What DNS does

The Domain Name System is the internet's phone book. When you type a site name, your device asks a DNS resolver for the matching IP address, and only then connects. Every app does this constantly: streaming services, game launchers, smart speakers and software updates all start with DNS lookups.

Your router normally receives DNS server addresses from your ISP and passes them to your devices through DHCP (or answers queries itself and forwards them upstream). That default is fine for many people, but it means:

  • Your ISP's resolvers see every domain your household looks up, in plain text.
  • Your ISP decides what, if anything, gets filtered, and how outages are handled.
  • You get no built-in ad, tracker or malware blocking.

Public DNS providers compared

Cloudflare — 1.1.1.1

  • Consistently among the fastest resolvers in independent measurements.
  • Publishes a privacy commitment not to sell query data, with short log retention and third-party audits.
  • Filtered variants: 1.1.1.2 / 1.0.0.2 (malware) and 1.1.1.3 / 1.0.0.3 (malware plus adult content).

Google Public DNS — 8.8.8.8

  • Very high availability and a global anycast network.
  • No filtering. Google documents what it logs on its Public DNS privacy page.

Quad9 — 9.9.9.9

  • Blocks domains flagged by threat-intelligence feeds, which helps against phishing and malware.
  • Run by a non-profit foundation based in Switzerland.
  • An unfiltered option is available at 9.9.9.10 if you want privacy without blocking.

AdGuard DNS — 94.140.14.14

  • Blocks ad and tracker domains for every device on the network.
  • Family variant 94.140.14.15 / 94.140.15.16 also blocks adult content and enforces safe search.

OpenDNS — 208.67.222.222

  • Long-running service from Cisco, popular for simple parental controls.
  • FamilyShield addresses 208.67.222.123 / 208.67.220.123 block adult content with no account needed.

NextDNS

  • Fully customizable: choose blocklists, see query logs, set per-device profiles.
  • Free tier with a monthly query limit; paid plans remove it.
  • Each profile gets its own addresses, shown in your NextDNS dashboard.

How to change DNS on your router

  1. Log in to the router's admin page or app. If you're unsure how, see how to log in to your router.
  2. Look for DNS under Internet, WAN, LAN / DHCP Server or Network. On mesh systems (eero, Google/Nest Wifi, Deco) it is in the app's advanced network settings.
  3. Switch DNS from Automatic / Get from ISP to Manual / Custom.
  4. Enter a primary and secondary server, for example 1.1.1.1 and 1.0.0.1.
  5. If your router supports IPv6, set IPv6 DNS too (Cloudflare: 2606:4700:4700::1111; Google: 2001:4860:4860::8888), or devices may keep using the ISP's IPv6 resolvers.
  6. Save. Devices pick up the change when they renew their DHCP lease; toggling Wi-Fi off and on forces it.

WAN DNS vs LAN DNS: some routers have a DNS field on the WAN/Internet page (what the router itself uses) and another on the DHCP page (what it hands to devices). If the router acts as a DNS forwarder, setting the WAN field is enough. If you're unsure, set both.

On ISP-supplied gateways

What you can change depends heavily on the gateway and its firmware, and providers update these interfaces regularly:

  • Some gateways allow custom DNS in the local admin page, usually under the LAN, DHCP or network settings.
  • Others keep DNS locked to the provider's servers for the whole home network.
  • App-managed gateways (common with cable and 5G home internet) often expose fewer advanced settings than a web interface.

If yours is locked, set DNS on each device (Windows: Settings → Network & internet → your connection → DNS server assignment; macOS: System Settings → Network → Details → DNS; iPhone/Android: per-network Wi-Fi settings or Private DNS on Android), or put the gateway in bridge/passthrough mode and use your own router. Provider-specific login help: Xfinity, Spectrum, AT&T, Verizon Fios, Cox.

Encrypted DNS: DoH and DoT

Classic DNS travels unencrypted on port 53, so anyone on the path, including your ISP, can read the domain names. DNS over HTTPS (DoH) and DNS over TLS (DoT) encrypt the lookup:

  • Cloudflare: https://cloudflare-dns.com/dns-query · DoT host one.one.one.one
  • Google: https://dns.google/dns-query · DoT host dns.google
  • Quad9: https://dns.quad9.net/dns-query · DoT host dns.quad9.net

Enthusiast routers and some ASUS, GL.iNet and OpenWrt-based models can encrypt DNS for the whole network; most ISP gateways cannot. The simplest way to get encrypted DNS is often on the device itself: Chrome, Edge and Firefox have a Secure DNS option, Windows 11 supports DoH per connection, and Android's Private DNS setting uses DoT.

How to check which DNS you're using

  1. Visit 1.1.1.1/help to see whether you're using Cloudflare and whether DoH/DoT is active.
  2. Run the standard test at dnsleaktest.com to see which resolvers are answering your queries.
  3. If results still show your ISP, restart the device's network connection, check for IPv6 DNS, and make sure no browser or VPN is overriding DNS.

Frequently asked questions

What is the best DNS server to use?

It depends on what you want. Cloudflare (1.1.1.1 / 1.0.0.1) is fast nearly everywhere and has a strong privacy policy. Google Public DNS (8.8.8.8 / 8.8.4.4) is extremely reliable. Quad9 (9.9.9.9 / 149.112.112.112) blocks known malicious domains and is operated by a Swiss non-profit foundation. AdGuard DNS (94.140.14.14 / 94.140.15.15) filters ads and trackers network-wide. NextDNS lets you build a custom filter list with logs and per-profile settings. For most homes, Cloudflare or Quad9 is a sensible default.

Will changing DNS make my internet faster?

Usually not in a way you will notice. DNS only affects how long it takes to look up a name before a connection starts, typically a few milliseconds, and results are cached by your devices and router. It does not change your download speed. Switching can help if your ISP's resolvers are slow or unreliable, but the real reasons to change DNS are privacy, malware or ad filtering, parental controls and resilience when an ISP's DNS has an outage.

Should I set DNS on the router or on each device?

On the router if you want one change to cover everything, including smart TVs, consoles and IoT gadgets that have no DNS setting of their own. On the device if your ISP gateway won't let you change DNS, or you want one computer to use a different resolver. Keep in mind that modern browsers and operating systems can use DNS over HTTPS on their own, which bypasses whatever the router hands out.

Why can't I change DNS on my ISP's gateway?

Some ISP-supplied gateways don't expose a DNS setting for the home network at all, or only let you change it for the gateway itself. If your gateway is one of them, you have three options: set DNS manually on your important devices; add your own router (with the gateway in bridge mode or IP passthrough) and set DNS there; or run a local filtering resolver such as Pi-hole or AdGuard Home and point devices at it.

Can DNS block ads for every device in my house?

Largely, yes. Point your router at AdGuard DNS or a NextDNS profile with ad blocking enabled, and every device on Wi-Fi gets ad and tracker domains blocked without installing anything. Limits: ads served from the same domain as the content (YouTube is the classic example) still get through, devices using their own encrypted DNS bypass the filter, and some apps break when a required domain is blocked, so you may need to allowlist occasionally.