CoreDNS

CoreDNS is an integrated component of Netgate Nexus which handles DNS-based tasks with extremely high performance. This component is based on the CoreDNS Project, but the functionality in Netgate Nexus is primarily focused on a new and exclusive CoreDNS plugin created by Netgate called rexdns.

The rexdns plugin boosts the performance of CoreDNS, making it able to handle domain expressions with millions of entries even faster than standard CoreDNS, plus rexdns has the ability to match complex expressions using syntax similar to regular expressions.

Together, CoreDNS and rexdns enable users to take more control over their local DNS resolution behavior with features such as:

  • Pattern-based expressions for filtering, forwarding, and local resolution.

  • Blocklists containing expressions to block which can be managed manually or by ThreatGate.

  • Multiple groups of DNS settings based on client prefixes with optional fallback to default settings.

  • Zero Trust Egress mode which blocks all traffic except hosts resolved directly via CoreDNS to prevent users from bypassing local DNS restrictions.

Note

CoreDNS can easily use Unbound as its upstream DNS server as both can run at the same time on different ports; it is not necessary to completely replace Unbound. Though CoreDNS performs DNS forwarding and can work independently without Unbound, it lacks some functionality in Unbound that users might prefer or require.

CoreDNS is only available in the Netgate Nexus GUI while Configuring pfSense Plus Software Instances. While managing an instance in the Netgate Nexus GUI, navigate to Services > CoreDNS.