All vendors

Vendor lineage

Quad9 - a public resolver that blocks by default

Swiss-based public recursive resolver that refuses to answer for known-malicious domains.

Quad9 operates a public recursive DNS resolver from Switzerland, and its distinguishing choice is that blocking is the default rather than an option: queries for domains on its threat feeds return no answer.

That makes it the clearest working example of DNS as a security control available to anybody, without an appliance or a subscription. Pointing a resolver at it applies a threat feed to every device on the network, including the ones that cannot run an agent.

The Swiss jurisdiction is part of the design rather than a detail of incorporation, because the question a public resolver has to answer is what happens to the query log. A resolver's privacy posture is a legal position as much as a technical one, and it is the property worth comparing between providers.

The claim above - that a resolver's privacy posture is a legal position - was tested between 2021 and 2023, and the result is more instructive than either side expected. In June 2021 a Hamburg court, acting for Sony Music, ordered Quad9 to stop resolving a site that linked to pirated recordings. The order was the first of its kind against a public resolver. The court held that a DNS service does not enjoy the liability protections an internet provider or a domain registrar does, and set the penalty for non-compliance at 250,000 euros per infringing query.

Every element of the case was outside Germany. The domain sat under Tonga's top-level domain, its servers and the servers it linked to were elsewhere, and Quad9 had no office or presence in the country. Swiss jurisdiction did not prevent the proceeding: a treaty between Switzerland and the European Union allowed the injunction to be served across the border. And because geolocation cannot exclude a country's users with certainty, the plaintiff demanded, and the foundation - facing that per-query penalty - implemented, a block that applied to everyone who used the resolver, anywhere.

That is the mechanism worth keeping. A national court order, applied at a service used worldwide, became a global block through nothing more than the imprecision of geolocation; the fragmentation the Cisco entry describes arriving from governments here arrived from a record label. The Regional Court in Leipzig went further in March 2023 and held the resolver liable as a wrongdoer for what its users did with an answer to a lookup.

The Dresden Higher Regional Court reversed that in December 2023: a resolver plays no central role in infringement and cannot be held liable for it. The foundation's argument had been the one the DNS family article in this catalogue makes on technical grounds - that a resolver passes metadata and stores no content, and is at most a conduit. The appeal court agreed. It took two and a half years, and an Italian court reached the opposite conclusion about Cloudflare's resolver in the same period.

Two things survive the case. The first is that the question of who can compel a supplier, asked elsewhere in this catalogue about intelligence services, has a civil-law answer as well, and the party doing the compelling need not be a state. The second is that the penalty structure did the work before the law was settled: a threat priced per query is existential to a service that answers billions of them, and a global block was implemented under that pressure and lifted only when the appeal succeeded. The eventual ruling was the right one. The service had already been made to behave as if it were wrong.

Sources