Skip to content

Linux

Most desktop Linux distributions, including Ubuntu, Fedora and Debian with GNOME, use systemd-resolved for DNS. It supports DNS-over-TLS, so your lookups are encrypted.

Check that it’s in use:

Terminal window
resolvectl status

If this prints your DNS settings, carry on. If the command isn’t found, see other setups below.

  1. Create the configuration file below for your location. The #hostname after each address tells systemd-resolved which name to verify the TLS certificate against.

    /etc/systemd/resolved.conf.d/bancuh.conf
    [Resolve]
    DNS=45.33.24.129#us-dns1.bancuh.com 2600:3c00::f03c:94ff:fe97:f94f#us-dns1.bancuh.com
    DNSOverTLS=yes
    Domains=~.
    Terminal window
    sudo mkdir -p /etc/systemd/resolved.conf.d
    sudo nano /etc/systemd/resolved.conf.d/bancuh.conf
  2. Restart the resolver:

    Terminal window
    sudo systemctl restart systemd-resolved
  3. Stop NetworkManager from adding your network’s own DNS servers, which would otherwise be used alongside Bancuh DNS. Replace <connection> with the name shown by nmcli connection show:

    Terminal window
    nmcli connection modify <connection> ipv4.ignore-auto-dns yes ipv6.ignore-auto-dns yes
    nmcli connection up <connection>
  4. Confirm the setup. The global section should list the Bancuh servers with +DNSOverTLS:

    Terminal window
    resolvectl status
    resolvectl query zedo.com # blocked domains return 0.0.0.0
Terminal window
sudo rm /etc/systemd/resolved.conf.d/bancuh.conf
sudo systemctl restart systemd-resolved
nmcli connection modify <connection> ipv4.ignore-auto-dns no ipv6.ignore-auto-dns no
nmcli connection up <connection>

If your system doesn’t use systemd-resolved, set plain DNS instead: through your network manager’s settings, or by listing the servers in /etc/resolv.conf.

ServerIPv4IPv6
us-dns145.33.24.1292600:3c00::f03c:94ff:fe97:f94f