Private Pierce

DNS Filtering Service Comparison: Logging, Encryption, and Deployment

This source-dated DNS filtering service comparison separates identity collection, query logging, log region, filtering inputs, encrypted transport, and deployment; it does not test, score, rank, or recommend a path.

Scope: 5 products

DNS filtering choices differ by operator, logging model, and deployment path

A DNS-filtering label alone does not identify the operator, query-logging default, log region, encrypted transport support, or whether filtering runs through a managed resolver or a local deployment.

This matrix keeps those questions separate across a frozen five-path roster: AdGuard DNS, Control D, NextDNS, Pi-hole, and Quad9. The four managed resolver paths and the local Pi-hole deployment remain in one comparison because a reader may consider them for a similar network-control job, but the page does not treat their operating models as equivalent. A field that applies to a hosted service is not copied into the local-deployment row, and a local configuration statement is not rewritten as a service policy.

The comparison uses thirteen attributes because each one answers a narrower question. Signup identifiers and later verification concern identity collection at different moments. General retention and deletion do not replace the dedicated DNS-query logging and log-region fields. Blocklist sources describe filtering inputs; encrypted DNS describes documented transport support; router deployment describes a setup path. Operating entity, request reporting, public source artifacts, and assessment records supply still different evidence.

Every displayed vendor or project value is transcluded from the current persisted cell for the exact product, plan, region, platform, attribute, and observation version. The value travels with its claim type, source class, source URL, capture date, and evidence state. A typed unknown therefore belongs to one field at one captured scope. It is not completed from another column, another row, general product knowledge, or a later source that has not passed the same capture process.

The page supplies no score, rank, best label, preferred-product conclusion, or performance verdict. Alphabetical order expresses no preference. The privacy-tool comparison methodology and corrections hub explains the frozen roster, source labels, capture rules, corrections path, and neutral ordering. The related email-alias comparison covers an address layer that may be used alongside network-level controls without claiming that either layer makes the other anonymous.

What each path collects at signup and what can trigger later verification

Signup identifiers describe what the documented path requests before initial use, while later-verification triggers describe a separate event and any additional identifier requested after that point.

The signup column keeps the identifier, requiredness, collecting actor, plan, region, platform, and scope supplied by the exact current cell. It does not assume that every path has an account. When a path is documented as accountless or locally deployed, the table preserves that operating distinction instead of inventing a signup workflow or borrowing one from a managed service.

The later-verification column is independent. It records a trigger, requested identifier, requesting actor, and scope only when the cell establishes them. Signup, account recovery, support contact, risk review, abuse response, billing, and another later event are not merged simply because more than one may involve identity information. A documented requirement at one stage does not prove that the same requirement exists at every other stage.

These cells describe captured documents rather than completed account exercises. No account was created and no verification event was triggered for this comparison. Vendor-stated requirements remain vendor-stated and scoped to the named product tuple and capture. If the declared sources do not disclose a later-verification field, the typed absence remains visible; it is not translated into a promise that a later check can never occur.

What each path collects at signup and what can trigger later verification
JurisdictionSignup identifiersLater verification
AdGuard DNSAdGuard DNS identifies ADGUARD SOFTWARE LIMITED, registered in Limassol, Cyprus, as the data controller for personal-data processing.sourceAdGuard DNS processes an email address and a hash of the password used for authorization.sourceAdGuard DNS may ask a privacy-rights requester to further confirm their identity.source
Control DControl D's agreement identifies ControlD Inc. as the owner of Control D and a company registered in Ontario, Canada.sourceControl D says it requires email and organization name as basic account information.sourceControl D says it may require identity verification depending on a request emailed to [email protected].source
NextDNSNextDNS's terms define “NextDNS” as NextDNS Inc., a Delaware corporation.sourceNextDNS's source submits email and password values to `/accounts`.sourceUnknown Verified absenceNot disclosed in the captured primary source.source
Pi-holePi-hole Core's copyright notice names Pi-hole, LLC.sourcePi-hole describes itself as network-wide ad blocking via the user's own Linux hardware.sourceUnknown Verified absenceNot disclosed in the captured primary source.source
Quad9Quad9 identifies the Swiss foundation Quad9 as the responsible party for its data and website privacy and points to relevant Commercial Register documents.sourceQuad9 says it has no user signup or account mechanism and no technical or business need to identify users or distinguish one user from another.sourceQuad9 says it has no user signup or account mechanism, no need to identify users, and no records or data structures associated with or keyed by a user.source

Source: 5 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.

