A beginners guide to DNS and OpenDNS


Recommended Posts

A beginners guide to DNS and OpenDNS

Welcome to the wonderful world of OpenDNS. You are probably wondering what the heck is OpenDNS? In fact what the heck is DNS?

Think of DNS like a gigantic Internet phone book. Every ISP (Internet Service provider) has one. Every website that you connect to has a number associated with it. It's called an IP address. Think of it as a websites phone number. A website can have a bunch of numbers or it can just have one number and sometimes those numbers can change.

Let's take Google for example. People know Google as www.google.com. A computer knows Google as 208.69.36.230 or 208.69.36.231. In the very early days of the internet they didn't want people to have to type in long numbers just to get to a website. So they created "Domain names" like .com .org .gov and the list goes on. This makes it simpler for human brains to remember internet addresses.

Only problem is, we have to be able to use the website name, while the computer has to be able to use the website IP address (number). This is where DNS server was born. When you type in www.google.com into your web browser the computer checks the phone books (DNS server) and say's hey look www.google.com's phone number is 208.69.36.2230 and proceeds to connect to the website.

Now let's imagine you had a DNS server that knew about websites online that could harm your computer and removed them from the phone book so your computer couldn't connect to them.

Welcome to OpenDNS.

OpenDNS is a free DNS server you can use instead of the one provided by your ISP. It has many benefits.

It's Faster - Sometimes it can be faster than the DNS server you already use. Think about it, if your ISP has a slow DNS server then the time it takes your computer to located a websites phone number could slow you down your internet web browsing. It would only be a few milliseconds, but a few milliseconds here and there can add up.

It's Safer - It allows you to specify which sites or whole categories you want it to filter from the phone book. Let's take porn for example. Because it's a DNS server it knows about every porn website on the internet. So you just tell it, "Filter all porn websites" It then removes all the porn websites from its phone book so you can no longer connect to them. That is just one of many types of sites you can block. You can block sites that contain ad-aware (nasty stuff that could infect your computer), Phishing sites (the kind of site that tricks you into thinking they are your bank). Want to block your children's access to Facebook or Myspace? No problem just tell it to block social networking sites :)

I'm not going to say it will block EVERY website in every category. It only blocks what it knows about. For phishing websites it only blocks what has been reported to them by other people. But it is still MUCH safer than browsing the internet using the DNS server provided by your ISP.

Configuring your computer to use OpenDNS.

XP

1) Open the control panel (Start / control panel or start / setting control panel)

2) Double click on Network connections (If you do not see it listed then click on "Switch to classic" view in the top left side of the control panel)

3) Right click the network adaptor you wish to apply OpenDNS to. Usually it's the one labeled "Local Area Connection".

4) Left Click Properties.

5) Under "This connection uses the following items" double click on the one labeled "Internet Protocol (TCP / IP).

6) At the very bottom of the Internet Protocol (TCP / IP) Properties box put a dot in the box labeled "Use the Following DNS server addresses"

7) 2 boxes will now become active. "Preferred DNS server" and "Alternate DNS server". Each box requires a different set of numbers. Use the numbers below

Preferred DNS Server- 208.67.222.222 (remember to hit the space bar after you type 67 otherwise it gets all confused)

Alternate DNS server - 208.67.220.220

8) Click OK and then OK again.

That's it. Now that our computer is using OpenDNS lets configure it. Skip to the section Configuring OpenDNS.

Windows Vista.

1) Open the control panel (Start / control panel or start / setting control panel)

2) Double click on Network and Sharing Center (If you do not see that listed then click on "Switch to classic" view in the top left of the control panel)

3) On the top left side of the screen left click "Manage network connections"

4) Right click the network adaptor you wish to apply OpenDNS to. Usually it's the one labeled "Local Area Connection".

5) Left Click Properties. Then click Continue

6) Under "This connection uses the following items" double click on the one labeled "Internet Protocol (TCP / IPv4).

7) At the very bottom of the Internet Protocol (TCP / IPv4) Properties box put a dot in the box labeled "Use the Following DNS server address"

8) 2 boxes will now become active. "Preferred DNS server" and "Alternate DNS server" each box requires a different set of numbers. Use the numbers below

Preferred DNS Server- 208.67.222.222 (remember to hit the space bar after you type 67 otherwise it gets all confused)

Alternate DNS server - 208.67.220.220

9) Click OK and then OK again.

That's it. Now that our computer is using OpenDNS lets configure it. Skip to the section Configuring OpenDNS.

