@@ -55,47 +55,67 @@ Visibility and troubleshooting tools
5555
5656Monitor your network activity and troubleshoot issues through real-time logs and detailed analytics.
5757
58- - ** Real-time Monitoring** : See every DNS query hitting the NextDNS resolver.
58+ - ** Real-time Monitoring** : See recent DNS events hitting the NextDNS resolver.
5959
60- - ** Search and Filter** :
60+ - ** Search and Filter** : Select a device scope such as ** All devices ** and search the log list for a
6161
62- - ** Blocked Queries Only ** : Quickly identify what is being blocked .
62+ domain or event. Keep account-wide filtering separate from per-device identification .
6363
64- - ** Raw DNS Logs ** : View absolute DNS record details.
64+ - ** Event inspection ** : Expand an individual log row to inspect the event details exposed by the UI,
6565
66- - ** Identification ** : To find out ** why ** a domain is blocked, hover over the information icon
66+ including the queried domain, source or device context, and relative time.
6767
68- ( ** ⓘ ** ) next to the query. It will tell you the specific blocklist or security feature
68+ - ** Identification ** : To find out ** why ** a domain is blocked, use the event details and the profile's
6969
70- responsible.
70+ blocking controls to distinguish a blocklist, security feature, parental-control rule, or manual
7171
72- - ** Direct Action ** : You can allow or block domains directly from the log entry using the checkmark
72+ deny rule.
7373
74- or cross icons.
74+ - ** Direct Action ** : If the current UI exposes allow or block actions from a log entry, confirm the
7575
76- - ** Reloading ** : Use the reload icon to check for the most recent queries after making configuration
76+ target domain and profile before applying the action.
7777
78- changes.
78+ - ** Reloading ** : Refresh the log view after making configuration changes and verify that new events
7979
80- - ** Global Overview ** : Track total queries and the percentage of blocked requests .
80+ use the intended profile and device scope .
8181
82- - ** Insights ** :
82+ Use the device selector and time-range selector before interpreting any chart. The dashboard can
8383
84- - ** Top Domains ** : Identify the most requested domains.
84+ show a global view such as ** All devices ** over a recent period, but the selected scope changes the
8585
86- - ** Top Reasons ** : See which rules are triggering the most blocks .
86+ meaning of every count .
8787
88- - ** Top Clients ** : Identify which devices are the most active on your network .
88+ - ** Global Overview ** : Track total queries, blocked queries, and the blocked-query percentage .
8989
90- - ** Retention ** : Data in the Analytics tab respects your chosen retention period in Settings.
90+ - ** Resolved versus blocked domains ** : Compare domains resolved without a block to domains blocked
9191
92- - Periodically check the ** Blocked Queries Only ** filter to ensure no essential services are being
92+ by Security, Privacy, Parental Control, or a manual deny rule.
9393
94- blocked.
94+ - ** Insights ** : Review blocked reasons, devices, client IPs, root-domain aggregates, GAFAM dominance,
9595
96- - Use the ** Analytics ** to understand the traffic patterns on your network and identify potential
96+ encrypted-DNS percentage, DNSSEC validation percentage, and traffic destinations by country.
9797
98- issues (like a device making excessive requests).
98+ - ** Retention** : Analytics and logs are bounded by the profile's retention and privacy settings;
99+
100+ do not infer historical completeness when retention or client-IP logging is limited.
101+
102+ A domain count is not the same as a unique application or user count. Root-domain aggregates combine
103+
104+ subdomains, IP sections may contain multiple addresses for one network, and ** Unidentified devices**
105+
106+ indicate that the selected connection did not provide a usable device identity. Use the Setup page's
107+
108+ identification instructions before treating device-level analytics as complete.
109+
110+ - Periodically use the device scope and search controls to inspect recent events and ensure that no
111+
112+ essential services are being blocked.
113+
114+ - Use ** Analytics** to understand traffic patterns, compare resolved and blocked domains, and identify
115+
116+ potential issues such as a device making excessive requests.
117+
118+ - [ NextDNS Dashboard] ( https://my.nextdns.io/ )
99119
100120- [ NextDNS Help Center] ( https://help.nextdns.io )
101121
@@ -113,48 +133,72 @@ Manage your NextDNS profile settings, log storage, and performance optimizations
113133
114134- ** Logs Enabled** : Toggle on/off log recording.