Field definitions

Signup identifiers
Identifiers, requiredness, collecting actor, plan, region, platform, and scope stated for signup or initial use.
Later verification
A later trigger, requested identifier, requesting actor, and scope stated by the current cell.

Who operates the path and what its documents say about retention, deletion, and requests

Operating identity, general retention, deletion, and request reporting are separate fields, so one policy statement cannot stand in for every actor, record category, or disclosure process.

The operating-entity column reports the legal or project identity and jurisdictional detail supported by the current cell. It does not treat brand, hosting location, user location, endpoint location, governing law, and network location as synonyms. The Pi-hole row remains a local project and deployment path where its cells say so; it is not recast as an organization operating a managed recursive resolver for the reader.

Retention stays tied to the data category, controller, trigger, duration, exception, and scope named by the source. A period attached to one category does not become a universal retention schedule for every DNS record, account record, security record, support record, or diagnostic artifact. A relative or non-numeric period remains in the recorded source terms instead of being converted into an estimated calendar date.

Deletion is also narrower than complete erasure of every related record. The column reports the initiation path, controller, completion statement, timeframe, exceptions, and scope established by its cell. A documented account-deletion path does not establish what another actor retains, while a local uninstall or database action is not rewritten as a hosted-service erasure promise. When the cell does not settle a detail, the page does not fill it from the retention column.

Request reporting preserves the period, jurisdiction, unit, scope, counts, and process statements that the exact cell supplies. Requests, orders, accounts, identifiers, disclosures, and challenged matters are not assumed to be interchangeable units. A process statement is not a count, and the absence of a disclosed report is not rendered as zero requests.

Who operates the path and what its documents say about retention, deletion, and requests
JurisdictionOperating entityRetentionDeletionRequest reporting
AdGuard DNSAdGuard DNS identifies ADGUARD SOFTWARE LIMITED, registered in Limassol, Cyprus, as the data controller for personal-data processing.sourceAdGuard DNS identifies ADGUARD SOFTWARE LIMITED, registered in Limassol, Cyprus, as the data controller for personal-data processing.sourceAdGuard DNS says it keeps an anonymous database of domains requested in the previous 24 hours and that nothing in it can link a domain name to the originating user.sourceAdGuard DNS says users can completely delete their Personal Data through an AdGuard account or by sending a request to [email protected].sourceAdGuard DNS says it processes Personal Data where necessary for compliance with its legal obligations, such as to exercise or defend its legal rights or for taxation purposes.source
Control DControl D's agreement identifies ControlD Inc. as the owner of Control D and a company registered in Ontario, Canada.sourceControl D's agreement identifies ControlD Inc. as the owner of Control D and a company registered in Ontario, Canada.sourceControl D says the most granular data it stores is kept for no more than one month, only when Full Analytics is selected for the Device.sourceControl D says users can request deletion of their Personal Data from its systems, and it will comply unless it has a legitimate reason not to delete the data.sourceControl D says it will inform users when it shares Personal Data with recipients outside the company under the listed circumstances, unless prohibited by law.source
NextDNSNextDNS's terms define “NextDNS” as NextDNS Inc., a Delaware corporation.sourceNextDNS's terms define “NextDNS” as NextDNS Inc., a Delaware corporation.sourceNextDNS says its server discards all request and response data immediately after sending the response.sourceNextDNS's source sends a DELETE request to `/accounts/@me` with the current password value.sourceNextDNS's terms say that, to the extent legally permitted, a receiving party compelled by law to disclose confidential information must give the disclosing party prior notice and reasonable assistance at the disclosing party's cost if it wants to contest the disclosure.source
Pi-holePi-hole Core's copyright notice names Pi-hole, LLC.sourcePi-hole Core's copyright notice names Pi-hole, LLC.sourcePi-hole stores queries in its database for 91 days by default and allows a positive number of days or `0` to disable the database.sourcePi-hole can be uninstalled with `pihole uninstall`.sourcePi-hole directs privacy-policy complaints to `[email protected]`.source
Quad9Quad9 identifies the Swiss foundation Quad9 as the responsible party for its data and website privacy and points to relevant Commercial Register documents.sourceQuad9 identifies the Swiss foundation Quad9 as the responsible party for its data and website privacy and points to relevant Commercial Register documents.sourceQuad9 says a query's Reply To IP address remains in volatile memory only for the microseconds to milliseconds needed to service the query and increment counters, then is deleted without being stored.sourceQuad9 says its service does not record or store users' personal data and therefore responds to personal-data requests that it does not have the data.sourceQuad9 says it will release summaries of any requests for information it receives from authorized law enforcement or judicial bodies.source

Source: 5 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.