OS X Leopard (Thanks to thefarewellnote)

1 . Go to System Preferences

2. Click on Network

3 . Select Your Network (Airport or Ethernet) and click Advanced

4. Select the DNS tab and add 208.67.222.222 and 208.67.220.220 to the list of DNS servers. Click OK

That's it. Now that your computer is using OpenDNS lets configure it!

Configuring OpenDNS.

1) Open up the web browser of your choice and type www.OpenDNS.com in the address bar and press enter.

2) At the very top of the OpenDNS website left click on "Create account"

3) Fill out the information on the page and when you are finished press the "Create Account" button.

4) Check your email. You should receive an email from OpenDNS in the next 1-10 mins. Open the email and click the link provided.

In this next section we will be telling OpenDNS what your computer's IP address (Phone number) is. We do this so when you tell OpenDNS to filter out websites it knows which computer to filter it for.

1) Left click on the "Networks" button on the top of the screen.

2) Click the "Add This Network" button.

You should now see "You've successfully added a network!. Just a few more steps and your home"

4) In that new box Left click "OpenDNS updater for Windows"

5) A download box will appear. (for internet explorer tell it to run / for firefox tell it to save file.)

6) Once the file gets done downloading run the file and follow the direction to install it.

The phone number of your computer never stays the same forever. So when your computers phone number changes, this program will update the records of OpenDNS. This way it will always knows your new number and thus keep you protected.

7) Once you are done installing the application and if it doesn't automatically open double click the new OpenDNS shortcut on your desktop.

8) Fill out the "OpenDNS username" and "OpenDNS Password" that you selected when you created your account.

9) Left click on the Preferences tab and click the button labeled "Install as service" this will insure the application will run in the background from the moment you turn your computer on.

10) Press ok.

We are just about done. Now all we need to do is go back to the OpenDNS website and tell it which sites we want to filter.

Setting up Filters.

1) The OpenDNS website should still be open on the bottom of the screen. If you closed it you can go back to www.opendns.com and log back in.

2) Left click on the "Settings" tab.

3) On the left hand side of the screen click "Content Filtering"

4) On the right hand of the screen left click on "custom".

Here is the list of categories that OpenDNS will block. Put a check mark next to the ones you want to block. I would strongly recommend you block at lease "Ad-aware and Parked Domains, even if you decide to block nothing else.

5) Once you have chosen your list you can left click the apply button. Nothing you do here is set in stone. You can always log back into the website at anytime and modify your selection. Please allow 3 mins for the categories you choose to take in effect.

That's it! You are now figured to use OpenDNS. Enjoy!.

Edited by warwagon
Link to comment
https://www.neowin.net/forum/topic/765624-a-beginners-guide-to-dns-and-opendns/
Share on other sites

Only had a quick look, but it's a nice guide! OpenDNS now prevents Conficker from phoning home too, as well as providing a SmartCache service.

I've never had a fault with them, although for those on dynamic IPs it is somtimes a little tricky to set up.

While you are writing about it, why not include the negative points of OpenDNS as well, and not just the positives ?

I've never had any negative experiences.

Only had a quick look, but it's a nice guide! OpenDNS now prevents Conficker from phoning home too, as well as providing a SmartCache service.

I've never had a fault with them, although for those on dynamic IPs it is somtimes a little tricky to set up.

I talk about setting that up via the OpenDNS updater. It updates your IP address to OpenDNS if it changes. I have it running on my server so I never see it.

Nicely wrote. Liked how you covered what DNS was at the start.

Here is the settings on Leopard OS X - your forgot us Mac nerds

OS X Leopard

1 . Go to System Preferences

2. Click on Network

3 . Select Your Network (Airport or Ethernet) and click Advanced

4. Select the DNS tab and add 208.67.222.222 and 208.67.220.220 to the list of DNS servers. Click OK

There is a pretty big drawback to OpenDNS though, Privacy.

I have a dynamic IP and use the OpenDNS updater, so basically my defined network in the OpenDNS settings gets tags on the IP. However, there are of course other people using my IP as assigned by my ISP, but because the IP is linked to my Network if they use OpenDNS (maybe they don't even know they are using it) I can see where they go using the OpenDNS stats feature (Top Domains, unique IP's).

I've tracked a Nigerian, and I kid you not they like eBay :) They also visit some Nigerian social network thing. I could theoretically watch my Top Domains list and report them if they visited anything naughty. They could do the same to me, however because I use the OpenDNS updater I usually assign the IP to my OpenDNS network within seconds. I could also block the domains other people visit who happen to have the same IP as me and use OpenDNS.

