For internet service providers · private beta

The legal blocklist on every resolver — automatically, with proof of compliance

Regulator decisions, court orders and sanctions lists become signed RPZ zones that the agent applies on your unbound within a minute. No hand-edited configs, no inbound ports, and a report of exactly when each server blocked each domain.

Linux · FreeBSDunbound RPZed25519 signaturesPanel + Telegram
app.argusdns.net · Overviewmockup
dns14,210 qps · legal v143
dns23,880 qps · legal v143
dns3list outdated · v141
12:47List applied · dns1 · legal v143
12:46New version · legal v143 · +12 domains
11:52Server connected · dns4 · FreeBSD 14.1
curl -sL https://get.argusdns.net | sh -s -- --code XXXX-XXXX
What you get

Three things a hand-maintained list can't give you

An ISP has to enforce decisions quickly and be able to prove it. ArgusDNS makes both the system's job, not the on-duty engineer's.

01

A list that updates itself

One legal list for every provider. A new decision is a new RPZ zone version; the agent sees it on the next heartbeat and applies it without restarting unbound.

02

Proof of compliance

For every decision, the panel knows when each of your servers applied it. A compliance report for any period as CSV or PDF, ready for an audit or a regulator's request.

03

Subscriber protection — optional

Levels L1–L3: phishing and malware domains, then ad networks and trackers, then adult content. Your organization's own allowlist, hit statistics and client anomalies.

How it works

An agent on the resolver, the control plane in one place

Step 1

Install the agent

One command on Linux or FreeBSD with unbound already running. The installer verifies sha256 and the ed25519 signature before it runs anything.

Step 2

Approve the server

With an enroll code the server lands in your organization right away; approval is one button in Telegram or in the panel. The agent gets its config and the first list version within a minute.

Step 3

The agent pulls signed lists

A heartbeat every 30 seconds. On a new version the agent downloads the artifact itself, verifies the signature and loads the RPZ zone. The center never connects to your server.

Step 4

Watch it in the panel

Server status, query charts, blocking hits, the legal grounds for every domain. Telegram alerts when a server falls behind or goes offline.

Architecture

The core is ours, only the agent is on your side

ArgusDNS is delivered as a service: decision processing, list signing and the panel run in our infrastructure. Inside the ISP's network there is only the agent on the resolver, which fetches signed lists itself.

ISP

ISP resolverwith the ArgusDNS agent · outbound only · verifies signatures
Subscribersqueries to the resolver
ISP operatorpanel · alerts

Protective layer

Agent entrytraffic filtering
List distributioncache of signed versions
Panel entrytraffic filtering

ArgusDNS core · our infrastructure

Agent intakeenrollment · status · statistics
Storageservers · decisions · versions · statistics
Published listssigned, immutable versions
List signerisolated key · verifies every change itself
Decision processingdocument parsing · admin approval
Decision sourcesregulator · courts · sanctions lists
Panel and reportsserver status · grounds · compliance

The resolver accepts only lists and commands with a valid signature, which it verifies itself. If the core is unreachable, the resolver keeps running with the lists already applied.

Security

A spoofed center can't make your resolver block anything

A resolver is critical ISP infrastructure, so the trust model is built so that a compromised center, protective layer or DNS cannot add a single extra domain.

Pull onlyThe agent calls the center itself. No inbound port, no SSH from the center.
ed25519Every list artifact and every command is signed with the policy key; the public key is built into the agent.
Separate signerThe key lives in an isolated process under its own user; it checks the format, the diff and the limits itself before signing.
Protected listDomains that can't be blocked even by a mistaken decision: banks, government services, CDNs.
CanaryA control domain in every zone — the agent checks that blocking really works.
Download

Runs where your unbound runs

The agent sends the center only per-minute counters and top lists — never the content of subscriber queries. The raw log, if enabled, stays on your server.

Linux · Debian 12/13, Ubuntu 22.04/24.04

amd64 and arm64. One command installs, registers and later updates the agent.

curl -sL https://get.argusdns.net | sh
version
—
date
—
size
—
sha256
—

FreeBSD 13 / 14 · amd64

The same one-line installer: unbound from base or pkg, an rc.d service, the same features as on Linux.

fetch -o - https://get.argusdns.net/freebsd | sh
version
—
date
—
size
—
sha256
—

The installer verifies the archive's sha256 and signature itself; the values above are for manual checks.

FAQ

What ISPs ask us

What exactly does the agent change in unbound?

It adds a separate file with rpz: blocks for the enabled zones and, if needed, respip in module-config. Your main config isn't rewritten; every change shows as a diff in the panel before it's applied.

What does a subscriber get instead of a blocked site?

NXDOMAIN or a CNAME stub pointing at your own page — an organization setting. The organization allowlist never affects the legal list.

What if the center is unreachable?

The resolver keeps running with the zones already applied; statistics queue locally for up to 24 hours. The agent has a backup center address and switches after three failures.

We already use ArgusNOC

ArgusDNS opens as a tab inside the ArgusNOC panel via SSO — the same organization, the same roles.

Access

Request access for your ISP

A beta for Ukrainian ISPs. Tell us how many resolvers you run and on which OS — we'll create your organization and send an enroll code.