DNS resolver registry · Canadian Internet Registration Authority (CIRA)

CIRA Canadian Shield DNS servers

CIRA Canadian Shield is run by Canadian Internet Registration Authority (CIRA) and offers 3 service variants with different filtering, reachable over DNS (53), DoT, DoH. Every address and endpoint below is taken from the operator's documentation; the behaviour is what we measured on 2026-09-24.
149.112.121.10
primary address
12
addresses in 3 variants
Does not validate
DNSSEC in our test
None sent
client subnet (ECS)

Addresses

CIRA Canadian Shield DNS addresses by variant

Set the IPv4 or IPv6 addresses as your DNS servers, or use an encrypted endpoint where one is listed.

Canadian Shield Private

Not specified by the operator

IPv4
149.112.121.10
149.112.122.10
IPv6
2620:10A:80BB::10
2620:10A:80BC::10
DoH
https://private.canadianshield.cira.ca/dns-query
DoT
private.canadianshield.cira.ca

Canadian Shield Protected

Malware, phishing, botnets and online scams

IPv4
149.112.121.20
149.112.122.20
IPv6
2620:10A:80BB::20
2620:10A:80BC::20
DoH
https://protected.canadianshield.cira.ca/dns-query
DoT
protected.canadianshield.cira.ca

Canadian Shield Family

Everything in Protected, plus adult content

IPv4
149.112.121.30
149.112.122.30
IPv6
2620:10A:80BB::30
2620:10A:80BC::30
DoH
https://family.canadianshield.cira.ca/dns-query
DoT
family.canadianshield.cira.ca

Measured

What we observed

Measured 2026-09-24 from one vantage point, three rounds per address, majority result. Anycast resolvers can behave differently from other networks. How we test

DNSSEC validation Does not validate

Returned addresses for dnssec-failed.org, rhybar.cz and badsig.go.dnscheck.tools, which a validating resolver would refuse.

Client subnet (ECS)

No client subnet reached the authoritative server from any address we probed.

Plain DNS and NXDOMAIN

6/6 documented IPv4 addresses answered on port 53. Random non-existent names came back as NXDOMAIN, so errors are not rewritten into ads or search pages.

Encrypted endpoints

  • DoH https://private.canadianshield.cira.ca/dns-queryAnswered
  • DoH https://protected.canadianshield.cira.ca/dns-queryAnswered
  • DoH https://family.canadianshield.cira.ca/dns-queryAnswered
  • DoT private.canadianshield.cira.caAnswered
  • DoT protected.canadianshield.cira.caAnswered
  • DoT family.canadianshield.cira.caAnswered

Networks

Which networks carry it

The announcing network comes from RIPEstat routing data for each documented address. The query network is where the resolver sent its own lookups during our probe, which a DNS leak test reports.

Announcing the service addresses

  • AS40568 CIRADNS3 - CIRA Canadian Internet Registration Authority Autorit Canadienne pour les enregistrements Internet

Queried from, in our probe

  • AS5645 TEKSAVVY - TekSavvy Solutions, Inc.
  • AS55195 CIRA-CLOUD1 - CIRA Canadian Internet Registration Authority Autorit Canadienne pour les enregistrements Internet

In the operator's words

Operator statements

Quoted from the operator's pages and checked word for word. We have not audited these practices.
“As a national not-for-profit, CIRA will never sell your personal data or use it to show you ads.”
www.cira.ca

Check it

Confirm your device is using CIRA Canadian Shield

Changing a DNS setting does not guarantee your lookups reach that resolver: a VPN, a browser's own secure DNS or a proxy can send them elsewhere. Our DNS leak test shows which resolvers actually received your queries.

From a terminal

# Which address did the resolver query from?
dig +short whoami.akamai.net @149.112.121.10

# Does it pass your subnet on (ECS)?
dig +short TXT o-o.myaddr.l.google.com @149.112.121.10

# Does it validate DNSSEC? SERVFAIL means yes
dig dnssec-failed.org @149.112.121.10

Behind a proxy

With an HTTP proxy, or a client set to socks5h://, the proxy side resolves hostnames, so your own resolver setting does not apply to that traffic. With socks5:// in curl or Python requests, your device resolves names first. The SOCKS5 vs SOCKS5h guide shows how to check which one you have.

Questions

CIRA Canadian Shield questions

What are CIRA Canadian Shield's DNS server addresses?

Canadian Shield Private: 149.112.121.10, 149.112.122.10, 2620:10A:80BB::10, 2620:10A:80BC::10. Canadian Shield Protected: 149.112.121.20, 149.112.122.20, 2620:10A:80BB::20, 2620:10A:80BC::20. Canadian Shield Family: 149.112.121.30, 149.112.122.30, 2620:10A:80BB::30, 2620:10A:80BC::30.

Does CIRA Canadian Shield validate DNSSEC?

Not in our 2026-09-24 test: it returned addresses for all three deliberately mis-signed domains.

Does CIRA Canadian Shield support DNS over HTTPS or DNS over TLS?

DoH: https://private.canadianshield.cira.ca/dns-query, https://protected.canadianshield.cira.ca/dns-query, https://family.canadianshield.cira.ca/dns-query. DoT: private.canadianshield.cira.ca, protected.canadianshield.cira.ca, family.canadianshield.cira.ca. 6 of 6 answered our test query on 2026-09-24.

Does CIRA Canadian Shield send my IP subnet to other servers (ECS)?

We observed no client subnet on any address we probed.

How can I check that I am using CIRA Canadian Shield?

Run a DNS leak test and compare the network it reports with the one CIRA Canadian Shield queried from in our probe (AS5645, AS55195). On the command line, dig +short whoami.akamai.net @149.112.121.10 returns the address the resolver used to query Akamai.

Sources

Sources and dates

Documentation checked 2026-09-24. Measured 2026-09-24. Registry reviewed 2026-09-24.