Website profiles · Technology insights · Alternatives

quad9.net No paid content found Multilingual

Categories: Security & Privacy

A public and free DNS service for a better security and privacy

Visit website

Updated: 2026-09-24 21:29 Language: English (default) Access: Normal

Profile views 1 Outbound visits 0
Quad9 Full homepage screenshot

Related questions

More questions →
What Does Security Mean for a CDN and Edge Platform?

Security on a CDN and edge platform means filtering and absorbing malicious traffic at edge nodes before it reaches your origin server. Instead of only hardening the origin, you distribute protection across a global network so attacks are mitigated closer to their source. This matters most when your site faces volumetric attacks, application-layer exploits, or automated abuse, and when you want to avoid exposing your origin IP directly. Tencent EdgeOne, for example, positions security alongside acceleration, serverless, and video delivery as a core edge capability.

The core security layers

A CDN/edge platform typically bundles several distinct protections. They address different threats and are often enabled independently.

Layer What it does Threat it addresses When you need it
DDoS mitigation Absorbs and disperses high-volume traffic across edge nodes Volumetric floods (L3/L4 and large L7 floods) Any public-facing site; critical for sites that attract attention or have thin origin capacity
WAF (Web Application Firewall) Inspects HTTP requests against rule sets SQL injection, XSS, command injection, known exploit patterns Sites with login forms, APIs, CMS platforms, or user input
Bot management Distinguishes human traffic from automated clients Credential stuffing, scraping, inventory hoarding, spam Sites with accounts, e-commerce, or valuable content
TLS/SSL Encrypts traffic between client and edge (and often edge to origin) Eavesdropping, tampering, man-in-the-middle Every site handling any user data or requiring trust

These layers are complementary. DDoS mitigation keeps your service online under flood; WAF blocks exploit attempts that slip past volume-based defenses; bot management handles low-and-slow abuse that looks like normal traffic; TLS protects data in transit.

How edge-based security differs from origin-only protection

With origin-only protection, every request reaches your server before it is evaluated. Your origin absorbs the full attack volume, and its IP is often discoverable.

With edge-based security, requests terminate at an edge node first. The edge:

  • Filters or challenges suspicious requests before forwarding.
  • Absorbs volumetric attacks across many nodes rather than one server.
  • Hides the origin IP when configured correctly, so attackers cannot target it directly.

The practical difference: origin-only defenses fail when the attack exceeds origin capacity. Edge defenses scale with the network, so capacity is less of a bottleneck. The trade-off is that you must route traffic through the edge consistently — if your origin IP leaks or is reachable directly, attackers can bypass the edge entirely.

Which protection addresses which threat

  • Volumetric DDoS: needs DDoS mitigation with enough edge capacity to absorb the flood. Origin-only rate limiting usually fails here because the pipe itself saturates.
  • Application exploits (injection, XSS): needs WAF rules. These attacks are small in volume, so DDoS mitigation alone will not stop them.
  • Credential stuffing and scraping: needs bot management. These requests often look legitimate at the network level, so volume-based defenses miss them.
  • Data interception: needs TLS end-to-end. Terminating TLS only at the edge without re-encrypting to origin leaves the edge-to-origin leg exposed.

A site can need all four, or only some. A static marketing site with no login may only need DDoS mitigation and TLS. An e-commerce site with accounts and checkout needs all four.

Practical steps to evaluate and enable security on a CDN/edge platform

  1. Inventory your exposure. List public endpoints, login flows, APIs, and any user input. This tells you which layers are relevant.
  2. Confirm origin IP is not directly reachable. If it is, edge security is bypassable. Restrict origin to accept traffic only from edge nodes.
  3. Enable TLS end-to-end. Configure certificates at the edge and verify the edge-to-origin leg is encrypted, not plaintext.
  4. Turn on DDoS mitigation. Usually always-on; verify the platform's capacity and whether it auto-scales.
  5. Deploy WAF in monitor mode first. Log what would be blocked before enforcing, to avoid breaking legitimate traffic.
  6. Add bot management where accounts or content value exist. Start with detection, then move to challenge/block.
  7. Test with a controlled request. Send a known-malicious pattern (e.g., a test SQLi string) and confirm it is blocked. Send normal traffic and confirm it passes.

Common misconfigurations and how to verify

  • Origin IP exposed. Verify by resolving your domain and checking whether the origin responds directly. If it does, lock it down.
  • WAF in monitor-only mode left on. Check logs for blocked vs. logged events; if nothing is ever blocked, enforcement may be off.
  • TLS terminated at edge but plaintext to origin. Inspect the edge-to-origin connection; if it is HTTP, data is exposed internally.
  • Bot rules too aggressive. Watch for legitimate users getting challenged; tune thresholds against real traffic.
  • DDoS protection untested. Run a controlled load test within allowed limits to confirm mitigation engages.

Verification is the same for each layer: send a request that should be blocked and confirm it is, then send a request that should pass and confirm it is not blocked. If both behave as expected, the layer is working.