Field definitions

Operating entity
The legal or project identity and jurisdictional details stated by the current cell.
Retention
Data category, controller, trigger, duration, exceptions, and scope stated by the captured source.
Deletion
Deletion initiation, controller, completion statement, timeframe, exceptions, and scope stated by the cell.

DNS query logging defaults and log regions are separate comparison fields

A DNS logging default states the documented starting behavior and retention choices, while a log-region field states only the storage, processing, or selection scope its source identifies.

The logging column keeps the documented default, relevant query or metadata categories, retention setting, available choice, plan, platform, and limitations together. Enabled, disabled, configurable, temporary, diagnostic, and another scoped condition are not compressed into a single privacy label. A default does not establish every later user setting, and a choice available to one plan or client does not automatically extend to every plan or deployment.

The log-region column answers a different question. It records only the storage or processing location, selection mechanism, eligibility, plan, category, and limits established by the current cell. Legal domicile, resolver endpoint, user location, processing location, storage location, and a selectable region remain distinct when the evidence distinguishes them. A missing region statement is not replaced by the operating-entity jurisdiction.

The local Pi-hole row stays local where its captured records place the query data. The matrix does not present that model as equivalent to sending queries to a managed resolver, and it does not assume a local deployment has no upstream resolver, network exposure, administrator access, diagnostic record, or other data path. Those questions require their own evidence and are outside what these two cells establish.

Read the two columns together without fusing them. A documented region does not reveal whether logging is on by default. A logging default does not reveal where every covered category is handled. Neither field alone establishes anonymity, complete non-retention, current behavior beyond the capture, or a product-wide privacy result.

DNS query logging defaults and log regions are separate comparison fields
JurisdictionDNS logging defaultDNS log region
AdGuard DNSAdGuard DNS identifies ADGUARD SOFTWARE LIMITED, registered in Limassol, Cyprus, as the data controller for personal-data processing.sourceAdGuard DNS stores DNS-query logs for dashboard display, lets users disable logging, and lets them configure the limited storage period and optional anonymized subnet IP logging.sourceAdGuard DNS says personal information is stored in its own data center in Frankfurt, Germany.source
Control DControl D's agreement identifies ControlD Inc. as the owner of Control D and a company registered in Ontario, Canada.sourceControl D says it never stores the data used for the Activity Log unless the user selects Full Analytics.sourceControl D says Analytics data is stored in a customer-selected location, currently New York, Amsterdam, or Sydney.source
NextDNSNextDNS's terms define “NextDNS” as NextDNS Inc., a Delaware corporation.sourceNextDNS's source shows logs enabled in its settings.sourceNextDNS says logs can be stored in the United States, European Union, United Kingdom, or Switzerland.source
Pi-holePi-hole Core's copyright notice names Pi-hole, LLC.sourcePi-hole logs DNS queries and replies to `pihole.log` by default, with `true` or `false` as the allowed settings.sourcePi-hole allows its database location to be configured through `files.database`, which defaults to `/etc/pihole/pihole-FTL.db`.source
Quad9Quad9 identifies the Swiss foundation Quad9 as the responsible party for its data and website privacy and points to relevant Commercial Register documents.sourceQuad9 says a query's Reply To IP address remains in volatile memory only for the microseconds to milliseconds needed to service the query and increment counters, then is deleted without being stored.sourceQuad9 says the aggregate data it keeps may be retained in full or partial form in permanent archives.source

Source: 5 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.

Field definitions

DNS logging default
Documented default, covered query or metadata categories, retention choices, plan, platform, and limitations.
DNS log region
Storage or processing location, selection mechanism, eligibility, category, plan, and scope stated by the cell.

Blocklists, encrypted DNS, and router deployment answer different capability questions

Blocklist sources describe filtering inputs, encrypted DNS describes documented transport roles, and router deployment describes the prerequisites for applying a path at the network level.

The blocklist column records the built-in, third-party, custom, or other list inputs established by the current cell, together with their update, selection, plan, platform, and scope qualifiers. A named list or input does not establish filtering accuracy, completeness, speed, maintenance quality, or suitability for a particular threat model. The page did not submit test domains, measure blocking results, or compare false positives.

The encrypted-DNS column records the documented protocol, endpoint, client or server role, setup requirement, plan, platform, and limitation. DNS over HTTPS and DNS over TLS are treated here as transport support only. A protocol statement does not establish that the resolver keeps no logs, that an account reveals no identity, that destination traffic receives end-to-end protection, that all clients use the protocol, or that a network cannot observe or bypass another part of the path.

