that the network already applies DNS filtering, so Firefox does not switch on its own DNS-over-HTTPS by itself and your queries keep reaching this resolver. It affects automatic activation only. If you have deliberately enabled DoH in Firefox's settings, that choice is respected and Firefox will keep using the provider configured there instead of this one.NXDOMAIN: applies DNS filtering to resources preloaded via Chrome's private prefetch proxy.stats.txt file described below. That file contains totals and rankings only, with no client IP addresses and no per-client data, and it is overwritten on every update. No web server access logs are kept for it.SERVFAIL) are logged. Entries are retained for 24 hours for troubleshooting purposes on the legal basis of Art. 6(1)(f) GDPR (legitimate interest in service reliability), and no client IP addresses are stored.The following links provide server health status and a simplified overview of hourly statistics, including queries, blocked queries, clients, and other metrics. Each file is regenerated every 5 minutes from the server's in-memory statistics, so figures can be up to 5 minutes old:
root.hagezi.org · wurzn.hagezi.org · juuri.hagezi.org · ctif.hagezi.org
Servers are accessible via encrypted DNS protocols, including DNS-over-HTTPS/3 (DoH/DoH3), DNS-over-TLS (DoT), and DNS-over-QUIC (DoQ), as well as unencrypted DNS over port 53 (Do53). Whenever possible, use DoH or DoH3.
[!WARNING] Clients that use multiple encrypted DNS protocols simultaneously (e.g., DoH, DoT, and DoQ) against the same server may resolve the same domain in parallel multiple times, unnecessarily exhausting rate limits. There is no practical benefit to using all encrypted protocols at once; it only wastes resources.
[!NOTE] Connections from Tor exit nodes are blocked on all servers and protocols, including Do53, due to persistent attack traffic observed from that network.
[!NOTE] On the naming: the three full-protection servers are all called "root", once per location.
rootis English,wurznis the Franconian dialect spoken around Nuremberg, andjuuriis Finnish.ctifbreaks the pattern and stands for Cyber Threat Intelligence Feed, after the list it runs on.
These servers block ads, tracking, analytics, metrics, and telemetry in addition to phishing, malware, scam, fake, and cryptojacking domains.
| Location | Protocols | Endpoint/URL | Apple Config | Recommended for |
|---|---|---|---|---|
| Germany, Falkenstein | DoH/DoH3 | https://root.hagezi.org/dns-query | Link · QR | AT, BA, BE, BG, CH, CZ, DE, DK, FR, GB, HU, IE, IT, LU, NL, PL, RO, SI, SK |
| DoT/DoQ | root.hagezi.org | |||
| Do53 | 188.34.161.2102a01:4f8:c17:1c66::1 | |||
| Germany, Nuremberg | DoH/DoH3 | https://wurzn.hagezi.org/dns-query | Link · QR | AT, BA, BE, BG, CH, CZ, DE, DK, ES, FR, GB, GR, HR, HU, IE, IT, LU, MD, MK, MT, NL, PL, PT, RO, RS, SI, SK, TR, UA |
| DoT/DoQ | wurzn.hagezi.org | |||
| Do53 | 159.69.155.942a01:4f8:1c1c:d363::1 | |||
| Finland, Helsinki | DoH/DoH3 | https://juuri.hagezi.org/dns-query | Link · QR | DK, EE, FI, LT, LV, NO, SE |
| DoT/DoQ | juuri.hagezi.org | |||
| Do53 | 95.217.163.172a01:4f9:c013:dc4e::1 |
This server blocks only phishing, malware, scam, fake, cryptojacking, and other harmful domains, without ad or tracker blocking.
| Location | Protocols | Endpoint/URL | Apple Config | Recommended for |
|---|---|---|---|---|
| Germany, Nuremberg | DoH/DoH3 | https://ctif.hagezi.org/dns-query | Link · QR | AT, BA, BE, BG, CH, CZ, DE, DK, ES, FR, GB, GR, HR, HU, IE, IT, LU, MD, MK, MT, NL, PL, PT, RO, RS, SI, SK, TR, UA |
| DoT/DoQ | ctif.hagezi.org | |||
| Do53 | 162.55.58.402a01:4f8:1c19:6c19::1 |
EU and neighboring countries with limited coverage from current server locations: AD, CY, GE, IS, LI, MC, ME, SM.
