Skip to content

Commit b392c00

Browse files
author
tuanductran
committed
feat(ui): align dashboard guidance with current settings
1 parent 011eadd commit b392c00

4 files changed

Lines changed: 157 additions & 77 deletions

File tree

skills/nextdns-ui/AGENTS.md

Lines changed: 81 additions & 37 deletions
Original file line numberDiff line numberDiff line change
@@ -55,47 +55,67 @@ Visibility and troubleshooting tools
5555

5656
Monitor your network activity and troubleshoot issues through real-time logs and detailed analytics.
5757

58-
- **Real-time Monitoring**: See every DNS query hitting the NextDNS resolver.
58+
- **Real-time Monitoring**: See recent DNS events hitting the NextDNS resolver.
5959

60-
- **Search and Filter**:
60+
- **Search and Filter**: Select a device scope such as **All devices** and search the log list for a
6161

62-
- **Blocked Queries Only**: Quickly identify what is being blocked.
62+
domain or event. Keep account-wide filtering separate from per-device identification.
6363

64-
- **Raw DNS Logs**: View absolute DNS record details.
64+
- **Event inspection**: Expand an individual log row to inspect the event details exposed by the UI,
6565

66-
- **Identification**: To find out **why** a domain is blocked, hover over the information icon
66+
including the queried domain, source or device context, and relative time.
6767

68-
(****) next to the query. It will tell you the specific blocklist or security feature
68+
- **Identification**: To find out **why** a domain is blocked, use the event details and the profile's
6969

70-
responsible.
70+
blocking controls to distinguish a blocklist, security feature, parental-control rule, or manual
7171

72-
- **Direct Action**: You can allow or block domains directly from the log entry using the checkmark
72+
deny rule.
7373

74-
or cross icons.
74+
- **Direct Action**: If the current UI exposes allow or block actions from a log entry, confirm the
7575

76-
- **Reloading**: Use the reload icon to check for the most recent queries after making configuration
76+
target domain and profile before applying the action.
7777

78-
changes.
78+
- **Reloading**: Refresh the log view after making configuration changes and verify that new events
7979

80-
- **Global Overview**: Track total queries and the percentage of blocked requests.
80+
use the intended profile and device scope.
8181

82-
- **Insights**:
82+
Use the device selector and time-range selector before interpreting any chart. The dashboard can
8383

84-
- **Top Domains**: Identify the most requested domains.
84+
show a global view such as **All devices** over a recent period, but the selected scope changes the
8585

86-
- **Top Reasons**: See which rules are triggering the most blocks.
86+
meaning of every count.
8787

88-
- **Top Clients**: Identify which devices are the most active on your network.
88+
- **Global Overview**: Track total queries, blocked queries, and the blocked-query percentage.
8989

90-
- **Retention**: Data in the Analytics tab respects your chosen retention period in Settings.
90+
- **Resolved versus blocked domains**: Compare domains resolved without a block to domains blocked
9191

92-
- Periodically check the **Blocked Queries Only** filter to ensure no essential services are being
92+
by Security, Privacy, Parental Control, or a manual deny rule.
9393

94-
blocked.
94+
- **Insights**: Review blocked reasons, devices, client IPs, root-domain aggregates, GAFAM dominance,
9595

96-
- Use the **Analytics** to understand the traffic patterns on your network and identify potential
96+
encrypted-DNS percentage, DNSSEC validation percentage, and traffic destinations by country.
9797

98-
issues (like a device making excessive requests).
98+
- **Retention**: Analytics and logs are bounded by the profile's retention and privacy settings;
99+
100+
do not infer historical completeness when retention or client-IP logging is limited.
101+
102+
A domain count is not the same as a unique application or user count. Root-domain aggregates combine
103+
104+
subdomains, IP sections may contain multiple addresses for one network, and **Unidentified devices**
105+
106+
indicate that the selected connection did not provide a usable device identity. Use the Setup page's
107+
108+
identification instructions before treating device-level analytics as complete.
109+
110+
- Periodically use the device scope and search controls to inspect recent events and ensure that no
111+
112+
essential services are being blocked.
113+
114+
- Use **Analytics** to understand traffic patterns, compare resolved and blocked domains, and identify
115+
116+
potential issues such as a device making excessive requests.
117+
118+
- [NextDNS Dashboard](https://my.nextdns.io/)
99119

100120
- [NextDNS Help Center](https://help.nextdns.io)
101121

@@ -113,48 +133,72 @@ Manage your NextDNS profile settings, log storage, and performance optimizations
113133

114134
- **Logs Enabled**: Toggle on/off log recording.
115135

116-
- **Log Retention**: Choose how long to keep logs (from 1 hour to 3 months).
136+
- **Privacy adjustments**: Choose independently whether to retain client IP addresses and queried
137+
138+
domains in logs.
117139