I've never had any negative experiences.

Well you could have mentioned that for the majority of the world, using OpenDNS will most likely cause dns lookups to be slower, unless you for some reason have absolute **** ISP/DNS servers.

Then there's the features of OpenDNS, where it may block more than you want if you use those features (which would be the only reason to use it over your ISP DNS if you're no American or a londoner).

And then there's the fact that their blacklists are user controlled. whitelists/blacklists should NEVER be user controlled. then you get situations like the one we had on this very site where on of the OpenDNS volunteer moderators came here to recruit people to vote for his suggestions to add MSN plus website to the adware/malware black list. he failed, maybe because picking neowin as his ground for finding allies was a bad choice (I'm hoping it was because the majority of neowin users are to smart to go with crap like that). But imagine what religious cults could do. Those crazy people have enough people in them to get anything they don't like black listed. Open source zealots, more than enough people willing to sell their soul to black list some MS and Apple sites. and Apple and MS fanboys are no better.

Well you could have mentioned that for the majority of the world, using OpenDNS will most likely cause dns lookups to be slower, unless you for some reason have absolute **** ISP/DNS servers.

Then there's the features of OpenDNS, where it may block more than you want if you use those features (which would be the only reason to use it over your ISP DNS if you're no American or a londoner).

{Paragraph about user controlled blacklists...}

Well, you must have a fantastic ISP that has great DNS servers, because I've (and anyone else I've setup with this) had nothing but improved lookup times with this.

Pretty sure you can control what types of sites it blocks for you... (not sure what difference it makes if you are an American or a Londoner.(whatever that means, I know of at least 3 places in the world called London))

No service is perfect, but I would say in my opinion, for anyone online that isn't a power user of any kind, this is something to help them for reliability, and safety....

IMHO of course....

(not sure what difference it makes if you are an American or a Londoner.(whatever that means, I know of at least 3 places in the world called London))

What he's trying to say is - unless you're from the UK or the US, OpenDNS servers will be much further away than your ISP's servers.

Personally, I gave OpenDNS another try a couple of days ago, but surfing felt generally slower and I had my brother complain how he can't access some of the websites he regularly visits.

What he's trying to say is - unless you're from the UK or the US, OpenDNS servers will be much further away than your ISP's servers.

Personally, I gave OpenDNS another try a couple of days ago, but surfing felt generally slower and I had my brother complain how he can't access some of the websites he regularly visits.

OpenDNS has never blocked any Legit safe websites.

OpenDNS has never blocked any Legit safe websites.

Interesting. How exactly would you know that? Do you visit every web site in OpenDNS's cache?

I'm aware of at least two perfectly legit web sites that used to be blocked.

That coupled with occasional downtime and no servers in my proximity mean I won't be using it.

When I switched to Verizon FiOS, my Xbox used to take a long time to sign in to Xbox Live. So I switched to OpenDNS on my router and Xbox then started signing up before my TV showed the dashboard. But then, having OpenDNS somehow messed up my work VPN where names of hosts at my work wouldn't resolve. So I switched my router back to ISP's DNS and only Xbox was using OpenDNS. Here comes the problem - over last few months - ever since the NXE shipped, my XBL sign up started taking longer and Xbox party would frequently freeze. All this while I had completely forgotten about the OpenDNS entries on Xbox. Last week, I removed them and now using FiOS' DNS servers. No lag, no worries.

Bottom line - Your mileage may vary. ;)

I have used it in the past and I really like it. I just redid it actually, I have never paid much attention to torrent speeds with it but I will let you know. Going to download the Opie & Anthony show :)

I set a tracert running. The left hand side shows OpenDNS and the Right hand side is BT Broadbands DNS Servers. You work out which is quicker. I don't know if its a placebo or not but I have just switched over to OpenDNS and browsing seems to have speeded up ALOT.

Go Figure . . .