[!NOTE] Encrypted DNS Stamps let compatible tools connect to HaGeZi DNS automatically, with all needed connection details built in.
| Endpoint | Protocol : DNS Stamp |
|---|---|
root.hagezi.org | DoH: sdns://AgMAAAAAAAAADjE4OC4zNC4xNjEuMjEwAA9yb290LmhhZ2V6aS5vcmcKL2Rucy1xdWVyeQ |
DoT: sdns://AwMAAAAAAAAADjE4OC4zNC4xNjEuMjEwAA9yb290LmhhZ2V6aS5vcmc | |
DoQ: sdns://BAMAAAAAAAAADjE4OC4zNC4xNjEuMjEwAA9yb290LmhhZ2V6aS5vcmc | |
wurzn.hagezi.org | DoH: sdns://AgMAAAAAAAAADTE1OS42OS4xNTUuOTQAEHd1cnpuLmhhZ2V6aS5vcmcKL2Rucy1xdWVyeQ |
DoT: sdns://AwMAAAAAAAAADTE1OS42OS4xNTUuOTQAEHd1cnpuLmhhZ2V6aS5vcmc | |
DoQ: sdns://BAMAAAAAAAAADTE1OS42OS4xNTUuOTQAEHd1cnpuLmhhZ2V6aS5vcmc | |
juuri.hagezi.org | DoH: sdns://AgMAAAAAAAAADTk1LjIxNy4xNjMuMTcAEGp1dXJpLmhhZ2V6aS5vcmcKL2Rucy1xdWVyeQ |
DoT: sdns://AwMAAAAAAAAADTk1LjIxNy4xNjMuMTcAEGp1dXJpLmhhZ2V6aS5vcmc | |
DoQ: sdns://BAMAAAAAAAAADTk1LjIxNy4xNjMuMTcAEGp1dXJpLmhhZ2V6aS5vcmc |
| Endpoint | Protocol : DNS Stamp |
|---|---|
ctif.hagezi.org | DoH: sdns://AgMAAAAAAAAADDE2Mi41NS41OC40MAAPY3RpZi5oYWdlemkub3JnCi9kbnMtcXVlcnk |
DoT: sdns://AwMAAAAAAAAADDE2Mi41NS41OC40MAAPY3RpZi5oYWdlemkub3Jn | |
DoQ: sdns://BAMAAAAAAAAADDE2Mi41NS41OC40MAAPY3RpZi5oYWdlemkub3Jn |
[!TIP] For a general idea of the latency between your location and our server locations, use WonderNetwork's Global Ping Statistics.
Example WonderNetwork compilation configured for Germany:
To optimize latency, personally measure the response times by pinging each DNS server from your own connection. This factors in your specific network conditions, such as geographic location, ISP routing, and local congestion, giving you a practical, real-world latency measurement. Selecting the server with the lowest ping time maximizes responsiveness and reduces DNS query delays.
Use the provided test scripts to measure actual DNS resolution times (beyond simple ICMP latency), evaluating how quickly each server resolves domain queries in practice:
./dnsperftest.sh
Latency cheat sheet (PDF): summarizes measured network latency in milliseconds from six European PoPs (Amsterdam, Falkenstein, Frankfurt, Helsinki, Nürnberg, Vienna) to cities across European countries, highlighting the fastest location per city and EU membership status, based on WonderNetwork ping data.
DNS resolution reference values (ms):
| DNS resolve/lookup time (ms) | Rating | What it usually means |
|---|---|---|
| < 20 | Excellent | Very fast response, often due to a nearby resolver and/or a warm cache. |
| 20-50 | Very good | Common target range for good user experience. |
| 50-100 | OK | Usually fine, but can add noticeable delay if a page triggers many lookups. |
| 100-120 | Average | Often cited as the upper end of "average" DNS lookup time. |
| 120-200 | Slow | Suggests distance, routing/latency, resolver load, or extra resolution steps. |
| > 200 | Very slow / problematic | Frequently indicates a real performance or reachability issue (retries, timeouts, overload). |
188.34.161.210 / 2a01:4f8:c17:1c66::1 (PTR: root.hagezi.org), Hetzner Online GmbH, Falkenstein, Saxony, DE159.69.155.94 / 2a01:4f8:1c1c:d363::1 (PTR: wurzn.hagezi.org), Hetzner Online GmbH, Nürnberg, Bavaria, DE95.217.163.17 / 2a01:4f9:c013:dc4e::1 (PTR: juuri.hagezi.org), Hetzner Online GmbH/HOS-GUN, Helsinki, Uusimaa, FI162.55.58.40 / 2a01:4f8:1c19:6c19::1 (PTR: ctif.hagezi.org), Hetzner Online GmbH, Nürnberg, Bavaria, DEIf a DNS leak test shows IP addresses other than these, your device or network might be leaking DNS queries through fallback resolvers or directly to your ISP. This means requests are bypassing your intended DNS protection and potentially exposing your browsing activity.
