A list that updates itself
One legal list for every provider. A new decision is a new RPZ zone version; the agent sees it on the next heartbeat and applies it without restarting unbound.
Regulator decisions, court orders and sanctions lists become signed RPZ zones that the agent applies on your unbound within a minute. No hand-edited configs, no inbound ports, and a report of exactly when each server blocked each domain.
curl -sL https://get.argusdns.net | sh -s -- --code XXXX-XXXX
An ISP has to enforce decisions quickly and be able to prove it. ArgusDNS makes both the system's job, not the on-duty engineer's.
One legal list for every provider. A new decision is a new RPZ zone version; the agent sees it on the next heartbeat and applies it without restarting unbound.
For every decision, the panel knows when each of your servers applied it. A compliance report for any period as CSV or PDF, ready for an audit or a regulator's request.
Levels L1–L3: phishing and malware domains, then ad networks and trackers, then adult content. Your organization's own allowlist, hit statistics and client anomalies.
One command on Linux or FreeBSD with unbound already running. The installer verifies sha256 and the ed25519 signature before it runs anything.
With an enroll code the server lands in your organization right away; approval is one button in Telegram or in the panel. The agent gets its config and the first list version within a minute.
A heartbeat every 30 seconds. On a new version the agent downloads the artifact itself, verifies the signature and loads the RPZ zone. The center never connects to your server.
Server status, query charts, blocking hits, the legal grounds for every domain. Telegram alerts when a server falls behind or goes offline.
ArgusDNS is delivered as a service: decision processing, list signing and the panel run in our infrastructure. Inside the ISP's network there is only the agent on the resolver, which fetches signed lists itself.
The resolver accepts only lists and commands with a valid signature, which it verifies itself. If the core is unreachable, the resolver keeps running with the lists already applied.
A resolver is critical ISP infrastructure, so the trust model is built so that a compromised center, protective layer or DNS cannot add a single extra domain.
The agent sends the center only per-minute counters and top lists — never the content of subscriber queries. The raw log, if enabled, stays on your server.
amd64 and arm64. One command installs, registers and later updates the agent.
curl -sL https://get.argusdns.net | sh
The same one-line installer: unbound from base or pkg, an rc.d service, the same features as on Linux.
fetch -o - https://get.argusdns.net/freebsd | sh
The installer verifies the archive's sha256 and signature itself; the values above are for manual checks.
It adds a separate file with rpz: blocks for the enabled zones and, if needed, respip in module-config. Your main config isn't rewritten; every change shows as a diff in the panel before it's applied.
NXDOMAIN or a CNAME stub pointing at your own page — an organization setting. The organization allowlist never affects the legal list.
The resolver keeps running with the zones already applied; statistics queue locally for up to 24 hours. The agent has a backup center address and switches after three failures.
ArgusDNS opens as a tab inside the ArgusNOC panel via SSO — the same organization, the same roles.
A beta for Ukrainian ISPs. Tell us how many resolvers you run and on which OS — we'll create your organization and send an enroll code.