This is the multi-page printable view of this section. Click here to print.

Return to the regular view of this page.

Advanced Features

Advanced features tutorial: ECS/client subnets, quick response, rules and filter lists, device naming, and other advanced configurations and best practices.

Here we will introduce some advanced usage tips for private services.

1 - Blocked Application List

App-level blocking list: one-click ban of social/gaming apps with schedule support, region-based preset lists, helping minors avoid addiction and boosting productivity.

It is important not to confuse this with blacklists, which are usually used to block ads, privacy trackers, malware, etc. The Blocked Application List is for completely preventing the use of specified applications.

It is typically combined with a schedule to build personal habits and avoid addiction. Commonly used for minors’ habit formation—for example, prohibiting social media and games during study hours. It can also be used for adult self-discipline, such as banning social media and games during work hours.

This service provides pre-configured rules based on popular apps in each country. Because popular culture changes and companies evolve, these lists may become outdated, but we are committed to ongoing maintenance.

If you find that an app in the list is not fully blocked, or if you need to add a recently popular app, please contact us and we will handle it promptly.

Need help?

Contact on WeChat private6688
or Send email [email protected]
Please describe your issue in detail, and we will respond as soon as possible.

Country/RegionApplication List
GlobalGlobal Application List
Mainland ChinaMainland China Application List

2 - ECS Boosts CDN Access Speed

ECS (Extended Client Subnet) acceleration: pass subnet information upstream to improve CDN hit rates and enable closer resolution, delivering faster and more stable access.

NullPrivate supports ECS, delivering more precise resolution and optimizing your network experience.

What is ECS (Extended Client Subnet)?

ECS (Extended Client Subnet) is a DNS protocol extension that allows a DNS resolver (such as your NullPrivate server) to pass part of the client’s IP address information to the authoritative DNS server. This enables the authoritative server to provide more accurate DNS responses based on the client’s network location.

How ECS Works

  1. Traditional DNS Query: Without ECS, the DNS resolver only sends its own IP address to the authoritative DNS server. This forces the authoritative server to make resolution decisions based on the resolver’s location (usually a data center), which can yield sub-optimal results.

  2. ECS-enabled DNS Query: When ECS is enabled, the DNS resolver includes a portion of the client’s IP address (the subnet) in the DNS query. For example, if the client’s IP is 203.0.113.45, the resolver might send 203.0.113.0/24 as ECS information.

  3. Authoritative Server Response: Upon receiving a query containing ECS information, the authoritative DNS server can use it to select the IP address best suited to the client—typically the server geographically closest to the client.

Benefits of ECS

  • Faster Response Times: By directing clients to the nearest server, ECS reduces latency and improves application responsiveness.
  • Enhanced User Experience: Faster response times create a smoother, more enjoyable online experience.
  • More Effective CDN Usage: Content Delivery Networks (CDNs) can leverage ECS to direct users to the optimal content server, boosting efficiency and lowering costs.
  • Bypass Local Resolver Limitations: Some local ISP DNS servers may have issues such as resolution errors or domain hijacking. ECS can bypass these limitations to obtain more accurate resolution results.

Why Use ECS with NullPrivate?

As a private DNS server, NullPrivate can be configured to use upstream DNS servers for domain resolution. With ECS enabled, NullPrivate can pass your client subnet information to those upstream servers, yielding more accurate resolution results.

3 - DDNS Dynamic Resolution

Use NullPrivate to implement convenient DDNS dynamic resolution service

What is DDNS?

DDNS (Dynamic DNS) allows you to bind a fixed domain name to a dynamic IP address, suitable for home broadband users accessing internal network devices such as NAS, smart home controllers, etc.

Feature Highlights

  • Easy to use: Only requires a single script to achieve automatic updates
  • Zero additional cost: No need to purchase a domain
  • High reliability: Built on NullPrivate’s DNS infrastructure
  • Fast propagation: DNS records take effect immediately after update, no DNS propagation wait required

Usage Guide

explorer_VIZAwW9wSO

You can find the DDNS script download address under Filters->DNS Rewriting.

FAQ

How to verify if it’s working?

Check if resolution points correctly to your current IP address using the ping your-domain.name command.

Or log in to the service backend and view records under Filters->DNS Rewriting.

How to schedule automatic updates?