Contact support@hagezi.org for support and questions. You can also use the official public Matrix support chat, or contact the operator directly via Matrix or Signal.
NXDOMAIN answer signals that it does, so the client does not switch on its own DNS provider automatically.version.bind or id.server; disabling it prevents attackers from identifying the server software or instance.sdns://) that bundles a DNS server's address, protocol, and public key information so compatible client software can configure a connection automatically.ping to measure basic network round-trip time; it measures raw network latency only, not actual DNS query resolution time.NXDOMAIN (domain does not exist) and SERVFAIL (resolution error).[!NOTE] Legal and regulatory terms (GDPR, DSA, ENISA, and related concepts) are defined in the Glossary in PRIVACY.
This document covers technical setup and usage only. The full disclaimer, EU privacy policy, Digital Services Act (DSA) content-moderation compliance information, and a glossary of legal terms are maintained in a separate document: PRIVACY.
282 followers · starred Sep 2026
16 followers · starred Jun 2026
38 followers · starred Jun 2026
4 followers · starred May 2026
HaGeZi DNS: Free, Non-Commercial EU Public DNS Servers
Python
584
1 commits
updated Oct 3, 2026
HaGeZi DNS offers free, non-commercial public DNS resolvers designed and operated by a private individual for the European community. It provides robust DNS-based blocking of ads, trackers, scam, phishing, fake, and malware domains, helping users achieve greater privacy and security online at zero cost.
[!NOTE] This document covers technical setup and usage. For the full privacy policy, EU/Digital Services Act (DSA) compliance disclosure, and the glossary of legal terms, see PRIVACY.
version.bind and id.server queries are refused for security hardening.[!NOTE] IP-based blocklists (used for firewall-level abuse prevention) may occasionally contain false positives. If you believe your IP is being blocked incorrectly, contact support@hagezi.org, or reach the operator privately via Matrix or Signal. Please use one of these rather than the public support chat, since sorting out an IP block means sharing your IP address. See PRIVACY for the legal basis of this processing.
HaGeZi DNS employs a balanced blocking strategy to deliver robust privacy and security while minimizing unnecessary restrictions. It offers effective protection without excessive blocking, making it ideal for most users. This balance is achieved with the following blocklists:
| Blocklist | Link | Blocks |
|---|---|---|
| HaGeZi Multi Pro | Link | Ads, tracking, analytics, metrics, telemetry |
| HaGeZi TIF (Threat Intelligence Feeds) | Link | Phishing, malware, scam, fake, cryptojacking |
Blocklists are regenerated every 4 hours and updated on the servers immediately afterward.
[!IMPORTANT] No intentional censorship beyond privacy, ad, and security filtering. If a domain seems to be blocked incorrectly, or you believe a domain should be blocked, submit a report via the blocklist repository's issue tracker or contact support@hagezi.org. You can also use the official public Matrix support chat. See PRIVACY for the full content-moderation and DSA compliance disclosure.
[!NOTE] A separate DNS server is available that uses only the HaGeZi TIF list, blocking exclusively phishing, malware, scam, fake, cryptojacking, and other harmful domains.
0.0.0.0. Blocked domains resolve to 0.0.0.0 instead of REFUSED/NXDOMAIN or 127.0.0.1, so connections fail immediately without local timeouts or retries in many apps, reducing unnecessary traffic.NXDOMAIN: this signals to Firefox that the network already applies DNS filtering, so Firefox does not switch on its own DNS-over-HTTPS by itself and your queries keep reaching this resolver. It affects automatic activation only. If you have deliberately enabled DoH in Firefox's settings, that choice is respected and Firefox will keep using the provider configured there instead of this one.NXDOMAIN: applies DNS filtering to resources preloaded via Chrome's private prefetch proxy.stats.txt file described below. That file contains totals and rankings only, with no client IP addresses and no per-client data, and it is overwritten on every update. No web server access logs are kept for it.SERVFAIL) are logged. Entries are retained for 24 hours for troubleshooting purposes on the legal basis of Art. 6(1)(f) GDPR (legitimate interest in service reliability), and no client IP addresses are stored.The following links provide server health status and a simplified overview of hourly statistics, including queries, blocked queries, clients, and other metrics. Each file is regenerated every 5 minutes from the server's in-memory statistics, so figures can be up to 5 minutes old:
root.hagezi.org · wurzn.hagezi.org · juuri.hagezi.org · ctif.hagezi.org
Servers are accessible via encrypted DNS protocols, including DNS-over-HTTPS/3 (DoH/DoH3), DNS-over-TLS (DoT), and DNS-over-QUIC (DoQ), as well as unencrypted DNS over port 53 (Do53). Whenever possible, use DoH or DoH3.