118-
- **Log Storage Location**: **Switzerland** is often recommended by privacy enthusiasts due to their
140+
- **Log Retention**: Choose a retention window from **1 hour** through **2 years**. Treat retention
119141

120-
strong data protection laws.
142+
and storage location as profile settings, not as proof that a particular legal or privacy regime
121143

122-
- **Block Page**: Display a dedicated page when a site is blocked.
144+
applies to every deployment.
123145

124-
- **Caution**: This setting can break **PayPal 2FA**, **iCloud Private Relay**, **Microsoft
146+
- **Log Storage Location**: Select the location exposed by the dashboard for the profile.
125147

126-
Teams**, and **Yahoo! Mail**. Only enable if you have installed the NextDNS Root CA.
148+
- **Block Page**: Display a page when a domain is blocked. This can slightly increase page-load time
149+
150+
and may produce HTTPS warnings. When disabled, blocked queries are answered with the unspecified
151+
152+
address `0.0.0.0` or `::`.
153+
154+
- **Log operations**: Use **Download logs** for export and treat **Clear logs** as destructive because
155+
156+
it permanently removes the profile's stored logs.
127157

128158
- **Anonymized EDNS Client Subnet**: Often enabled by default to improve CDN routing without
129159

130160
exposing your full IP.
131161

132162
- **Cache Boost**: Recommended for performance. It tells clients to keep DNS answers longer.
133163

134-
- **CNAME Flattening**: Reduces the number of DNS queries.
164+
- **CNAME Flattening**: Prevent CNAME-chasing resolvers from making unnecessary intermediate
165+
166+
queries that can pollute logs.
167+
168+
- **Rewrites**: Override DNS responses for a domain and its subdomains. Local IP addresses are
135169

136-
- **Warning**: May break compatibility with services like **Yahoo! Mail**.
170+
supported as answers.
137171

138-
- **Rewrites**: Manually redirect any domain or subdomain (for example, `local.home` to `192.168.1.1`).
172+
- **Bypass Age Verification (beta)**: Acknowledge the legal-age requirement before enabling the
139173

140-
- **Bypass Age Verification**: Allows accessing content that requires age verification via DNS
174+
dashboard's age-verification bypass feature. Do not present this beta feature as a universal
141175

142-
identification (added August 2025).
176+
content-access guarantee.
143177

144-
- **Known limitation**: Community reports (NextDNS Help Center, early 2026) describe the feature
178+
- **Web3 (beta)**: Enable the dashboard's unfiltered gateway for decentralized naming and content
145179

146-
as inconsistent — it has been intermittently pulled from the dashboard due to bugs, and
180+
systems such as ENS, Unstoppable Domains, Handshake, and IPFS. Browsers may require a trailing `/`
147181

148-
behavior varies by site and country. Don't treat it as a guaranteed bypass; verify it still
182+
when opening a Web3 domain directly.
149183

150-
works for the target site/region before relying on it.
184+
- **Access (beta)**: Invite another person with editing or viewing-only access to the profile. Share
151185

152-
- **Web3**: Enable resolution of decentralised domains (HNS, ENS, and more).
186+
access deliberately because an editor can change filtering and logging behavior.
187+
188+
- **Duplicate**: Copy all profile settings to a new profile before experimenting with a high-impact
189+
190+
change.
191+
192+
- **Delete**: Deleting a profile also permanently deletes its associated logs. Confirm the target
193+
194+
profile before using this action.
153195

154196
- **Set-and-Forget**: If you want a trouble-free experience, stick to the **NORMAL** or **PRO**
155197

156198
blocklists and avoid aggressive security settings like "Block Newly Registered Domains".
157199

200+
- [NextDNS Dashboard](https://my.nextdns.io/)
201+
158202
- [NextDNS Help Center](https://help.nextdns.io)
159203

160204
### 1.3 Denylist and Allowlist

skills/nextdns-ui/SKILL.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ description:
77
license: MIT
88
metadata:
99
author: tuanductran
10-
version: '1.0.1'
10+
version: '1.1.0'
1111
---
1212