Windows Task Scheduler

  1. Open Task Scheduler
  2. Create Basic Task
  3. Set execution frequency (recommended 15-30 minutes)
  4. Select PowerShell as program location, enter full script command in parameters

Linux Cron Job

Add the following to crontab (executes every 15 minutes):

*/15 * * * * /path/to/update_dns.sh https://xxxxxxxx.adguardprivate.com admin:password123 nas.home

Important Notes

  • Keep your username and password secure to prevent leakage
  • Recommended to add update script to system scheduled tasks for automatic execution
  • If resolution doesn’t take effect promptly, check network connection and credential validity

4 - DNS Split-Horizon Configuration Guide

A detailed walkthrough on optimizing network access via DNS split-horizon, including domestic and overseas DNS server setup and rule configuration.

DNS Split-Horizon Overview

DNS split-horizon routes resolution requests for different domains to distinct DNS servers, greatly improving network access. A well-designed setup can:

  • Accelerate domain resolution
  • Increase website stability
  • Optimize cross-border access
  • Avoid DNS pollution

NullPrivate Split-Horizon Configuration

Basic Example

# Domestic DNS servers
223.5.5.5                                    # Alibaba DNS
2400:3200::1                                 # Alibaba DNS IPv6
public0.adguardprivate.svc.cluster.local    # Private DNS, mainland upstream

# Overseas DNS servers
tls://1.0.0.1                               # Cloudflare DNS
tls://[2606:4700:4700::1001]               # Cloudflare DNS IPv6
public2.adguardprivate.svc.cluster.local    # Private DNS, other upstream

# Split-horizon rules
[/google.com/bing.com/github.com/stackoverflow.com/]tls://1.0.0.1 public2.adguardprivate.svc.cluster.local
[/cn/xhscdn.com/tencentclb.com/tencent-cloud.net/aliyun.com/alicdn.com/]223.5.5.5 2400:3200::1 public0.adguardprivate.svc.cluster.local

Domestic Carrier DNS Servers

China Telecom DNS Servers

NamePrimary DNS ServerSecondary DNS Server
Anhui CT61.132.163.68202.102.213.68
Beijing CT219.142.76.3219.141.140.10
Chongqing CT61.128.192.6861.128.128.68
Fujian CT218.85.152.99218.85.157.99
Gansu CT202.100.64.6861.178.0.93
Guangdong CT202.96.128.86202.96.128.166
Guangxi CT202.103.225.68202.103.224.68
Guizhou CT202.98.192.67202.98.198.167
Henan CT222.88.88.88222.85.85.85
Heilongjiang CT219.147.198.230219.147.198.242
Hubei CT202.103.24.68202.103.0.68
Hunan CT222.246.129.8059.51.78.211
Jiangsu CT218.2.2.2218.4.4.4
Jiangxi CT202.101.224.69202.101.226.68
Inner Mongolia CT219.148.162.31222.74.39.50
Shandong CT219.146.1.66219.147.1.66
Shaanxi CT218.30.19.4061.134.1.4
Shanghai CT202.96.209.133116.228.111.118
Sichuan CT61.139.2.69218.6.200.139
Tianjin CT219.150.32.132219.146.0.132
Yunnan CT222.172.200.6861.166.150.123
Zhejiang CT202.101.172.3561.153.177.196
Tibet CT202.98.224.68202.98.224.69

China Unicom DNS Servers

NamePrimary DNS ServerSecondary DNS Server
Beijing CU123.123.123.123123.123.123.124
Chongqing CU221.5.203.98221.7.92.98
Guangdong CU210.21.196.6221.5.88.88
Hebei CU202.99.160.68202.99.166.4
Henan CU202.102.224.68202.102.227.68
Heilongjiang CU202.97.224.69202.97.224.68
Jilin CU202.98.0.68202.98.5.68
Jiangsu CU221.6.4.66221.6.4.67
Inner Mongolia CU202.99.224.68202.99.224.8
Shandong CU202.102.128.68202.102.152.3
Shanxi CU202.99.192.66202.99.192.68
Shaanxi CU221.11.1.67221.11.1.68
Shanghai CU210.22.70.3210.22.84.3
Sichuan CU119.6.6.6124.161.87.155
Tianjin CU202.99.104.68202.99.96.68
Zhejiang CU221.12.1.227221.12.33.227
Liaoning CU202.96.69.38202.96.64.68