[!WARNING] Clients that use multiple encrypted DNS protocols simultaneously (e.g., DoH, DoT, and DoQ) against the same server may resolve the same domain in parallel multiple times, unnecessarily exhausting rate limits. There is no practical benefit to using all encrypted protocols at once; it only wastes resources.
[!NOTE] Connections from Tor exit nodes are blocked on all servers and protocols, including Do53, due to persistent attack traffic observed from that network.
[!NOTE] On the naming: the three full-protection servers are all called "root", once per location.
rootis English,wurznis the Franconian dialect spoken around Nuremberg, andjuuriis Finnish.ctifbreaks the pattern and stands for Cyber Threat Intelligence Feed, after the list it runs on.
These servers block ads, tracking, analytics, metrics, and telemetry in addition to phishing, malware, scam, fake, and cryptojacking domains.
| Location | Protocols | Endpoint/URL | Apple Config | Recommended for |
|---|---|---|---|---|
| Germany, Falkenstein | DoH/DoH3 | https://root.hagezi.org/dns-query | Link · QR | AT, BA, BE, BG, CH, CZ, DE, DK, FR, GB, HU, IE, IT, LU, NL, PL, RO, SI, SK |
| DoT/DoQ | root.hagezi.org | |||
| Do53 | 188.34.161.2102a01:4f8:c17:1c66::1 | |||
| Germany, Nuremberg | DoH/DoH3 | https://wurzn.hagezi.org/dns-query | Link · QR | AT, BA, BE, BG, CH, CZ, DE, DK, ES, FR, GB, GR, HR, HU, IE, IT, LU, MD, MK, MT, NL, PL, PT, RO, RS, SI, SK, TR, UA |
| DoT/DoQ | wurzn.hagezi.org | |||
| Do53 | 159.69.155.942a01:4f8:1c1c:d363::1 | |||
| Finland, Helsinki | DoH/DoH3 | https://juuri.hagezi.org/dns-query | Link · QR | DK, EE, FI, LT, LV, NO, SE |
| DoT/DoQ | juuri.hagezi.org | |||
| Do53 | 95.217.163.172a01:4f9:c013:dc4e::1 |
This server blocks only phishing, malware, scam, fake, cryptojacking, and other harmful domains, without ad or tracker blocking.
| Location | Protocols | Endpoint/URL | Apple Config | Recommended for |
|---|---|---|---|---|
| Germany, Nuremberg | DoH/DoH3 | https://ctif.hagezi.org/dns-query | Link · QR | AT, BA, BE, BG, CH, CZ, DE, DK, ES, FR, GB, GR, HR, HU, IE, IT, LU, MD, MK, MT, NL, PL, PT, RO, RS, SI, SK, TR, UA |
| DoT/DoQ | ctif.hagezi.org | |||
| Do53 | 162.55.58.402a01:4f8:1c19:6c19::1 |
EU and neighboring countries with limited coverage from current server locations: AD, CY, GE, IS, LI, MC, ME, SM.
[!NOTE] Encrypted DNS Stamps let compatible tools connect to HaGeZi DNS automatically, with all needed connection details built in.
| Endpoint | Protocol : DNS Stamp |
|---|---|
root.hagezi.org | DoH: sdns://AgMAAAAAAAAADjE4OC4zNC4xNjEuMjEwAA9yb290LmhhZ2V6aS5vcmcKL2Rucy1xdWVyeQ |
DoT: sdns://AwMAAAAAAAAADjE4OC4zNC4xNjEuMjEwAA9yb290LmhhZ2V6aS5vcmc | |
DoQ: sdns://BAMAAAAAAAAADjE4OC4zNC4xNjEuMjEwAA9yb290LmhhZ2V6aS5vcmc | |
wurzn.hagezi.org | DoH: sdns://AgMAAAAAAAAADTE1OS42OS4xNTUuOTQAEHd1cnpuLmhhZ2V6aS5vcmcKL2Rucy1xdWVyeQ |
DoT: sdns://AwMAAAAAAAAADTE1OS42OS4xNTUuOTQAEHd1cnpuLmhhZ2V6aS5vcmc | |
DoQ: sdns://BAMAAAAAAAAADTE1OS42OS4xNTUuOTQAEHd1cnpuLmhhZ2V6aS5vcmc | |
juuri.hagezi.org | DoH: sdns://AgMAAAAAAAAADTk1LjIxNy4xNjMuMTcAEGp1dXJpLmhhZ2V6aS5vcmcKL2Rucy1xdWVyeQ |
DoT: sdns://AwMAAAAAAAAADTk1LjIxNy4xNjMuMTcAEGp1dXJpLmhhZ2V6aS5vcmc | |
DoQ: sdns://BAMAAAAAAAAADTk1LjIxNy4xNjMuMTcAEGp1dXJpLmhhZ2V6aS5vcmc |
| Endpoint | Protocol : DNS Stamp |
|---|---|
ctif.hagezi.org | DoH: sdns://AgMAAAAAAAAADDE2Mi41NS41OC40MAAPY3RpZi5oYWdlemkub3JnCi9kbnMtcXVlcnk |
DoT: sdns://AwMAAAAAAAAADDE2Mi41NS41OC40MAAPY3RpZi5oYWdlemkub3Jn | |
DoQ: sdns://BAMAAAAAAAAADDE2Mi41NS41OC40MAAPY3RpZi5oYWdlemkub3Jn |
[!TIP] For a general idea of the latency between your location and our server locations, use WonderNetwork's Global Ping Statistics.
