→■ DNSIGHT

What my iPhone did while I slept

296 distinct DNS lookups across 130 domains in three and a half hours, with nobody touching the phone.

5 August 2026 · Oliver, OK Labs

I gave my iPhone its own encrypted DNS endpoint and logged everything it resolved through the system resolver for one night. I went to sleep at 02:30 and woke at 07:00. The window below is the part where I was definitely asleep and definitely not touching the phone.

701
raw lookups
296
distinct
130
domains
3h 30m
asleep

Who the phone talked to

Ranked by lookups between 02:30 and 06:00, registrable domain:

DomainLookupsWhat it is
apple.com52Apple services
apple-dns.net39Apple service routing
aaplimg.com32Apple CDN
ouraring.com24sleep ring, syncing
googleapis.com22Google APIs
google.com17Google
facebook.com16Facebook
instagram.com14Instagram
akadns.net13Akamai routing
googleusercontent.com11Google content CDN
8slp.net10Eight Sleep mattress
icloud.com8iCloud sync
browser-intake-datadoghq.com5app telemetry

Most of it is unremarkable and honestly fine. A locked iPhone has housekeeping to do, and my sleep ring and mattress were doing the one job I bought them for. The Apple traffic is the phone being a phone.

The part I keep looking at is thirty lookups to Facebook and Instagram, spread thinly across a night when I was unconscious and neither app was open. That is background refresh doing what background refresh does. It is documented, it is not a scandal, and I still had no way to see it until I built one.

DNSight activity timeline: 7,163 DNS lookups from one iPhone over 24 hours, in ten-minute buckets, stacked by category, with session marks above and blocked lookups below.
The same iPhone over a different 24 hours, 3–4 August, as DNSight draws it: 7,163 lookups in ten-minute buckets, coloured by category, session marks along the top, blocked lookups on the strip below. The night described in this piece is one day later and produced the numbers above.

Where my own tool got it wrong

At 05:13 the timeline said “Opened Instagram”. I was asleep. Nobody opened anything.

This is the honest limit of DNS as a signal, and it is worth stating plainly rather than waiting to be caught. At the resolver, a human opening an app and an app waking itself up look identical. Both produce a burst of lookups to the same hostnames. There is no foreground signal in DNS, so any tool claiming “you opened X” from DNS alone is inferring, and sometimes it will infer wrong about you while you sleep.

I changed it this morning. A visit with no distinguishing action now reads “Instagram was active” rather than “Opened Instagram”. When there is a real signature in the hostnames, a comment endpoint, an upload endpoint, a search endpoint, the timeline still names what happened, because those are much harder to produce by accident. Everything else is reported as activity, not as an act.

Treat a DNS log as a step counter, not an ECG.

What DNS can and cannot show you

The rest of the night, for completeness

Across the whole night the phone made 4,608 raw lookups. The bulk of those were not the phone being mysterious. Between 00:19 and 01:35 there were bursts of 45 to 48 social lookups a minute, which is me, awake, doomscrolling TikTok and Instagram well past when I said I was going to bed.

I built the tool. The tool caught me. I am publishing that too, because a phone-monitoring product whose author quietly edits out his own 1:26am TikTok session is not a product anyone should trust.

DNSight gives each device its own encrypted DNS endpoint and turns what it resolves into a readable per-device timeline. It works on Wi-Fi, cellular and roaming, and setup on iOS is a one-tap profile that takes under 90 seconds.

$13.50 for your first month, 50% off through Aug 18. Run a 31-day audit of your own phone, then cancel if you are done.

See your own night →