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • I just looked on my computer and there are settings and log files for utilities I have never even turned on!
    • O&O ShutUp10 3.1.1104 by Razvan Serea O&O ShutUp10 offers a simple yet effective way to take control of your Windows privacy. It provides access to almost 50 privacy-related tweaks, most of them hidden or not easily accessible to the average computer users. Using a very simple interface, you decide how Windows 10/11 should respect your privacy by deciding which unwanted functions should be deactivated. Using ShutUp10 you can easily disable Windows Defender, turn off telemetry, disable peer-to-peer updates, turn off Wi-Fi Sense, disable automatic Windows updates, turn off and reset Cortana and more. ShutUp10 allows you to create a System Restore point before you apply any changes, so that you can revert your system at any time if you run into problems. O&O ShutUp10 is entirely free and does not have to be installed – it can be simply run directly and immediately on your PC. And it will not install or download retrospectively unwanted or unnecessary software, like so many other programs do these days! O&O ShutUp10 Free and Premium The latest version brings O&O ShutUp10 Premium, expanding the app’s long-standing privacy controls with automatic enforcement of user-defined settings. Instead of manually rechecking options after every Windows update, users can set their preferred privacy configuration once—or apply recommended settings in a single click—and the tool continuously monitors them in the background. If Windows 10 or 11 re-enables disabled features or introduces new data collection paths, Premium restores the chosen settings automatically without user intervention. The free version remains available and fully functional for manual adjustments, offering the same core privacy controls for Windows. However, the Premium tier is aimed at users who want long-term, hands-off protection, adding automatic reapplication after updates, ongoing monitoring, and optional notifications to ensure privacy settings remain consistent over time. O&O ShutUp10 3.1.1104 changelog: Added “Show Differences” button in the overview panel “Don’t show again” option for the restore point prompt Ctrl+F keyboard shortcut for search/filter functionality Detection and linking of system-wide and user-specific setting associations Automatic search while typing PREM: Option to preserve notification counters and timestamps across application restarts PREM: Reset blocked settings button in the Settings dialog PREM: Informational message when no settings are blocked PREM: Update check can also be triggered from the menu PREM: Notification deduplication and activity log summary feature Improved L005 “Disable Windows Location Service”: Version-specific split (up to Windows 11 23H2) and new variant for Windows 11 24H2+ L001 (Disable Location): Added Night Light warning to the description in all languages Search now detects setting IDs even when ID display is disabled and offers to enable it Detection and removal of Copilot/AI desktop apps in RecallTerminator Optimized High DPI support PREM: Reset button is now only enabled when blocked items exist – setting IDs are shown in the confirmation dialog PREM: Updated tray icons with higher-resolution versions PREM: Activity Log timestamps now use localized date and time formats PREM: Tray icon status now uses OK/Warning indicators and localized tooltips PREM: Recall folder detection switched to service-based detection PREM: Copilot uninstallation now provides UI feedback and improved verification Fixed Description text was not displayed correctly for the last item and disappeared when clicking the scrollbar Crash when clicking a search result heading or the […] button PREM: Installation path is now correctly preserved during upgrades PREM: Tray icon was not reliably removed when exiting the application PREM: Main window was not displayed correctly in single-instance mode PREM: Incorrect display of the & symbol in tray icon tooltips on Windows 10 PREM: Fixed notification flooding after sleep/standby PREM: Dashboard was not refreshed after applying recommended settings during onboarding PREM: Progress bar was not reset after deleting Recall folders PREM: Fixed service startup failures PREM: Fixed incorrect drift detection when Automatic Protection was disabled PREM: Notifications now correctly count all deviating settings when protection is enabled PREM: Registration Wizard was shown after sleep/standby despite a valid license Download: O&O ShutUp10 3.1.1104 | 76.4 MB (Freeware) Download: O&O ShutUp10 32-bit | ARM64 View: O&O ShutUp10 Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Fascinating...W h i t e P o w e r is now also asterisks out.  
    • In the past few days I have noticed two odd moderation activities. First, when I posted the term 'White Nationist Christian' it was asterisk's out. When I changed it to **** it was allowed! Second, in the Politics is a ###business thread I was allowed to post that the GOP is a party of p e d ophiles but I was censored  when I posted the GOP are a party of p e d ophile protectors. Wtf Neowin. Please explain.
  • Recent Achievements

    • One Month Later
      Vincian earned a badge
      One Month Later
    • First Post
      Jocimo earned a badge
      First Post
    • Week One Done
      suprememobiles48 earned a badge
      Week One Done
    • One Month Later
      Windows Guy earned a badge
      One Month Later
    • One Month Later
      Prasann earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      547
    2. 2
      +Edouard
      165
    3. 3
      PsYcHoKiLLa
      86
    4. 4
      Steven P.
      66
    5. 5
      ATLien_0
      64
  • Tell a friend

    Love Neowin? Tell a friend!