The arrangement
Why ΕΛΠΙΣ exists
Every website you have ever opened began with somebody being asked a question on your behalf: where is this? It is a small question. It is also a complete record of your curiosity, handed over in the clear, several hundred times a day, to whoever your network happened to name.

ΕΛΠΙΣ is that question answered by people who want nothing from it. What follows is the whole arrangement — what we block, what we refuse to keep, who we ask when we do not know, and how to check every word of it without taking our word for anything.
THE QUESTION
Is nobody's business
A list of the names you look up is a confession you never agreed to make. Encrypted transport keeps it between you and the resolver, and the resolver has no use for it afterwards.
THE DOOR
Stays where it is
We block advertising, tracking and malware, and we say so in writing. We do not quietly decide which opinions, countries or libraries you are allowed to reach. A resolver with politics is a censor with better manners.
THE LEDGER
Does not exist
There is no profile with your name on it, because there is nothing to put in it and nobody to sell it to. The lights are kept on by operators and sponsors, not by your browsing history.
THE CHAIN
Ends with us
We do not hand your query to Google or Cloudflare and call the result privacy. We ask the root servers ourselves, on our own hardware, on our own AS.
THE PROOF
Is yours to demand
Every claim on this page can be tested from your own machine in under a minute, with tools we do not control. Trust that cannot be checked is just advertising.
THE LIMIT
Is stated plainly
Encrypted DNS hides which names you ask for. It is not a VPN, it does not hide the addresses you then connect to, and it will not make you anonymous. Anyone promising otherwise is selling something.
The Blacklist No Middlemen Recursive resolvers Bootstrap DNS
The Blacklist
Every name on it earned its place. Ads, trackers, malware, phishing kits, and the quiet little domains that exist for no reason other than to follow you home — the resolver simply declines to tell you where they live. Nothing to install, nothing to configure: it is already running on the endpoint you picked on the front page.

These are the lists doing the work. They are not ours to hoard, so the subscription URLs are right here — take them for your own AdGuard Home, Pi-hole or Blocky.
01 AdGuard DNS filter ADS & TRACKING
The workhorse. AdGuard Base, Social Media, Tracking Protection and Mobile Ads rolled together with EasyList and EasyPrivacy, compiled for DNS rather than for a browser.
https://adguardteam.github.io/HostlistsRegistry/assets/filter_1.txt
Where it comes from
02 AdAway Default Blocklist MOBILE ADS
Fifteen years of Android ad hosts, maintained by people who got tired of paying for the same banner twice on a metered connection.
https://adguardteam.github.io/HostlistsRegistry/assets/filter_2.txt
Where it comes from
03 uBlock₀ filters – Badware risks BADWARE
The short list of sites documented to hand you adware, crapware or malware, or to relieve you of your login credentials. Short, because every entry on it is there for a reason somebody wrote down.
https://adguardteam.github.io/HostlistsRegistry/assets/filter_50.txt
Where it comes from
04 ΕΛΠΙΣ DNS filter IN HOUSE
Ours. Bogus, dead, parked, deceptive and legally abusive domains the big lists have not got around to, reviewed and trimmed for DNS by @Riri1x86. It ships with an exceptions list, because a filter that breaks your bank login is not protecting you from anything.
https://elpis.violetnetworks.xyz/bogus.txt
https://elpis.violetnetworks.xyz/allow.txt exceptions, load as an allowlist
Where it comes from
Family adds adult content and enforced safe search on top of all four. Everything else is left exactly where it is — a resolver that quietly edits the rest of your internet is the thing this project exists to route around.
No Middlemen
Most privacy resolvers are a polite fiction. Your question arrives sealed, and is then handed straight to Google or Cloudflare in the clear. One padlock, two custodians, and the second one keeps records.

ΕΛΠΙΣ answers it itself. The query goes to the root servers, down through the TLD, to the authoritative server that actually holds the answer — asked from our own hardware, on our own AS, over our own transit. Total privacy, total independence. There is nobody upstream to sell you to, because there is nobody upstream.
RECURSIVE
We ask, nobody asks for us
Root, then TLD, then the authoritative name server. No forwarding to a household name, and no third party quietly assembling the other half of your day.
IPv6 FIRST
The address space that is not rationed
Native v6 from the resolver out, AAAA ahead of A, and DNS64/NAT64 for networks that have finished with IPv4 entirely.
EDNS(0)
Room to answer properly
Responses larger than 512 bytes, DNS cookies, and the headroom that signatures need. The modern internet does not fit in a packet designed in 1987.
DNSSEC
Signatures checked, not admired
A tampered answer fails instead of arriving with a shrug. Ask for a domain whose chain is broken — wrong signature, expired, missing — and you get nothing at all, which is the only honest reply. ECDSA P-256, P-384 and Ed25519.
ECH
The handshake stays shut
HTTPS and SVCB records served intact, ech parameter and all, so your browser can encrypt its Client Hello and stop announcing which site it wants before it has even asked.
VERIFY
Take nobody's word for it
Ours least of all. dnscheck.tools reports who actually answered you, from which network, and what they bothered to validate.
Recursive resolvers — IPv6
The recursors themselves, on plain port 53, doing exactly one thing: resolving. No block lists, no rewrites, no NXDOMAIN where an answer ought to be. Whatever the authoritative server says is what comes back, whether we approve of it or not.

Which makes these the wrong thing to hand a laptop, and the right thing to put behind a box that already does its own filtering. Running AdGuard Home, Pi-hole, Blocky, Technitium or anything of that family? Set these as your upstream. You keep your lists, your logs and your rules; we do the recursion, and your household stops handing every query it makes to Google or Cloudflare on the way out. They work in the bootstrap field too — the one that has to resolve an encrypted endpoint's hostname before the encryption can begin.
IPv6 only, and unfiltered on purpose. If you want The Blacklist doing its work as well, that lives on the encrypted endpoints on the front page — the same resolvers with the filtering in front of them. Wiring one up as an upstream is on the setup page.
2402:4e20:b00b::1111
2402:4e20:b00b::1001
2402:4e20::1111
2402:4e20::1001
Then go and check
One page, no account, no install. Set correctly you should see IPv6, EDNS, DNSSEC and ECH all lit, every signature test passing, and your resolver named as Perfect Network in Semenyih — not as your telco.
Run dnscheck.tools
Bootstrap DNS servers
A chicken and egg problem: to reach an encrypted resolver by name, something has to resolve that name first. These plain resolvers exist for that single moment, and for nothing else. Most clients call the field bootstrap. The four recursors above do the job equally well if the box has IPv6; the addresses here are what you need when it does not.
AS IPv4 IPv6
AS154516 151.158.198.49 2402:4e20::b00b
151.158.198.24 2402:4e20:198::2
151.158.198.23 -
AS4788 175.143.78.185 -
60.54.118.241 -
That is the whole arrangement
No account, no client to install, no subscription to lapse. Pick a region and a transport, take the endpoint, and the day we stop deserving it, take it back.
Choose your gun