Skip to content
DnsLister Forum

Where domain hunters compare notes

Goodbye NextDNS. Hello ControlD

After roughly four years as a paying NextDNS user, I think I am finally switching.

I've attached some of my old NextDNS invoices for context, because this isn't the conclusion of someone who tried NextDNS for a month and bounced. I've used it for years, recommended it to others, and generally been very happy with it.

But I've been testing ControlD for the past week and, after an initially somewhat confusing start, I am honestly very impressed.

I think I am staying.

ControlD has a steeper learning curve, but it rewards you for learning it

My first couple of days with Control D involved quite a few moments of:

"Why can't I do this?"

…followed half an hour later by:

"Oh. I can. I just didn't know where it was."

That has probably been the biggest difference coming from NextDNS.

NextDNS is incredibly easy to understand. You open a configuration, toggle some security features and blocklists, look at your logs, add an allowlist or denylist entry, and you are basically done.

ControlD requires a different mental model. Endpoints, Profiles, Clients, Services, Filters, Custom Rules, Profile Options, Analytics refinements, redirect actions, multiple profiles and so on take some time to piece together.

But once it clicks, the amount of control available is in a completely different league.

A good example was Analytics.

I wanted to look at blocked requests for a particular Client behind one of my router Endpoints. Initially I thought: surely I should be able to do this, so why can't I find it?

Then I discovered the Refine functionality.

Once I understood how refinements work, suddenly I could slice the data by action, Endpoint, Client, domain, filter, protocol and other dimensions instead of just scrolling through a log hoping to spot something useful.

That experience has happened several times during my trial.

I initially thought ControlD was missing equivalents to some of the little NextDNS features I had grown accustomed to. Then I discovered, for example, that NextDNS's Cache Boost effectively has an equivalent through Control D's configurable TTL overrides, except Control D actually gives me separate control over blocked, redirected and bypassed responses.

The same happened with ECS. The naming and implementation are different, but Control D has configurable ECS behaviour including no ECS, automatic ECS and custom subnets.

So my biggest piece of advice for anyone moving from NextDNS would be: don't assume a feature is missing just because you cannot immediately find a toggle with the same name.

The functionality may be somewhere else, and in several cases I have found the Control D implementation to be considerably more configurable once I understood it.

ctrld on a router is a game changer

This may actually be my favourite part.

I run ctrld directly on my router, and the integration between the router, Clients and the Control D dashboard is excellent.

Instead of my entire LAN appearing as one anonymous DNS source, Control D can identify the individual clients behind the router and expose them in the dashboard. I can see their activity separately and even assign different Profiles to individual clients.

And ctrld itself is not just a dumb DNS forwarder. It supports secure DNS for devices that otherwise only know how to speak plain UDP/53, advanced routing policies, split-horizon DNS, multiple listeners, caching and quite a bit more.

For a homelab/networking nerd, this is fantastic.

It feels less like "install our DNS client" and more like Control D has given me an actual DNS policy engine that happens to integrate with their service.

The fact that ASUS Merlin, OpenWRT, pfSense/OPNsense, Firewalla, Ubiquiti and several other router platforms are explicitly supported makes this one of Control D's strongest advantages in my opinion.

The other reason I am leaving NextDNS: it feels stale

This is harder to quantify, because NextDNS still works extremely well.

And I want to stress that point.

NextDNS has been reliable for me for years. Its interface is clean. Its network is fast. Its security settings are easy to understand. The core product does what it says on the tin.

But increasingly it feels like a finished product being maintained rather than one being actively pushed forward.

Some features have worn a "Beta" label for years. The interface has barely changed. Communication about what is being developed is minimal. There is very little visibility into what is coming next.

Maybe a lot is happening behind the scenes. I genuinely don't know.

And that is part of the problem.

After four years as a customer, I could not tell you what NextDNS is trying to become over the next two years.

ControlD feels alive

This has probably surprised me more than the feature set itself.

Control D actually talks about development.

There is a proper changelog. There are regular product-update posts. They discuss what shipped, what was improved, what changed under the hood and, importantly, sometimes what is coming next.

Just looking at the last year or so, ControlD has shipped Analytics 2.0, major backend and dashboard improvements, Dragonfly domain intelligence, passkeys, scheduling improvements, client-management features, analytics refinements, new security tooling and a long list of smaller quality-of-life changes.

And they actually write about them.

The March and May 2026 updates even finish with explicit "What's Coming Soon?" sections.

That might sound like a small thing, but after using a service where development has increasingly felt opaque, it makes an enormous difference.

I don't need a vendor to promise me Feature X on October 14th.

I just want evidence that the product I am paying for has momentum.

ControlD gives me that impression right now.

The privacy and security side also deserves credit

ControlD being independently certified to both ISO 27001 and ISO 27701, on top of SOC 2 Type II, was a significant factor for me.

ISO 27001 is about information-security management, while ISO 27701 specifically extends that framework into privacy-information management.