The router column reports whether the captured documentation describes router-level use and which device, firmware, DNS-setting, local-host, or other prerequisite it names. Network-level setup is not assumed to cover devices that ignore the configured resolver, use a different protocol path, leave the network, or follow another configuration. The table also does not infer that the same setup steps work on every router or firmware release.

The three columns therefore remain independent. A path may document one capability without settling the others, and the meaning of a value stays attached to its product, plan, region, platform, and observation. No combination of the three becomes a security score, privacy score, effectiveness grade, or recommendation.

Blocklists, encrypted DNS, and router deployment answer different capability questions
JurisdictionBlocklist sourcesEncrypted DNS supportRouter deployment
AdGuard DNSAdGuard DNS identifies ADGUARD SOFTWARE LIMITED, registered in Limassol, Cyprus, as the data controller for personal-data processing.sourceAdGuard DNS lets users select blocklists and customize filtering rules.sourceAdGuard DNS supports DoH, DoT, and DoQ.sourceAdGuard DNS provides general setup instructions for Private AdGuard DNS on routers and cautions that configuration details may vary by model.source
Control DControl D's agreement identifies ControlD Inc. as the owner of Control D and a company registered in Ontario, Canada.sourceControl D says its Native Filters are hand-curated and maintained by Control D.sourceControl D says its Endpoint creation wizard presents a unique set of DNS resolvers for the Endpoint.sourceControl D says it can be configured on most routers, with ease varying by supported DNS protocols and whether the user has a Static IP.source
NextDNSNextDNS's terms define “NextDNS” as NextDNS Inc., a Delaware corporation.sourceNextDNS's source includes a blocklists entry under privacy.sourceNextDNS says it supports all four protocols and directs users to the setup tab for more information on how to use them.sourceNextDNS says there are different ways to set it up on a device or router, each with pros and cons.source
Pi-holePi-hole Core's copyright notice names Pi-hole, LLC.sourcePi-hole's installer says it relies on third-party lists to block ads and lets the user include the suggested list or add another list after installation.sourcePi-hole documents installing the dnscrypt-proxy tool to use DNS-over-HTTPS or other encrypted DNS protocols between Pi-hole and upstream DNS servers.sourcePi-hole says configuring a router so DHCP clients use Pi-hole as their DNS server applies content blocking to all connected devices without further intervention.source
Quad9Quad9 identifies the Swiss foundation Quad9 as the responsible party for its data and website privacy and points to relevant Commercial Register documents.sourceQuad9 says it integrates commercial and publicly available threat-intelligence feeds that identify exploits, malware, ransomware, spyware, and other potentially harmful sites, with partner feeds updated as new domain-based risks emerge.sourceQuad9 says all of its services accept DNS over TLS queries on standard port 853.sourceQuad9 says users can protect all devices on a network by changing the DNS servers configured in the router instead of changing each device individually.source

Source: 5 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.

Field definitions

Blocklist sources
Built-in, third-party, custom, or other filtering inputs and their update, selection, plan, platform, and scope qualifiers.
Encrypted DNS support
Documented protocol, endpoint, client or server role, setup requirement, plan, platform, scope, and limitations.
Router deployment
Documented network-level setup path, prerequisites, router or firmware scope, configuration locator, plan, and limits.

Source availability and audit records are different evidence types

A public repository identifies only the documented component and version scope, while an audit cell records only the assessment artifact, assessor, period, and scope named by its source.

Source availability records the component, repository or artifact locator, version or release locator, license, and limitations established by the current cell. A public repository for a client, daemon, list, documentation set, or another named component does not establish that every hosted service, policy system, resolver operation, deployment, or release is public. The component boundary remains part of the value.

The assessment column answers a separate question. It records the assessor, scope, standard, period or date, report locator, publication status, and stated limitations when the captured source supplies them. A vendor-published assessment reference remains at the claim type stored with its cell. The presence of an artifact does not independently verify every product claim, version, infrastructure layer, or present-day behavior.

Four rows carry a verified absence for the audit field under the declared method. That label means the specified primary documents did not disclose an assessment artifact within the capture boundary. It does not mean no audit exists, no private assessment occurred, no security work was performed, or the product failed an assessment. The page preserves the stored label and explanation instead of shortening it to none or unaudited.

Neither column is a trust badge. Source availability is not an assessment, and an assessment is not a complete source inventory. Both remain dated records whose usefulness depends on the named component, scope, version, period, and limitations.

