How to Change Your DNS Server (and Whether You Should)

Your device uses whatever DNS server your network hands it, which is usually your ISP's. Switching to a public resolver like Cloudflare, Google or Quad9 takes a couple of minutes, and it can fix lookup failures or add malware filtering. It won't make your downloads faster, though, and in a few situations it quietly makes things worse.

What changing DNS actually does

Every time you visit a site, something has to turn the name into an IP address. That's your resolver. Change it and you change who answers those questions, who sees them, and what rules they apply to the answers.

The resolver does not carry your traffic. Once the address is known, your connection goes to the site directly, over the same ISP as before. So a new DNS server won't raise your speed test result or lower your ping to a game server. What it can change is the brief delay before each new connection starts, and whether certain names resolve at all.

Good reasons to switch:

  • Your ISP's resolver is unreliable, slow to respond, or returns errors for domains that work elsewhere.
  • You want filtering: Cloudflare's 1.1.1.2 blocks known malware, 1.1.1.3 adds adult content, and Quad9's 9.9.9.9 blocks malicious domains by default.
  • You'd rather your ISP didn't have a log of every hostname you look up (though see the caveat on encryption below).
  • Your ISP redirects failed lookups to a search or advertising page instead of returning an error.

Weak reasons: "faster internet" and "better gaming". Neither survives contact with how DNS works.

The main public resolvers

ProviderIPv4IPv6
Cloudflare1.1.1.1, 1.0.0.12606:4700:4700::1111, 2606:4700:4700::1001
Google8.8.8.8, 8.8.4.42001:4860:4860::8888, 2001:4860:4860::8844
Quad99.9.9.9, 149.112.112.1122620:fe::fe, 2620:fe::9

Always set both addresses from the same provider. Mixing providers means you get different filtering depending on which one happens to answer.

How to change it on each device

Windows 11. Open Settings, then Network & internet, then Wi-Fi or Ethernet. Open the connection's properties (for Wi-Fi, choose Hardware properties) and select Edit next to DNS server assignment. Switch it to Manual, turn on IPv4, and fill in Preferred DNS and Alternate DNS. Windows 11 also offers a DNS over HTTPS option on the same screen for providers it recognises. Repeat for IPv6 if your connection uses it, or IPv6 lookups will keep going to your ISP.

macOS. Apple menu, System Settings, Network, pick the service (Wi-Fi or Ethernet), click Details, then DNS. Click the add button under the DNS servers list and enter each address. Servers shown in grey came from your router, and adding your own replaces them.

iPhone and iPad. Settings, Wi-Fi, tap the info button next to your network, Configure DNS, Manual. Remove the existing entries and add yours. This applies only to that Wi-Fi network, and it doesn't affect mobile data.

Android. Android 9 and later has a Private DNS setting, usually under Settings, Network & internet (the exact location varies by manufacturer). Choose "Private DNS provider hostname" and enter a hostname rather than an IP: one.one.one.one for Cloudflare, dns.google for Google, or dns.quad9.net for Quad9. This encrypts lookups using DNS over TLS and works on Wi-Fi and mobile data.

Linux with NetworkManager. Replace "Wired connection 1" with your connection's name from nmcli con show:

nmcli con mod "Wired connection 1" ipv4.dns "1.1.1.1 1.0.0.1" ipv4.ignore-auto-dns yes
nmcli con up "Wired connection 1"

Your router. Changing DNS in the router's DHCP or WAN settings covers every device on the network at once, including TVs and consoles that have no DNS setting of their own. Log in (our guide to finding your router's IP helps if you don't know the address) and look for DNS under WAN, Internet or DHCP. Some ISP-supplied routers lock this field.

Check it actually worked

Don't assume. On any system, nslookup prints the server that answered on its first lines:

nslookup example.com

To see which resolver is really reaching the internet on your behalf, ask Google's diagnostic name, which replies with the address of whichever resolver queried it:

dig +short TXT o-o.myaddr.l.google.com

If that returns an address belonging to your ISP when you've set Cloudflare, something is overriding you. Two usual suspects are a VPN, which normally pushes its own DNS, and an ISP or router that intercepts all traffic on port 53 and answers it itself. Encrypted DNS (Android's Private DNS, or DNS over HTTPS in your browser) gets around interception because it doesn't use port 53. Also remember that Chrome and Firefox can use their own secure DNS settings, separate from the operating system.

What switching can break

CDN routing. Big sites pick which server you reach partly from the location of the resolver asking. Google Public DNS sends a truncated version of your address to authoritative servers (the EDNS Client Subnet extension) to help with that. Cloudflare's 1.1.1.1 deliberately doesn't, for privacy, and Quad9 only does on its separate 9.9.9.11 addresses. Usually the difference is invisible, but occasionally a resolver without it lands you on a more distant server.

Work and school networks. Internal hostnames often exist only on the organisation's own DNS. Point a work laptop at 1.1.1.1 and intranet sites stop resolving with errors like DNS_PROBE_FINISHED_NXDOMAIN. Leave managed devices alone.

Hotel and airport Wi-Fi. Captive portals rely on intercepting your first lookups. A hard-coded resolver, especially in strict encrypted mode, can stop the login page from appearing. Switch back to automatic to sign in.

ISP features. Parental controls and security filters run at the ISP's resolver stop working when you leave it.

Frequently Asked Questions

Which DNS server is the fastest?

It depends on where you are and how close each provider's nearest server is. Measure from your own connection rather than trusting a ranking. Our ping test or a plain ping 1.1.1.1 from your machine gives a rough idea of the network distance.

Does changing DNS hide my browsing from my ISP?

Not on its own. Plain DNS to a public resolver is still unencrypted, so your ISP can read it in transit, and it can see the IP addresses you connect to either way. Encrypted DNS closes part of that gap. Our post on DNS over HTTPS vs DNS over TLS covers exactly what it hides and what it doesn't.

Is it safe to use a public DNS server?

The big providers publish privacy policies describing what they log and for how long. You're swapping who you trust, not removing the need to trust someone, so read the policy of the one you pick.

Should I change DNS on my router or on each device?

Router if you want the whole household covered, including devices without a DNS setting. Per device if you only want it on one machine, or if the device moves between networks, like a laptop or phone.

Was this useful?
Share

Related reading

0 comments

No comments yet. Be the first.

Leave a comment

Comments are reviewed before they appear. Your email is optional, is never published, and is only used if we need to reply.

« Back to Blog