1313
# NextDNS web UI skills
@@ -21,8 +21,8 @@ metadata:
2121
| [parental-control](rules/parental-control.md) | apps and games, categories, recreation time, restricted mode | Set up restrictions for family members |
2222
| [ddns-settings](rules/ddns-settings.md) | linked ip, ddns, noip, dynamic dns, router | Manage network IP linking and dynamic DNS |
2323
| [denylist-allowlist](rules/denylist-allowlist.md) | block domain, allow domain, allowlist, fixing breakage | Manually manage domain accessibility |
24-
| [analytics-logs](rules/analytics-logs.md) | monitoring, logs, blocked queries, identifier | Monitor network activity and troubleshoot |
25-
| [configuration-management](rules/configuration-management.md) | profile name, log location, performance, cache boost | Manage profile global settings |
24+
| [analytics-logs](rules/analytics-logs.md) | monitoring, logs, blocked queries, device filter, time range, DNSSEC, encrypted DNS | Interpret dashboard analytics and troubleshoot recent events |
25+
| [configuration-management](rules/configuration-management.md) | profile name, log location, retention, performance, cache boost, profile sharing, age verification, web3 | Manage profile settings and lifecycle safely |
2626
| [web3-settings](rules/web3-settings.md) | web3, blockchain, ens, unstoppable domains | Enable resolution for blockchain domains |
2727
| [rewrites](rules/rewrites.md) | rewrites, custom dns, hostname override, local dns, cname | Override DNS resolution for hostnames |
2828
| [root-ca-installation](rules/root-ca-installation.md) | root ca, certificate, block page, https, ssl, windows, macos, ios, android | Install Root CA to enable HTTPS block pages |

skills/nextdns-ui/rules/analytics-logs.md

Lines changed: 39 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,10 @@ tags:
1010
- query count
1111
- analytics
1212
- traffic analysis
13+
- device filter
14+
- time range
15+
- dnssec
16+
- encrypted dns
1317
---
1418

1519
# Analytics and logs
@@ -20,34 +24,48 @@ Monitor your network activity and troubleshoot issues through real-time logs and
2024

2125
## Logs tab
2226

23-
- **Real-time Monitoring**: See every DNS query hitting the NextDNS resolver.
24-
- **Search and Filter**:
25-
- **Blocked Queries Only**: Quickly identify what is being blocked.
26-
- **Raw DNS Logs**: View absolute DNS record details.
27-
- **Identification**: To find out **why** a domain is blocked, hover over the information icon
28-
(****) next to the query. It will tell you the specific blocklist or security feature
29-
responsible.
30-
- **Direct Action**: You can allow or block domains directly from the log entry using the checkmark
31-
or cross icons.
32-
- **Reloading**: Use the reload icon to check for the most recent queries after making configuration
33-
changes.
27+
- **Real-time Monitoring**: See recent DNS events hitting the NextDNS resolver.
28+
- **Search and Filter**: Select a device scope such as **All devices** and search the log list for a
29+
domain or event. Keep account-wide filtering separate from per-device identification.
30+
- **Event inspection**: Expand an individual log row to inspect the event details exposed by the UI,
31+
including the queried domain, source or device context, and relative time.
32+
- **Identification**: To find out **why** a domain is blocked, use the event details and the profile's
33+
blocking controls to distinguish a blocklist, security feature, parental-control rule, or manual
34+
deny rule.
35+
- **Direct Action**: If the current UI exposes allow or block actions from a log entry, confirm the
36+
target domain and profile before applying the action.
37+
- **Reloading**: Refresh the log view after making configuration changes and verify that new events
38+
use the intended profile and device scope.
3439

3540
## Analytics tab
3641

37-
- **Global Overview**: Track total queries and the percentage of blocked requests.
38-
- **Insights**:
39-
- **Top Domains**: Identify the most requested domains.
40-
- **Top Reasons**: See which rules are triggering the most blocks.
41-
- **Top Clients**: Identify which devices are the most active on your network.
42-
- **Retention**: Data in the Analytics tab respects your chosen retention period in Settings.
42+
Use the device selector and time-range selector before interpreting any chart. The dashboard can
43+
show a global view such as **All devices** over a recent period, but the selected scope changes the
44+
meaning of every count.
45+
46+
- **Global Overview**: Track total queries, blocked queries, and the blocked-query percentage.
47+
- **Resolved versus blocked domains**: Compare domains resolved without a block to domains blocked
48+
by Security, Privacy, Parental Control, or a manual deny rule.
49+
- **Insights**: Review blocked reasons, devices, client IPs, root-domain aggregates, GAFAM dominance,
50+
encrypted-DNS percentage, DNSSEC validation percentage, and traffic destinations by country.
51+
- **Retention**: Analytics and logs are bounded by the profile's retention and privacy settings;
52+
do not infer historical completeness when retention or client-IP logging is limited.
53+
54+
### Interpret dashboard metrics carefully
55+
56+
A domain count is not the same as a unique application or user count. Root-domain aggregates combine
57+
subdomains, IP sections may contain multiple addresses for one network, and **Unidentified devices**
58+
indicate that the selected connection did not provide a usable device identity. Use the Setup page's
59+
identification instructions before treating device-level analytics as complete.
4360

4461
## Best practices
4562

46-
- Periodically check the **Blocked Queries Only** filter to ensure no essential services are being
47-
blocked.
48-
- Use the **Analytics** to understand the traffic patterns on your network and identify potential
49-
issues (like a device making excessive requests).
63+
- Periodically use the device scope and search controls to inspect recent events and ensure that no
64+
essential services are being blocked.
65+
- Use **Analytics** to understand traffic patterns, compare resolved and blocked domains, and identify
66+
potential issues such as a device making excessive requests.
5067

