Open RootAlternative DNS network
Independent alternative DNS infrastructure

Domains beyond the traditional Internet.

Register alternative domains, manage DNS records, delegate your own nameservers and resolve the alternative web through a distributed global network, with encrypted DNS built in.

7configured nodes
853DNS-over-TLS
443DNS-over-HTTPS
24/7domain control panel
Open Root

An open path to alternative namespaces

Traditional resolvers only know the public ICANN root. Open Root also serves alternative TLDs and connects users, publishers and independent DNS operators without replacing normal Internet access.

01Alternative TLDsDiscover namespaces not available through conventional registrars.
02Authoritative DNSZones are published across seven geographically distributed nodes.
03Compatible resolversDNS Libre resolves normal domains plus Open Root and compatible alternative roots.
Domain services

Everything needed to publish an alternative domain

The Open Root DNS Panel turns registration and DNS administration into a clear, guided workflow.

Managed DNS

Create A, AAAA, CNAME, MX, TXT and URL records with templates and validation.

Custom nameservers

Delegate a domain to Xhandro, ClouDNS or another authoritative DNS provider.

Health and propagation

Compare records across every configured Open Root node and detect differences.

Public directory

Optionally publish your project in the directory of alternative websites.

DNS Libre

Encrypted DNS for the whole alternative web

DNS Libre encrypts every query with DNS-over-TLS and DNS-over-HTTPS before it leaves your device, resolving normal and alternative domains alike. Pick the standard endpoint or the ad-and-tracker-blocking one — same network, no extra setup.

DNS-over-HTTPS

Port 443 · looks like ordinary HTTPS traffic
Ad-blocking

DoH

Same resolution, filtering known ad and tracking domains.

URLhttps://noads.dnslibre.com.mx/dns-query

DNS-over-TLS

Port 853 · system-wide, covers every app at once
Ad-blocking

noads.dnslibre.com.mx

Same protocol, with ad and tracker blocking.

Port853

Standard DNS

Port 53 · unencrypted, works on routers and legacy devices

DNS

Set as primary/secondary DNS on routers and devices without encrypted-DNS support.

Primary107.174.78.121
Secondary107.174.81.168
How ad-blocking works

One dedicated node, same network

The ad-blocking endpoint runs on a node dedicated to filtering — before your device loads a page, known ad and tracking domains are answered as non-existent, so the ad or tracker never loads. No app or extension needed.

Blocklist source: StevenBlack/hosts (Unified variant), a community-maintained open source project. It currently blocks around 99,000 domains and updates automatically every week.

What happens on each query

  • 1You query a domain through the ad-blocking endpoint.
  • 2If it is on the blocklist, the server answers that it does not exist and the ad or tracker never loads.
  • 3If it is not on the list, it resolves normally — regular Internet domains and every Open Root / DNS Libre alternative TLD alike.
  • 4It is fully optional: switch back to the unfiltered endpoint any time, nothing else changes.
!

Honest note: No DNS-level blocker is perfect: some lists can over-block a legitimate domain or miss a brand-new one. If a page looks broken on the ad-blocking endpoint, try the unfiltered one to confirm whether the filter was the cause.

Frequently asked questions
Does the ad-blocking endpoint replace standard DNS Libre?

No, they are two separate options. The unfiltered endpoint keeps working exactly as always, with no filtering at all. The ad-blocking one is an alternative for anyone who also wants ads and trackers blocked.

Is the ad-blocking endpoint just as fast and private?

Yes. Same infrastructure, same encryption, same privacy policy — it only adds the step of checking each query against the blocklist before resolving.

•••

Are you using DNS Libre?

Checking your current resolver...

Configuration

Connect in a few minutes

Choose the method supported by your device. DoT covers the whole system at once; DoH is set per browser.

DoH — Browser

  1. Open the three-line menu and go to Settings.
  2. Go to General → Network Settings → Settings.
  3. At the bottom of the dialog, enable DNS over HTTPS.
  4. Set the provider to Custom and paste the DoH URL above.
  1. Open the three-dot menu and go to Settings.
  2. Go to Privacy and security → Security.
  3. Enable Use secure DNS.
  4. Select Custom and paste the DoH URL above.
  1. Go to edge://settings/privacy.
  2. Under Security, enable Use secure DNS.
  3. Select Custom and paste the DoH URL above.

Windows 11 also lets you set this natively under Settings → Network & internet → DNS, choosing "Encrypted only" and pasting the URL above.

DoT — Operating system

Edit /etc/systemd/resolved.conf with administrator privileges:

[Resolve]
DNS=107.174.78.121#dot.dnslibre.com.mxFallbackDNS=127.0.0.1 ::1
DNSOverTLS=yes
Domains=~.

Restart the service: sudo systemctl restart systemd-resolved

  1. Open Settings and search for Private DNS.
  2. Choose Private DNS provider hostname.
  3. Enter the DoT hostname above and save.

iOS and macOS have no manual field for DoT — it installs through a signed configuration profile. Download it from the device profiles section below.

Router (whole network)

Set the primary and secondary IPv4 addresses as DNS in your router's DHCP/LAN settings to protect every device at once. This method is unencrypted; routers running OpenWrt, pfSense or unbound can instead be pointed at the DoT hostname for encrypted resolution network-wide.

Device profiles

iOS and macOS

Download the profile, open it with Safari and confirm it under Settings → Profile Downloaded.

Open the complete DNS Libre guide
Distributed infrastructure

Configured DNS nodes

The site reads the network state automatically when the node status file is available.

Configured

107.174.78.121

Open Root network

IPv4
107.174.78.121
Configured

107.174.81.168

Open Root network

IPv4
107.174.81.168
IPv6
2607:9d00:2000:74::8b7:2ba0
Configured

192.3.110.114

Open Root network

IPv4
192.3.110.114
Configured

149.71.56.203

Open Root network

IPv4
149.71.56.203
IPv6
2602:fcc0:4444:c4ab::1
Configured

107.172.222.53

Open Root network

IPv4
107.172.222.53
IPv6
2605:6f01:2000:18::1d5e:d3c
Configured

143.20.79.204

Open Root network

IPv4
143.20.79.204
IPv6
2a12:bec4:1821:332::a
Configured

104.223.50.46

Open Root network

IPv4
104.223.50.46
IPv6
2607:5dc0:0:30::7075:f576
View network status
Privacy

What we keep, and what we don't

  • DNS query logging is disabled at the resolver daemon level on all seven nodes.
  • Recursive resolution runs on the Open Root nodes themselves — we don't forward your queries to a third party.
  • Traffic between your device and the server is end-to-end encrypted with TLS, both on DoH and DoT.
  • The ad-blocking endpoint filters ad and tracking domains using a public, community-maintained list — use the unfiltered endpoint if you prefer neutral resolution.
  • Abuse-protection events (rate limiting, automated blocking) may be recorded briefly to keep the network healthy.

Create your alternative domain

Open an account, choose an available TLD and publish your project using managed DNS or your own nameservers.

Create accountSign in