115135
116- - ** Log Retention** : Choose how long to keep logs (from 1 hour to 3 months).
136+ - ** Privacy adjustments** : Choose independently whether to retain client IP addresses and queried
137+
138+ domains in logs.
117139
118- - ** Log Storage Location ** : ** Switzerland ** is often recommended by privacy enthusiasts due to their
140+ - ** Log Retention ** : Choose a retention window from ** 1 hour ** through ** 2 years ** . Treat retention
119141
120- strong data protection laws.
142+ and storage location as profile settings, not as proof that a particular legal or privacy regime
121143
122- - ** Block Page ** : Display a dedicated page when a site is blocked .
144+ applies to every deployment .
123145
124- - ** Caution ** : This setting can break ** PayPal 2FA ** , ** iCloud Private Relay ** , ** Microsoft
146+ - ** Log Storage Location ** : Select the location exposed by the dashboard for the profile.
125147
126- Teams** , and ** Yahoo! Mail** . Only enable if you have installed the NextDNS Root CA.
148+ - ** Block Page** : Display a page when a domain is blocked. This can slightly increase page-load time
149+
150+ and may produce HTTPS warnings. When disabled, blocked queries are answered with the unspecified
151+
152+ address ` 0.0.0.0 ` or ` :: ` .
153+
154+ - ** Log operations** : Use ** Download logs** for export and treat ** Clear logs** as destructive because
155+
156+ it permanently removes the profile's stored logs.
127157
128158- ** Anonymized EDNS Client Subnet** : Often enabled by default to improve CDN routing without
129159
130160 exposing your full IP.
131161
132162- ** Cache Boost** : Recommended for performance. It tells clients to keep DNS answers longer.
133163
134- - ** CNAME Flattening** : Reduces the number of DNS queries.
164+ - ** CNAME Flattening** : Prevent CNAME-chasing resolvers from making unnecessary intermediate
165+
166+ queries that can pollute logs.
167+
168+ - ** Rewrites** : Override DNS responses for a domain and its subdomains. Local IP addresses are
135169
136- - ** Warning ** : May break compatibility with services like ** Yahoo! Mail ** .
170+ supported as answers .
137171
138- - ** Rewrites ** : Manually redirect any domain or subdomain (for example, ` local.home ` to ` 192.168.1.1 ` ).
172+ - ** Bypass Age Verification (beta) ** : Acknowledge the legal-age requirement before enabling the
139173
140- - ** Bypass Age Verification ** : Allows accessing content that requires age verification via DNS
174+ dashboard's age-verification bypass feature. Do not present this beta feature as a universal
141175
142- identification (added August 2025) .
176+ content-access guarantee .
143177
144- - ** Known limitation ** : Community reports (NextDNS Help Center, early 2026) describe the feature
178+ - ** Web3 (beta) ** : Enable the dashboard's unfiltered gateway for decentralized naming and content
145179
146- as inconsistent — it has been intermittently pulled from the dashboard due to bugs, and
180+ systems such as ENS, Unstoppable Domains, Handshake, and IPFS. Browsers may require a trailing ` / `
147181
148- behavior varies by site and country. Don't treat it as a guaranteed bypass; verify it still
182+ when opening a Web3 domain directly.
149183
150- works for the target site/region before relying on it.
184+ - ** Access (beta) ** : Invite another person with editing or viewing-only access to the profile. Share
151185
152- - ** Web3** : Enable resolution of decentralised domains (HNS, ENS, and more).
186+ access deliberately because an editor can change filtering and logging behavior.
187+
188+ - ** Duplicate** : Copy all profile settings to a new profile before experimenting with a high-impact
189+
190+ change.
191+
192+ - ** Delete** : Deleting a profile also permanently deletes its associated logs. Confirm the target
193+
194+ profile before using this action.
153195
154196- ** Set-and-Forget** : If you want a trouble-free experience, stick to the ** NORMAL** or ** PRO**
155197
156198 blocklists and avoid aggressive security settings like "Block Newly Registered Domains".
157199
200+ - [ NextDNS Dashboard] ( https://my.nextdns.io/ )
201+
158202- [ NextDNS Help Center] ( https://help.nextdns.io )
159203
160204### 1.3 Denylist and Allowlist
0 commit comments