1. Signup to NextDNS and follow the video instructions.

The URLS for denylist:

ocsp2.apple.com

valid.apple.com

crl.apple.com

certs.apple.com

appattest.apple.com

vpp.itunes.apple.com

ocsp2-lb.apple.com

ocsp2.g.aaplimg.com

crl3.digicert.com

crl4.digicert.com

ocsp.digicert.cn

ocsp.digicert.com

ocsp2-lb.apple.com.akadns.net

gsas.apple.com

gsas.idms-apple.com.akadns.net

ma-gsa-hb-prod.apple.com

aidc.apple.com

init.ess.apple.com

iphone-ld.origin-apple.com

crl5.digicert.com

crl2.digicert.com

crl.digicert.com

crl2.apple.com

crl3.apple.com

guzzoni-apple-com.v.aapling.com

axm-app.apple.com

comm-cohort.ess.apple.com

comm-main.ess.apple.com

mesu.apple.com

xp.apple.com

ppq.apple.com

ocsp.apple.com

PPQ.apple.com

The URLS for allowlist:

app.localhost.direct

api.palera.in

api.development.push.apple.com

register.appattest.apple.com

mask-h2.icloud.com

mask-canary.icloud.com

mask-api.icloud.com

api.push.apple.com

push.apple.com

Blocks Updates:

gdmf.apple.com

You can also use any DNS of your choice.

Important Note: When installing or opening applications for the first time, it is important to disable either complete DNS or just disable the URL “ppq.apple.com.” This is necessary for the successful installation of applications.