China Mobile DNS IPs

NamePrimary DNS ServerSecondary DNS Server
Beijing CM221.130.33.60221.130.33.52
Guangdong CM211.136.192.6211.139.136.68
Jiangsu CM221.131.143.69112.4.0.55
Anhui CM211.138.180.2211.138.180.3
Shandong CM218.201.96.130211.137.191.26

Public DNS IPs

NamePrimary DNS ServerSecondary DNS Server
114 DNS114.114.114.114114.114.115.115
CNNIC SDNS1.2.4.8210.2.4.8
Alibaba Public223.5.5.5223.6.6.6
DNSPod DNS+119.29.29.29119.29.29.29
Google DNS8.8.8.88.8.4.4

Configuration Tips

  1. Prefer geographically close DNS servers
  2. Configure both IPv4 and IPv6 DNS
  3. Set up backup DNS for critical domains
  4. Update split-horizon rules regularly
  5. Monitor DNS response times

Precautions

  • Record original DNS settings before changes
  • Avoid untrusted DNS servers
  • Periodically verify DNS resolution
  • Keep rule lists concise and effective

Proper DNS split-horizon configuration can significantly improve network access. Choose DNS servers and rules according to your actual needs.

References

5 - Using Custom Device Names

Customize device identification names: distinguish endpoints via extended domain names/URL paths, accurately view “Client Rankings” and logs, and facilitate rule and schedule management.

If you directly use the service’s listening address, such as:

  • tls://xxxxxxxx.adguardprivate.com
  • https://xxxxxxxx.adguardprivate.com/dns-query

The IPs seen in the Client Rankings in the backend are the cluster IPs of the load balancer, which are meaningless to users and cannot distinguish between different devices.

Client Rankings

You can identify different devices by using extended domain names and adding URL paths.

Custom Client Name

  • For DoT, use the extended domain name method, e.g., tls://device1.xxxxxxxx.adguardprivate.com
  • For DoH, use the added URL path method, e.g., https://xxxxxxxx.adguardprivate.com/dns-query/device2

Note:

  • Android devices do not require entering the protocol prefix tls:// during setup; simply input device1.xxxxxxxx.adguardprivate.com
  • Apple devices follow setup instructions by entering a client ID and downloading a configuration file for setup, without manual input

Apple Device Setup Instructions

All devices under personal service share the service’s query limit of 30 requests per second.

6 - Faster Request Response

Faster Request Response: Properly configure cache TTL, upstream mode, and region selection to reduce first-packet latency and retry rate, significantly improving perceived speed.

Paid users utilize AdGuard’s private service. The DNS request path is as follows:

DNS Request Path

The fastest response solution can be analyzed based on this path.

Local Cache Hit

The fastest response is a local cache hit. Since the local cache operates at memory level, it’s extremely fast—taking only a few microseconds.

This is controlled by the DNS response’s TTL (Time to Live) value, typically ranging from minutes to hours, indicating that query results remain valid during this period and don’t require re-querying.

You can set the minimum TTL value at Control Panel -> Settings -> DNS Settings -> DNS Cache Configuration -> Override Minimum TTL Value. Increasing this value extends cache duration, allowing the system to utilize local cache more frequently. The typical TTL value is 600 seconds.

However, since our service also includes filtering capabilities, if a required service is mistakenly blocked by ad-blocking rules, temporarily disabling encrypted DNS won’t immediately grant access because the local cached result has been modified by filtering rules. Therefore, setting it to 60 seconds is a safer value, ensuring that in rare cases users won’t wait too long after disabling encrypted DNS due to accidental blocking.

AdGuard DNS Servers

We currently use Alibaba Cloud servers located in Hangzhou, which can meet low-latency needs for most users in eastern China. As business grows, we will expand server coverage nationwide in the future.

Server Cache Hit

By default, each user is allocated 4MB of DNS cache, which experience shows is sufficient for household usage. Free modification of this setting may lead to forced service termination, so we’ve disabled user access to modify this setting.

Upstream DNS Servers

Using Alibaba Cloud services, we’ve selected Alibaba’s DNS service as the upstream provider, which typically returns results within milliseconds.

Users have three methods to request upstream DNS servers:

  1. Load Balancing: Enabled by default, automatically selects the fastest server to return results.
  2. Parallel Requests: Currently unrestricted in our service.
  3. Fastest IP Address: Currently a meaningless setting; modification entry has been disabled.

