Privacy-First DNS by NCFA Global
Written by Ansh Padam - COO & Managing Director
Privacy shouldn't be a premium feature. It should be the default.
Every time you visit a website, open an app, or connect to an online service, your device first needs to find out where that service lives on the internet. It does this using something called DNS. Most people never think about it, but DNS is one of the biggest sources of personal data on the internet.
At NCFA Global, we believe everyone deserves access to private internet infrastructure, regardless of whether they can afford expensive privacy services or host their own. That's why we built NCFA Privacy-First DNS. A free, public DNS resolver designed around one simple principle:
Privacy by default.
What is DNS?
DNS (Domain Name System) is often described as the internet's phonebook.
Instead of remembering IP addresses like:
57.129.129.227you simply type:
ncfa-global.comYour device asks a DNS resolver where that website is located, receives the correct address, and connects you automatically.
This happens thousands of times every day on your phone, laptop, smart TV and even many smart home devices.
Why does DNS matter for privacy?
Every DNS lookup reveals something about what you're doing online.
For example:
Which websites you're visiting
Which apps you're using
Which services your devices connect to
When those requests were made
Many traditional DNS providers log this information to improve services, analyse traffic, troubleshoot networks or provide statistics.
While many providers have excellent privacy policies, we wanted to ask a different question:
What if the data simply didn't exist in the first place?
Our approach
Instead of forwarding your DNS requests to another company, our resolver performs the lookups itself.
That means your requests aren't passed through multiple third-party DNS providers before reaching their destination.
Our infrastructure was built from the ground up with privacy as the primary objective.
What makes NCFA Privacy DNS different?
✅ No query logging
We don't keep a history of the websites you look up.
Our infrastructure is designed so DNS queries are processed in memory without creating permanent browsing logs.
✅ No third-party upstream resolvers
Many DNS services forward requests to larger public DNS providers.
We don't.
Our resolver communicates directly with the global DNS infrastructure, reducing unnecessary third-party involvement in the lookup process.
✅ Encrypted DNS
We support modern encrypted DNS standards, including:
DNS-over-HTTPS (DoH)
DNS-over-TLS (DoT)
DNS-over-QUIC (DoQ)
These protocols help prevent others on your network—such as public Wi-Fi operators or internet providers—from easily seeing your DNS requests while they're in transit.
✅ Privacy-focused ad & tracker blocking
Our resolver blocks known advertising and tracking domains using two well-respected community-maintained blocklists:
AdAway Default Blocklist
AdGuard DNS Filter
Unlike many filtered DNS services, we don't block social media, news websites, streaming services or other categories of content.
The goal isn't to decide what you should access.
The goal is simply to reduce unnecessary advertising and tracking.
✅ DNSSEC Validation
Every DNS response is cryptographically validated before being returned.
This helps protect against certain forms of DNS spoofing and tampering.
✅ Built for performance
Privacy shouldn't make your internet slower.
Our recursive infrastructure uses intelligent caching and modern DNS standards to deliver fast response times while maintaining strong privacy protections.
What we don't do
Transparency matters.
Our Privacy-First DNS is not designed to:
Filter the internet
Block websites based on opinion or category
Monitor browsing habits
Sell usage data
Build user profiles
Display advertising
Our focus is straightforward:
Private, secure and reliable DNS resolution.
Who is this for?
Our resolver is ideal for:
Individuals who value online privacy
Families looking for a trustworthy public DNS
Students
Small businesses
Developers
Privacy-conscious organisations
Whether you're replacing your ISP's DNS or looking for an alternative public resolver, getting started only takes a few minutes.
Getting Connected
You can connect using whichever method your device supports.
DNS-over-HTTPS (DoH)
Server:
57.129.129.227Template:
https://dns.ncfa-global.com/dns-queryDNS-over-TLS (DoT)
Server:
dns.ncfa-global.comPort:
853DNS-over-QUIC (DoQ)
Server:
dns.ncfa-global.comPort:
853Traditional DNS
IPv4:
57.129.129.227Frequently Asked Questions
Is it free?
Yes, NCFA Privacy-First DNS is provided free of charge.
Do I need an account?
No. There are no accounts, subscriptions or registrations required.
Will this make my internet anonymous?
No. DNS privacy protects your DNS lookups. It does not hide your IP address from websites you visit or replace a VPN.
Will it block adverts?
It blocks many known advertising and tracking domains using the AdAway Default Blocklist and the AdGuard DNS Filter. Some adverts may still appear depending on how a website delivers them.
Is this open to everyone?
Yes. Anyone can use the service.
Our Philosophy
Privacy shouldn't depend on expensive subscriptions, specialist hardware or technical knowledge.
The internet should respect people's privacy by design—not treat it as an optional upgrade.
That belief is what inspired the NCFA Privacy-First DNS project, and it's what continues to guide its development.
NCFA Global Limited
National Cyber & Forensics Alliance
Privacy. Security. Trust.