Privacy
What this site and its DNS server record, why, how long each record is kept, and who can see it.
Last updated 5 October 2026
This page covers dnsparanoia.com, dnsp.co, x.dnsparanoia.com, the DNS server that answers for dnsp.co and x.dnsparanoia.com, and the Tor onion version of the site.
Web server logs
The web server keeps an access log for each of dnsparanoia.com, dnsp.co and x.dnsparanoia.com. Each line holds your IP address, the date and time, the page address including anything after the ?, the HTTP status, the response size, the referring page, and your browser's User-Agent string. A separate error log can also hold your IP address and the address you asked for.
The page address includes what you type into forms on this site. A label you search on the log lookup page and the token in a probe report address are therefore written to this log.
Logs rotate daily and seven are kept, so entries are deleted within seven days. A copy also goes to the web server's container log, which is capped at a few tens of megabytes and holds well under a day.
The logs are used to run and protect the site. fail2ban reads them and blocks, for 24 hours, addresses that make requests no visitor of this site makes, such as asking for .asp pages. The logs are not shared and not combined with other data.
dnsp.co sends every visitor to dnsparanoia.com. x.dnsparanoia.com serves one blank image, used by the probe below.
Advertising
Every page on dnsparanoia.com loads Google's AdSense script from pagead2.googlesyndication.com and may show ads served by Google. Google then receives your IP address, your User-Agent and the address of the page, and can set and read its own cookies.
Google, and other advertising companies that Google works with, use cookies to choose ads based on your earlier visits to this site and to other sites. You can turn off ads personalised in this way: for Google, in Google's My Ad Center; for other participating companies, at aboutads.info or, in Europe, youronlinechoices.eu. Google describes what it does with this information in How Google uses information from sites that use its services.
Fonts from Google
Every page loads its typefaces from Google Fonts. Your browser fetches a stylesheet from fonts.googleapis.com and font files from fonts.gstatic.com. Those requests go to Google and carry your IP address and your browser's request headers, including its User-Agent. This is the one request the site causes to another company's servers.
Pages on dnsparanoia.com load Google's AdSense script, described under Advertising below. There is no tracking pixel. The site's own code sets no cookies and stores nothing in your browser.
The DNS server: whose address it sees
Most of the tests on this site are DNS queries to the server at dnsp.co. A query normally reaches it from your resolver, the machine that looks names up on your behalf, so the address it records is the resolver's. If you aim a query straight at the server, for example dig @dnsp.co, the address it records is yours.
The DNS server does not write individual queries to its console log. What it does record is described in the sections below.
Rate limiting
For every query, the server stores the sending address, the time of its first query, and a running count of its queries. It uses this to drop queries from an address that sends them faster than set limits.
These rows are not deleted on a schedule. An address's row is removed when that address has sent more than 10 queries and then sends another more than 10 seconds after its first, at under one query per second on average. Any other row stays in the database. No page on this site displays them.
log.dnsp.co
For every query for a name under log.dnsp.co, the server stores the full name, the sending address, and how many times that address has asked for that name. It stores no date or time.
These records are not deleted automatically. They are kept until the database is wiped by hand.
Showing them back is the purpose of the test. Anyone who asks for the same name over TCP, or enters the same label on the log lookup page, sees every address that has asked for it and how many times. No other check is made.
The probe and x.dnsparanoia.com
The probe page makes a random 16-character token in your browser and has your browser look up a name containing it under x.dnsparanoia.com. For every query that arrives under that zone, the server stores:
- the token, and the date and time to the millisecond
- the name as it arrived, keeping its capitalisation, and the record type
- the transport (UDP, TCP or DNS over TLS) and the sending address
- the complete query packet, in hexadecimal
- EDNS details: payload size, version, the DNSSEC flag, padding length, the names of any options, and NSID
- EDNS Client Subnet, if the resolver sent it: the subnet, address family and prefix lengths. This is a shortened form of the address of the device that made the lookup.
- the DNS cookie the resolver sent, if any, and whether it carried a server cookie
- for DNS over TLS: the protocol version, cipher, cipher strength in bits, the server name the client offered (SNI), the negotiated ALPN, and whether a client certificate was presented
Every five minutes the server deletes rows older than 60 minutes, so each row is deleted between 60 and 65 minutes after it was written.
The report at dns_probe.html?token=… shows the names, types, times, transports, sending addresses, client subnet, DNSSEC flag, whether a cookie was sent, and the TLS version and cipher. Anyone who has the token can open the report. No other check is made. The raw packet, the cookie value and the SNI are stored but not shown.
Your browser also requests a blank image from that name. That request, if it connects, is logged by the web server as described above. The token is part of the host name, which that log does not record.
Other tests
The QNAME minimisation test (min.dnsp.co) keeps the names, record types and arrival times seen under each token in the server's memory for 15 minutes, so that minreport.dnsp.co can report them. It keeps no addresses and writes nothing to disk.
relay.dnsp.co removes its own suffix from the name and passes the rest to the resolvers configured on the server (1.1.1.1 and 8.8.8.8 if none are configured). That resolver sees the name, sent from this server's address.
The remaining tests, such as reflect, raw, edns, ecs and tls, build their answer from the query and send it back to whoever asked. Nothing from them is stored.
Scan log and automatic blocking
The same DNS server also answers for other sites. When one address asks for more than 60 different names under those sites' wildcard zones within 60 seconds, the server writes one line to a scan log: the date and time, the address, the number of names, and the time window. Queries for dnsparanoia.com and dnsp.co names are not counted toward this.
fail2ban reads that log and blocks the address for 24 hours, on every port of the server, which includes this site. The scan log rotates weekly and four old copies are kept, so lines are deleted within about five weeks.
The Tor onion version
The onion version serves the same files and reads the same log and probe data, using a database account that can only read.
- The AdSense script is not loaded.
- Requests reach the web server from Tor on the same machine, so the address in its log is 127.0.0.1 rather than yours. The rest of each line is recorded as above, including the page address with any label or token.
- That log is written only to the container log. There is no daily file, and fail2ban does not read it. No size or age limit is set on it, so it is kept until the container is recreated, which happens when the service is redeployed.
- Tor itself logs at notice level, which does not include individual connections.
- The pages still load fonts from Google. Tor Browser fetches them through Tor, so Google sees a Tor exit address.
- When you run the probe from Tor Browser, the lookup is made by the Tor exit relay's resolver, and that is the resolver the report records.
Contact
Questions about any of this: contact details are at elifulkerson.com.