DNS resolver registry · Control D

Control D Free DNS DNS servers

Control D Free DNS offers 6 service variants with different filtering, reachable over DNS (53), DoT, DoH. Every address and endpoint below is taken from the operator's documentation; the behaviour is what we measured on 2026-09-24.
76.76.2.0
primary address
24
addresses in 6 variants
Validates
DNSSEC in our test
None sent
client subnet (ECS)

Addresses

Control D Free DNS DNS addresses by variant

Set the IPv4 or IPv6 addresses as your DNS servers, or use an encrypted endpoint where one is listed.

Unfiltered

None

IPv4
76.76.2.0
76.76.10.0
IPv6
2606:1a40::0
2606:1a40:1::0
DoH
https://freedns.controld.com/p0
DoT
p0.freedns.controld.com

Malware

Known dangerous sites

IPv4
76.76.2.1
76.76.10.1
IPv6
2606:1a40::1
2606:1a40:1::1
DoH
https://freedns.controld.com/p1
DoT
p1.freedns.controld.com

Ads & Tracking

Malware, ads and trackers

IPv4
76.76.2.2
76.76.10.2
IPv6
2606:1a40::2
2606:1a40:1::2
DoH
https://freedns.controld.com/p2
DoT
p2.freedns.controld.com

Social

Major social media apps and sites

IPv4
76.76.2.3
76.76.10.3
IPv6
2606:1a40::3
2606:1a40:1::3
DoH
https://freedns.controld.com/p3
DoT
p3.freedns.controld.com

Family Friendly

Malware, ads, trackers, adult content and drug sites

IPv4
76.76.2.4
76.76.10.4
IPv6
2606:1a40::4
2606:1a40:1::4
DoH
https://freedns.controld.com/family
DoT
family.freedns.controld.com

Uncensored

None; unblocks censored domains

IPv4
76.76.2.5
76.76.10.5
IPv6
2606:1a40::5
2606:1a40:1::5
DoH
https://freedns.controld.com/uncensored
DoT
uncensored.freedns.controld.com

Measured

What we observed

Measured 2026-09-24 from one vantage point, three rounds per address, majority result. Anycast resolvers can behave differently from other networks. How we test

DNSSEC validation Validates

Returned SERVFAIL for dnssec-failed.org, rhybar.cz and badsig.go.dnscheck.tools on every address that answered, while resolving example.com.

Client subnet (ECS)

No client subnet reached the authoritative server from any address we probed.

Plain DNS and NXDOMAIN

12/12 documented IPv4 addresses answered on port 53. Random non-existent names came back as NXDOMAIN, so errors are not rewritten into ads or search pages.

Encrypted endpoints

  • DoH https://freedns.controld.com/p0Answered
  • DoH https://freedns.controld.com/p1Answered
  • DoH https://freedns.controld.com/p2Answered
  • DoH https://freedns.controld.com/p3Answered
  • DoH https://freedns.controld.com/familyAnswered
  • DoH https://freedns.controld.com/uncensoredAnswered
  • DoT p0.freedns.controld.comAnswered
  • DoT p1.freedns.controld.comAnswered
  • DoT p2.freedns.controld.comAnswered
  • DoT p3.freedns.controld.comAnswered
  • DoT family.freedns.controld.comNo answer
  • DoT uncensored.freedns.controld.comAnswered

Networks

Which networks carry it

The announcing network comes from RIPEstat routing data for each documented address. The query network is where the resolver sent its own lookups during our probe, which a DNS leak test reports.

Announcing the service addresses

  • AS398962 CONTROLD - CONTROLD INC.

Queried from, in our probe

  • AS212238 CDNEXT Datacamp Limited

Check it

Confirm your device is using Control D Free DNS

Changing a DNS setting does not guarantee your lookups reach that resolver: a VPN, a browser's own secure DNS or a proxy can send them elsewhere. Our DNS leak test shows which resolvers actually received your queries.

From a terminal

# Which address did the resolver query from?
dig +short whoami.akamai.net @76.76.2.0

# Does it pass your subnet on (ECS)?
dig +short TXT o-o.myaddr.l.google.com @76.76.2.0

# Does it validate DNSSEC? SERVFAIL means yes
dig dnssec-failed.org @76.76.2.0

Behind a proxy

With an HTTP proxy, or a client set to socks5h://, the proxy side resolves hostnames, so your own resolver setting does not apply to that traffic. With socks5:// in curl or Python requests, your device resolves names first. The SOCKS5 vs SOCKS5h guide shows how to check which one you have.

Questions

Control D Free DNS questions

What are Control D Free DNS's DNS server addresses?

Unfiltered: 76.76.2.0, 76.76.10.0, 2606:1a40::0, 2606:1a40:1::0. Malware: 76.76.2.1, 76.76.10.1, 2606:1a40::1, 2606:1a40:1::1. Ads & Tracking: 76.76.2.2, 76.76.10.2, 2606:1a40::2, 2606:1a40:1::2. Social: 76.76.2.3, 76.76.10.3, 2606:1a40::3, 2606:1a40:1::3. Family Friendly: 76.76.2.4, 76.76.10.4, 2606:1a40::4, 2606:1a40:1::4. Uncensored: 76.76.2.5, 76.76.10.5, 2606:1a40::5, 2606:1a40:1::5.

Does Control D Free DNS validate DNSSEC?

Yes. On 2026-09-24 every Control D Free DNS address that answered returned SERVFAIL for three deliberately mis-signed domains while resolving ordinary names.

Does Control D Free DNS support DNS over HTTPS or DNS over TLS?

DoH: https://freedns.controld.com/p0, https://freedns.controld.com/p1, https://freedns.controld.com/p2, https://freedns.controld.com/p3, https://freedns.controld.com/family, https://freedns.controld.com/uncensored. DoT: p0.freedns.controld.com, p1.freedns.controld.com, p2.freedns.controld.com, p3.freedns.controld.com, family.freedns.controld.com, uncensored.freedns.controld.com. 11 of 12 answered our test query on 2026-09-24.

Does Control D Free DNS send my IP subnet to other servers (ECS)?

We observed no client subnet on any address we probed.

How can I check that I am using Control D Free DNS?

Run a DNS leak test and compare the network it reports with the one Control D Free DNS queried from in our probe (AS212238). On the command line, dig +short whoami.akamai.net @76.76.2.0 returns the address the resolver used to query Akamai.

Sources

Sources and dates

Documentation checked 2026-09-24. Measured 2026-09-24. Registry reviewed 2026-09-24.