For a DNS provider that potentially sits in a position to see an enormous amount of browsing metadata, I care quite a lot about this.

ControlD also allows users who enable Analytics to choose the jurisdiction where that data is stored. At the moment the available regions are New York, Amsterdam and Sydney.

Which brings me to my first feature request:

Can we get Switzerland as an Analytics/log-storage region?

One thing I genuinely liked about NextDNS was being able to select Switzerland for my logs. Given Control D's strong privacy posture, adding Switzerland would fit very nicely.

I'd use it immediately.

There are still a few areas where I think NextDNS is clearer

This isn't meant to be an unconditional love letter. There are things I would change.

The biggest one is the granularity and explanation of some Filters.

For example, Control D has a Social filter. But I would love to control what aspect of social media I am blocking.

Do I want to block the websites themselves?

Social-media trackers?

Embedded widgets?

Telemetry?

All of the above?

Likewise, IoT Telemetry is useful, but I would love to select individual vendors or categories rather than treating IoT telemetry as one large bucket.

And the Crypto filter is another example where I want much more granularity.

I don't necessarily want to prevent somebody on my network from visiting Coinbase or reading a cryptocurrency website.

I absolutely do want protection against cryptojacking and malicious mining infrastructure.

Those are different policies.

Control D already demonstrates with its Malware filter that Filters can have operating modes, so I would love to see that philosophy expanded to more categories.

I would also love a "Switching from NextDNS?" security guide

NextDNS makes several security protections extremely explicit:

  • Google Safe Browsing
  • Cryptojacking
  • DNS Rebinding
  • IDN Homograph Attacks
  • Typosquatting
  • Domain Generation Algorithms
  • Newly Registered Domains
  • Parked Domains

Control D obviously has substantial malware and phishing protection of its own, including threat-intelligence feeds, malicious-IP intelligence and ML-assisted detection.

But I have found it surprisingly difficult to establish a clean one-to-one answer to questions like:

"Does Control D protect me against IDN homograph attacks?"

"Does the Phishing filter include typosquatting?"

"Are DGAs detected by the ML malware filter?"

"Does Crypto specifically protect against cryptojacking?"

"Is there an equivalent to NextDNS's Parked Domains protection?"

"Is there any equivalent to the Google Safe Browsing integration, or is that redundant because Control D uses its own threat intelligence?"

Maybe the answer to all of these exists somewhere in the documentation and I simply haven't found it yet.

If so, please correct me.

But this would make an excellent documentation page or blog post:

"Migrating from NextDNS: Where your security settings went."

Not because ControlD necessarily lacks those protections, but because people coming from NextDNS are accustomed to seeing them exposed as individually named switches.

Right now, I am not always sure whether a protection is missing or simply incorporated into one of Control D's broader Filters. NextDNS at least makes the individual security mechanisms very obvious.

And finally: ECH. Please.

This is probably the feature I am most interested in seeing Control D push forward.

Control D has been talking publicly about Encrypted Client Hello for quite a long time. There was even an old roadmap item for global ECH support, although the team subsequently mentioned running into technical roadblocks.

Interestingly, the current API documentation still contains an option described as experimental ECH support/TLS bumping, while Control D's own 2026 privacy material acknowledges ECH as an important emerging piece of the privacy puzzle.

So… what is the current status?

I would love to see two things eventually:

  1. Proper ECH support for Control D's own infrastructure/web services wherever applicable.
  2. The more ambitious ECH proxy functionality Control D talked about previously, potentially allowing ECH protection even when the destination itself does not properly support it.

And if this does eventually ship, please give us a ControlD test page that verifies the complete setup.

Something like the existing Control D status/DNS-leak tooling, but showing:

DNS resolver: Control D
DNS protocol: DoH3
DNSSEC: Yes
ECH: Yes
SNI protected: Yes

That would be incredibly useful for actually confirming that a privacy setup is working rather than assuming it is.

So, goodbye NextDNS

At least for now.

Four years is a long time to use a service, and I don't regret paying for NextDNS. It has been extremely reliable and, for a long time, it was exactly what I needed.

But after a week with Control D, NextDNS suddenly feels much more limited than I realised.

ControlD is definitely more complicated. Some functionality is harder to discover, some terminology takes getting used to, and I still think certain security settings could be explained much better.

But once you get past that initial learning curve, the amount of control is remarkable.

More importantly, ControlD feels like a product whose developers are still actively asking themselves what they can build next.

That's ultimately what convinced me to switch.

And for the Control D team: I'd especially love some clarification around the NextDNS security-feature equivalents, log storage in Switzerland, more granular Filters, and where ECH currently stands.

Disclaimer: Yes, I used AI to correct my wording, spelling, and grammar. English is not my native language.

https://i.redd.it/v6jcm5r6xdoh1.jpeg

Source: r/ControlD · by /u/Re1hak

Leave a Reply

Your email address will not be published. Required fields are marked *