Explanation why “Fastest IP Address” is meaningless: The truly fastest IP should be selected by the device actually accessing the service. When AdGuard operates in Hangzhou while the user is in Beijing, AdGuard might consider Hangzhou IPs fastest, but in reality Beijing-based services would be quicker for the user. Selecting Hangzhou IPs would actually increase latency. Therefore, we’ve disabled this setting modification. This setting might be useful in home networks but meaningless in public services.

Many factors affect network experience: server bandwidth, network congestion, server load, network quality, etc. Selecting the “fastest IP” doesn’t guarantee the fastest response—latency is just one factor among many. To prevent user misconfiguration from degrading service quality, we’ve disabled this setting.

Rule Filtering

The most common mode is blacklisting, where users can select from preset blacklists. Blacklist hits use hash algorithms—hit time remains O(1) regardless of rule volume, so users needn’t worry about performance degradation from large rule sets.

However, rules are stored in memory after computation. Each user’s service is limited to 300MB memory usage, sufficient for most needs. Excessively large rule sets may cause memory shortages, leading to repeated service restarts and interruptions.

We’ve temporarily disabled third-party rules to prevent users from importing oversized rule sets. Third-party rule support will be reinstated when better restriction methods become available.

Summary

To achieve faster request responses, users can:

  1. Appropriately increase the minimum TTL value to improve local cache hit rate.
  2. Set appropriate DNS cache size (preset value already configured).
  3. Select geographically closest cities when creating services (pending business expansion).
  4. Use load balancing for domestic needs; use parallel requests for overseas needs.
  5. Use appropriate blacklist rules, avoiding oversized rule sets.

7 - Setting Up Trusted DNS Providers

When creating a paid service, it defaults to using faster domestic upstream services, including Alibaba’s IPv4, IPv6, and DoT services.

Some DNS providers may have resolution errors, resolving certain overseas websites to incorrect IP addresses, making them inaccessible. A common symptom is browsers reporting certificate errors.

To avoid resolution errors, you can switch to upstream providers like Cloudflare. When using such services, ensure you’re using the DoH or DoT protocols to prevent hijacking.

Additionally, you need to disable domestic upstream services because they are geographically closer and faster, causing AdGuard to prioritize them.

Add a # before the corresponding service IP to disable that upstream service.

Avoid Resolution Errors

After configuration, Test Upstream to ensure the upstream server is available, then Apply.

Avoid Resolution Errors - Apply

However, using only overseas services may degrade the experience for domestic apps, as these apps typically resolve overseas domains to specific external servers with slower domestic access speeds.

If you only need to avoid resolution errors for commonly used services, you can manually specify DNS addresses for misresolved domains while keeping other domains on default domestic upstream services.

In the AdGuard console, go to Settings -> DNS Settings -> Upstream DNS Servers. Add misresolved domains in the format [/example1.com/example2.com/]tls://1.0.0.1 to Custom DNS Servers, then click Save Settings.

Configure Upstream Servers

Configure Upstream Servers

public2.adguardprivate.svc.cluster.local is our internally provided error-free resolution service, using Cloudflare as upstream. Compared to users manually specifying overseas upstreams, it offers faster resolution speeds at the cost of minor delays in DNS updates. Users without professional needs can use our error-free resolution service.

To use external Cloudflare or Google resolution addresses, specify IPs with DoT/DoH. Examples:

#tls://1.1.1.1
tls://1.0.0.1
tls://[2606:4700:4700::1111]
tls://[2606:4700:4700::1001]
tls://[2606:4700:4700::64]
tls://[2606:4700:4700::6400]
https://1.1.1.1/dns-query
https://1.0.0.1/dns-query
https://[2606:4700:4700::1111]/dns-query
https://[2606:4700:4700::1001]/dns-query
#tls://8.8.8.8
#tls://8.8.4.4
tls://[2001:4860:4860::8888]
tls://[2001:4860:4860::8844]
tls://[2001:4860:4860::64]
tls://[2001:4860:4860::6464]
#https://8.8.8.8/dns-query
#https://8.8.4.4/dns-query
#https://[2001:4860:4860::8888]/dns-query
https://[2001:4860:4860::8844]/dns-query

Addresses prefixed with # are commented out, indicating they are currently blocked by firewalls and unavailable.

Our site fully supports IPv6, which is one of our key advantages. You can use IPv6 upstream addresses for more stable resolution speeds.