5168
## Reference
5269

70+
- [NextDNS Dashboard](https://my.nextdns.io/)
5371
- [NextDNS Help Center](https://help.nextdns.io)

skills/nextdns-ui/rules/configuration-management.md

Lines changed: 34 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,9 @@ tags:
1010
- performance
1111
- cache boost
1212
- cname flattening
13+
- profile sharing
14+
- age verification
15+
- web3
1316
---
1417

1518
# Configuration management
@@ -22,28 +25,42 @@ Manage your NextDNS profile settings, log storage, and performance optimizations
2225

2326
- **Profile Name**: Use descriptive names like "Router - Stable" or "Browser - Aggressive".
2427
- **Logs Enabled**: Toggle on/off log recording.
25-
- **Log Retention**: Choose how long to keep logs (from 1 hour to 3 months).
26-
- **Log Storage Location**: **Switzerland** is often recommended by privacy enthusiasts due to their
27-
strong data protection laws.
28-
- **Block Page**: Display a dedicated page when a site is blocked.
29-
- **Caution**: This setting can break **PayPal 2FA**, **iCloud Private Relay**, **Microsoft
30-
Teams**, and **Yahoo! Mail**. Only enable if you have installed the NextDNS Root CA.
28+
- **Privacy adjustments**: Choose independently whether to retain client IP addresses and queried
29+
domains in logs.
30+
- **Log Retention**: Choose a retention window from **1 hour** through **2 years**. Treat retention
31+
and storage location as profile settings, not as proof that a particular legal or privacy regime
32+
applies to every deployment.
33+
- **Log Storage Location**: Select the location exposed by the dashboard for the profile.
34+
- **Block Page**: Display a page when a domain is blocked. This can slightly increase page-load time
35+
and may produce HTTPS warnings. When disabled, blocked queries are answered with the unspecified
36+
address `0.0.0.0` or `::`.
37+
- **Log operations**: Use **Download logs** for export and treat **Clear logs** as destructive because
38+
it permanently removes the profile's stored logs.
3139

3240
## Performance and advanced
3341

3442
- **Anonymized EDNS Client Subnet**: Often enabled by default to improve CDN routing without
3543
exposing your full IP.
3644
- **Cache Boost**: Recommended for performance. It tells clients to keep DNS answers longer.
37-
- **CNAME Flattening**: Reduces the number of DNS queries.
38-
- **Warning**: May break compatibility with services like **Yahoo! Mail**.
39-
- **Rewrites**: Manually redirect any domain or subdomain (for example, `local.home` to `192.168.1.1`).
40-
- **Bypass Age Verification**: Allows accessing content that requires age verification via DNS
41-
identification (added August 2025).
42-
- **Known limitation**: Community reports (NextDNS Help Center, early 2026) describe the feature
43-
as inconsistent — it has been intermittently pulled from the dashboard due to bugs, and
44-
behavior varies by site and country. Don't treat it as a guaranteed bypass; verify it still
45-
works for the target site/region before relying on it.
46-
- **Web3**: Enable resolution of decentralised domains (HNS, ENS, and more).
45+
- **CNAME Flattening**: Prevent CNAME-chasing resolvers from making unnecessary intermediate
46+
queries that can pollute logs.
47+
- **Rewrites**: Override DNS responses for a domain and its subdomains. Local IP addresses are
48+
supported as answers.
49+
- **Bypass Age Verification (beta)**: Acknowledge the legal-age requirement before enabling the
50+
dashboard's age-verification bypass feature. Do not present this beta feature as a universal
51+
content-access guarantee.
52+
- **Web3 (beta)**: Enable the dashboard's unfiltered gateway for decentralized naming and content
53+
systems such as ENS, Unstoppable Domains, Handshake, and IPFS. Browsers may require a trailing `/`
54+
when opening a Web3 domain directly.
55+
56+
## Sharing and lifecycle
57+
58+
- **Access (beta)**: Invite another person with editing or viewing-only access to the profile. Share
59+
access deliberately because an editor can change filtering and logging behavior.
60+
- **Duplicate**: Copy all profile settings to a new profile before experimenting with a high-impact
61+
change.
62+
- **Delete**: Deleting a profile also permanently deletes its associated logs. Confirm the target
63+
profile before using this action.
4764

4865
## Maintenance
4966

@@ -52,4 +69,5 @@ Manage your NextDNS profile settings, log storage, and performance optimizations
5269

5370
## Reference
5471

72+
- [NextDNS Dashboard](https://my.nextdns.io/)
5573
- [NextDNS Help Center](https://help.nextdns.io)

0 commit comments

Comments
 (0)