Source availability and audit records are different evidence types
JurisdictionSource availabilityAssessment record
AdGuard DNSAdGuard DNS identifies ADGUARD SOFTWARE LIMITED, registered in Limassol, Cyprus, as the data controller for personal-data processing.sourceAdGuard DNS describes itself as an alternative solution for tracker blocking, privacy protection, and parental control.sourceUnknown Verified absenceNot disclosed in the captured primary source.source
Control DControl D's agreement identifies ControlD Inc. as the owner of Control D and a company registered in Ontario, Canada.sourceControl D describes a highly configurable DNS forwarding proxy.sourceControl D offers an attestation letter for download for its completed SOC 2 Type II audit.source
NextDNSNextDNS's terms define “NextDNS” as NextDNS Inc., a Delaware corporation.sourceNextDNS describes its CLI as a command-line tool for using its DNS-over-HTTPS service with advanced capabilities.sourceUnknown Verified absenceNot disclosed in the captured primary source.source
Pi-holePi-hole Core's copyright notice names Pi-hole, LLC.sourcePi-hole describes its software as free and open source and says it helps keep privacy under the user's sole control.sourceUnknown Verified absenceNot disclosed in the captured primary source.source
Quad9Quad9 identifies the Swiss foundation Quad9 as the responsible party for its data and website privacy and points to relevant Commercial Register documents.sourceQuad9 says its public-facing documentation is available at docs.quad9.net.sourceUnknown Verified absenceNot disclosed in the captured primary source.source

Source: 5 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.

Field definitions

Source availability
Named component, repository or artifact locator, version, release locator, license, scope, and limitations stated by the cell.
Assessment record
Assessor, scope, standard, period or date, report locator, publication status, and limitations stated by the cell.

How to read this matrix without turning it into a ranking

Read every cell as a dated, scoped record of vendor-published or public-repository evidence, not as a score, rank, product test, best label, or prediction of current behavior.

The roster is deliberately bounded to AdGuard DNS, Control D, NextDNS, Pi-hole, and Quad9. Inclusion does not endorse a path, and omission does not criticize an unlisted path. Alphabetical display order carries no preference. The comparison does not add a provider because it is popular, remove one because a field is unknown, or turn the number of documented fields into a completeness score.

Capture dates report when each source was collected. They do not promise that a policy, repository, interface, plan, platform, endpoint, or service has remained unchanged. Vendor-stated evidence describes the source at its captured scope; public-repository evidence describes the named artifact and version. The page does not independently test resolver behavior, speed, availability, blocking accuracy, security, protocol negotiation, router compatibility, or the completeness of any document set.

Typed unknowns remain field-specific. A verified absence means the declared primary documents did not disclose the field under the recorded method, not that the feature, report, process, or capability cannot exist. A not-applicable value preserves an operating-model boundary. Another unknown preserves a gap rather than converting it into no, none, unsupported, zero, or a favorable privacy inference.

Managed resolvers and the local Pi-hole deployment are comparable here only at the named attribute grain. The table does not claim that they place the same actor in the query path or create the same account, logging, custody, maintenance, or network relationships. Encrypted transport is likewise one field, not proof of anonymity, non-collection, filtering quality, or protection for destination traffic.

The methodology and correction route remains the privacy-tools hub. The private phone-number comparison applies the same separation between a provider's collection and the identifier exposed to another party. These links provide adjacent evidence models; they do not fill or override any DNS cell.

How to read Unknown

Unknown: Verified absence
The captured authority was searched and shows no such rule or filing. No value is printed because the absence is the finding. The reason and the authority are printed beside the badge.
Unknown: Not yet verified
The captured sources did not settle this field yet. No value is printed, not even an earlier one. The reason is printed beside the badge, and an authority is linked only when one was supplied.

Frequently asked questions

Does encrypted DNS mean a resolver keeps no query logs?

No. This matrix treats encrypted DNS as documented transport support and reports query-logging defaults and retention in a separate sourced field.

Is Pi-hole a managed DNS resolver service?

This comparison represents Pi-hole as a local deployment path where its cells say so; it does not rewrite Pi-hole as a managed recursive resolver operating the user's DNS logs.

What is the difference between DNS-log retention and DNS-log region?

Retention describes the documented category, trigger, duration, choices, and exceptions, while region describes only the documented storage, processing, or selection scope.

Can DNS filtering be applied at the router level?

The matrix reports each path's documented router-level setup and prerequisites. It does not assume that one configuration works on every router, firmware version, device, or network path.

Does a public repository or audit prove an entire DNS service is private?

No. A repository supports only its named component and version scope, and an assessment record supports only the artifact, assessor, period, and scope recorded by its cell.