Transparency statement

Resolver practices.

This document describes the public behaviour and policy boundaries of ScotNet Secure DNS. It follows the disclosure themes in RFC 8932 while avoiding claims that are not operationally verified.

Effective date. Version 1.2.0, reviewed 31 July 2026. Material changes are recorded below.

Service identity

Who and what

Operator
ScotNet, independently operated.
Public hostname
dns.scott.ovh
Supported transports
DNS over TLS on port 853 and DNS over HTTPS at https://dns.scott.ovh/dns-query.
Intended users
Approved users and devices. The service is not an open recursive resolver.
Administration
The AdGuard Home administration interface is bound to loopback and is not exposed as a public website route.

Encryption and validation

Transport and answer integrity

DoH
HTTPS requests are accepted at the exact /dns-query
DoT
TLS-protected DNS is available at dns.scott.ovh:853.
Certificates
Clients must validate the certificate for dns.scott.ovh. Certificate warnings must not be bypassed.
DNSSEC
Validation is enabled and monitored. Deliberately bogus signed responses are expected to fail with SERVFAIL.
Plain DNS
Port 53 may be enabled for approved clients, but encrypted transports are the published user-facing service.

Access control

Restricted by design

Data handling

What the service can observe

Information the resolver may receive

  • DNS question names and record types
  • Response status and filtering action
  • Timestamp and encrypted transport
  • Source network address or approved client identity
  • Operational errors and performance events

What is not promised

  • This is not a zero-log or anonymous resolver
  • Encrypted DNS does not hide queries from ScotNet
  • It does not hide destination IP addresses elsewhere
  • It does not prevent tracking inside websites or apps
Minimisation and retention. The public website uses no advertising or third-party analytics. ScotNet avoids behavioural profiling and does not sell resolver data. Operational and security records may be retained for diagnosis, abuse mitigation and reliability. ScotNet’s general privacy policy states that typical retention does not exceed 30 days unless an active investigation or legal obligation requires a temporary extension.

Access to records

Limited operational use

DNS behaviour

Filtering, ECS and upstreams

Filter scope
Known advertising, telemetry and abusive infrastructure may be filtered. Sources and categories change as policy and evidence change.
Filter response
No single public response code is guaranteed. Current policy can use address rewrites, NXDOMAIN, REFUSED or another controlled response.
False positives
Reports are reviewed manually. Submission does not guarantee an allow-list entry or immediate change.
EDNS Client Subnet
No contractual ECS behaviour is published. Clients must not rely on ECS being forwarded, stripped or disabled without operator confirmation.
Recursion and upstreams
The internal recursive or forwarding architecture is not published as a fixed dependency and may change without changing the public endpoints.

Availability

Best effort, monitored, no formal SLA

Change record

Practices revisions

DateVersionChange
31 July 20261.2.0Expanded platform onboarding, data-handling disclosure, access-control wording, reporting categories, status URL and machine-readable service facts. Resolver behaviour is unchanged.
30 July 20261.1.1Production acceptance release; public AdGuard administration removed, operational checks added and website security headers tightened.
30 July 20261.1.0First dedicated resolver-practices disclosure and setup pages.