Managed DNS
Create A, AAAA, CNAME, MX, TXT and URL records with templates and validation.
Register alternative domains, manage DNS records, delegate your own nameservers and resolve the alternative web through a distributed global network, with encrypted DNS built in.
Traditional resolvers only know the public ICANN root. Open Root also serves alternative TLDs and connects users, publishers and independent DNS operators without replacing normal Internet access.
The Open Root DNS Panel turns registration and DNS administration into a clear, guided workflow.
Create A, AAAA, CNAME, MX, TXT and URL records with templates and validation.
Delegate a domain to Xhandro, ClouDNS or another authoritative DNS provider.
Compare records across every configured Open Root node and detect differences.
Optionally publish your project in the directory of alternative websites.
DNS Libre encrypts every query with DNS-over-TLS and DNS-over-HTTPS before it leaves your device, resolving normal and alternative domains alike. Pick the standard endpoint or the ad-and-tracker-blocking one — same network, no extra setup.
Direct resolution, no domains blocked.
https://doh.dnslibre.com.mx/dns-querySame resolution, filtering known ad and tracking domains.
https://noads.dnslibre.com.mx/dns-queryServer hostname — this is what Android and iOS need.
853Same protocol, with ad and tracker blocking.
853Set as primary/secondary DNS on routers and devices without encrypted-DNS support.
107.174.78.121107.174.81.168The ad-blocking endpoint runs on a node dedicated to filtering — before your device loads a page, known ad and tracking domains are answered as non-existent, so the ad or tracker never loads. No app or extension needed.
Blocklist source: StevenBlack/hosts (Unified variant), a community-maintained open source project. It currently blocks around 99,000 domains and updates automatically every week.
Honest note: No DNS-level blocker is perfect: some lists can over-block a legitimate domain or miss a brand-new one. If a page looks broken on the ad-blocking endpoint, try the unfiltered one to confirm whether the filter was the cause.
No, they are two separate options. The unfiltered endpoint keeps working exactly as always, with no filtering at all. The ad-blocking one is an alternative for anyone who also wants ads and trackers blocked.
Yes. Same infrastructure, same encryption, same privacy policy — it only adds the step of checking each query against the blocklist before resolving.
Checking your current resolver...
Choose the method supported by your device. DoT covers the whole system at once; DoH is set per browser.
edge://settings/privacy.Windows 11 also lets you set this natively under Settings → Network & internet → DNS, choosing "Encrypted only" and pasting the URL above.
Edit /etc/systemd/resolved.conf with administrator privileges:
[Resolve] DNS=107.174.78.121#dot.dnslibre.com.mxFallbackDNS=127.0.0.1 ::1 DNSOverTLS=yes Domains=~.
Restart the service: sudo systemctl restart systemd-resolved
iOS and macOS have no manual field for DoT — it installs through a signed configuration profile. Download it from the device profiles section below.
Set the primary and secondary IPv4 addresses as DNS in your router's DHCP/LAN settings to protect every device at once. This method is unencrypted; routers running OpenWrt, pfSense or unbound can instead be pointed at the DoT hostname for encrypted resolution network-wide.
Download the profile, open it with Safari and confirm it under Settings → Profile Downloaded.
The site reads the network state automatically when the node status file is available.
Open Root network
Open Root network
Open Root network
Open Root network
Open Root network
Open Root network
Open Root network
Open an account, choose an available TLD and publish your project using managed DNS or your own nameservers.