Choosing what matters for your site

Match protections to your actual risk rather than enabling everything by default. A brochure site needs TLS and DDoS mitigation. A site with logins and payments needs WAF and bot management too. The decision hinges on whether you have user input, accounts, or valuable content — those are the conditions that make WAF and bot management worth the configuration effort. EdgeOne bundles these capabilities with its CDN and edge platform, so the evaluation question becomes which layers your site actually requires, not whether the platform offers them.

Website Overview

Identifiable technologies and additional version or configuration signals make the service easier to fingerprint, which may help targeted scanners narrow their checks. An established domain and managed infrastructure suggest continuity of operations and may support dependable delivery, although neither guarantees service quality.

Domain and Registration

Registered in 2017, this domain has about 9 years of history. That suggests continuity, although ownership and purpose may have changed. Transfer-protection status is present, helping reduce the risk of unauthorized domain transfers. The domain uses the common .net extension, which is not an independent safety signal.

DNS and Email

Nameservers are provided by pch.net, indicating managed DNS hosting. MX records point to the quad9.net email service. No CNAME was found; the observed records resolve directly to addresses. SPF and DMARC are configured. DKIM status is unknown. TXT records include verification markers for Google. Such markers may also remain after a service stops being used.

TLS and Certificates

The public key uses EC with 256 bits. The server supplied a complete certificate chain. No organization name is present in the certificate; the available fields are consistent with domain validation. The certificate was issued by Let's Encrypt, commonly associated with automated certificate services. The certificate's total validity is about 89 days, consistent with a short renewal cycle.

HTTP and Browser Security

The Server header exposes the software version: nginx/1.22.1. This makes version-targeted checks easier, but is not proof of an exploitable vulnerability. No X-Powered-By header was found, reducing one common source of backend fingerprinting information. All six checked browser-security headers are present. Their effectiveness still depends on the policy values and application behavior. No obvious internal addresses or debug information were found in the headers. No explicit CDN or WAF marker was found in the response headers.

Technology Stack Analysis

The public page identifies Hugo 0.147.8, nginx 1.22.1, with exact versions exposed for 2 technologies. These details can narrow vulnerability checks, although exposure alone is not a vulnerability.

Search and Social Sharing

The title has 71 characters and may be truncated in search results. The Generator tag identifies Hugo 0.147.8, making the publishing system easier to fingerprint. No homepage canonical URL was detected. If duplicate URLs exist, consolidation may be less explicit. Twitter Card metadata is configured. The page declares 6 language or regional alternatives using hreflang.

Hosting and Email

DNSpch.net
HostingSWITCH
Emailquad9.net
Location Switzerland flagGeneva, Switzerland 195.176.255.138

User reviews (0)

  • No reviews yet.

Pages, Search and Sharing

Meta descriptionA public and free DNS service for a better security and privacy
Canonical URLNot detected
LanguageEnglish (default) · Multilingual
Twitter Cardsummary_large_image
All bots 0 allowed · 1 disallowed
  • Disallow/result

Registration details RDAP / WHOIS

RegistrarKey-Systems GmbH
Registered2017-05-25
Expires2027-05-25
Domain statusclient delete prohibited、client transfer prohibited、server delete prohibited、server transfer prohibited、server update prohibited
Nameserversanyns.pch.net、ns2.pch.net、ns3.pch.net
DNSSECunsigned

DNS records

TypeNameValueTTLPriority
Aquad9.net195.176.255.138252—
AAAAquad9.net2001:620:2020:5:9::1381200—
MXquad9.netmx4.quad9.net30010
NSquad9.netanyns.pch.net172800—
NSquad9.netns2.pch.net172800—
NSquad9.netns3.pch.net172800—
TXTquad9.netgoogle-site-verification=pubFqUAodApNRC6sXcA_NNli9mak_IIlLSu6SWjyvPg1200—
TXTquad9.netslack-domain-verification=EhulLkEHEcEGaLail027zEvZEfO54vuTRtNOKfY91200—
TXTquad9.netv=spf1 a mx include:_spf.quad9.net include:mail.zendesk.com include:servers.mcsv.net ~all1200—
DMARC_dmarc.quad9.netv=DMARC1; p=quarantine; sp=none; rua=mailto:[email protected]; fo=11200—

TLS and certificates

AssessmentNormal configuration
Supported protocolsTLSv1.2、TLSv1.3
Negotiated protocolTLSv1.3
Certificate subjectquad9.net
IssuerLet's Encrypt
Valid until2026-11-04T22:28 · Remaining when checked: 41 days
Verification detailsCertificate trust: Passed · Hostname match: Passed

HTTP response headers

HeaderValue
content-typetext/html
servernginx/1.22.1
strict-transport-securitymax-age=63072000; includeSubdomains; preload
content-security-policydefault-src 'none'; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' blob: dat; media-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; manifest-src 'self'; frame-ancestors 'none'; connect-src 'self' https://quad9.net/ https://quad9.zendesk.com/ https://api.quad9.net/ https://view.quad9.net/
x-content-type-optionsnosniff
referrer-policysame-origin
permissions-policygeolocation=(), camera=(), microphone=(), magnetometer=(), local-network-access=(), midi=(), idle-detection=(), gyroscope=()

Identified technologies

Hugo 0.147.8nginx 1.22.1