Example WonderNetwork compilation configured for Germany:
To optimize latency, personally measure the response times by pinging each DNS server from your own connection. This factors in your specific network conditions, such as geographic location, ISP routing, and local congestion, giving you a practical, real-world latency measurement. Selecting the server with the lowest ping time maximizes responsiveness and reduces DNS query delays.
Use the provided test scripts to measure actual DNS resolution times (beyond simple ICMP latency), evaluating how quickly each server resolves domain queries in practice:
./dnsperftest.sh
Latency cheat sheet (PDF): summarizes measured network latency in milliseconds from six European PoPs (Amsterdam, Falkenstein, Frankfurt, Helsinki, Nürnberg, Vienna) to cities across European countries, highlighting the fastest location per city and EU membership status, based on WonderNetwork ping data.
DNS resolution reference values (ms):
| DNS resolve/lookup time (ms) | Rating | What it usually means |
|---|---|---|
| < 20 | Excellent | Very fast response, often due to a nearby resolver and/or a warm cache. |
| 20-50 | Very good | Common target range for good user experience. |
| 50-100 | OK | Usually fine, but can add noticeable delay if a page triggers many lookups. |
| 100-120 | Average | Often cited as the upper end of "average" DNS lookup time. |
| 120-200 | Slow | Suggests distance, routing/latency, resolver load, or extra resolution steps. |
| > 200 | Very slow / problematic | Frequently indicates a real performance or reachability issue (retries, timeouts, overload). |
188.34.161.210 / 2a01:4f8:c17:1c66::1 (PTR: root.hagezi.org), Hetzner Online GmbH, Falkenstein, Saxony, DE159.69.155.94 / 2a01:4f8:1c1c:d363::1 (PTR: wurzn.hagezi.org), Hetzner Online GmbH, Nürnberg, Bavaria, DE95.217.163.17 / 2a01:4f9:c013:dc4e::1 (PTR: juuri.hagezi.org), Hetzner Online GmbH/HOS-GUN, Helsinki, Uusimaa, FI162.55.58.40 / 2a01:4f8:1c19:6c19::1 (PTR: ctif.hagezi.org), Hetzner Online GmbH, Nürnberg, Bavaria, DEIf a DNS leak test shows IP addresses other than these, your device or network might be leaking DNS queries through fallback resolvers or directly to your ISP. This means requests are bypassing your intended DNS protection and potentially exposing your browsing activity.
Contact support@hagezi.org for support and questions. You can also use the official public Matrix support chat, or contact the operator directly via Matrix or Signal.
NXDOMAIN answer signals that it does, so the client does not switch on its own DNS provider automatically.version.bind or id.server; disabling it prevents attackers from identifying the server software or instance.sdns://) that bundles a DNS server's address, protocol, and public key information so compatible client software can configure a connection automatically.ping to measure basic network round-trip time; it measures raw network latency only, not actual DNS query resolution time.NXDOMAIN (domain does not exist) and SERVFAIL (resolution error).[!NOTE] Legal and regulatory terms (GDPR, DSA, ENISA, and related concepts) are defined in the Glossary in PRIVACY.
This document covers technical setup and usage only. The full disclaimer, EU privacy policy, Digital Services Act (DSA) content-moderation compliance information, and a glossary of legal terms are maintained in a separate document: PRIVACY.
282 followers · starred Sep 2026
16 followers · starred Jun 2026
38 followers · starred Jun 2026
4 followers · starred May 2026