Self-host DNS for privacy and security.

Tadoru is being built as a new open source DNS alternative for home networks. Once configured for your devices, it can block unwanted domains, serve local names, and choose where other queries go.

GitHub repository available soon
Why run DNS at home?

Make your network’s DNS your own.

Most devices use the DNS server chosen by their network. That server sees the names they ask for. Configure Tadoru for your network, then point your devices at it to apply your blocking rules.

For outside names, Tadoru can resolve from the root or use an encrypted upstream. It checks signed answers, caches repeat lookups, and can keep known names answering during an upstream outage. You decide what its local query log records.

What Tadoru does

More than a blocklist.

Tadoru resolves names, checks signed answers, serves local zones, and records what happened. You choose how much the log stores.

01

Choose what to block

Use published blocklists or your own names. Add allow rules when a list blocks too much, or pause blocking for a while.

02

Set rules by device

Put clients in groups with different lists and allow rules. Two groups can answer the same name differently.

03

Resolve your way

Resolve from the root, or forward over TLS, HTTPS, or QUIC. Phones and browsers can ask Tadoru over encrypted DNS too. The cache answers repeat lookups and can serve stale answers during an outage.

04

Check the answer

DNSSEC checks signed answers and signed proof that a name does not exist. By default, rebinding protection rejects outside answers that point to private addresses.

05

Name things at home

Give your own devices names under home.arpa. Tadoru answers the records you write in that local zone.

06

See what happened

Read queries by client and see whether an answer came from the cache, a resolver, or a block rule. Choose whether new log rows store names.