About DNS
DNS explained.
Web sites are given to humans as a domain name. But the internet works by numbers, not names.
When you type in a domain name a special server uses a table to look up the domain you entered to find the IP address that will then take your web browser (or email) to that web site.
Your ISP normally assigns you its own DNS servers by default. Every DNS query you make - basically every site you visit - passes through whichever DNS server you're using, which means that server (and whoever operates it) can see a list of every site you look up.
You're free to point your devices at a different DNS provider instead of your ISP's default. A DNS server address looks like 000.000.000.000. A few common options, with the tradeoffs:
DNS provider options, pros and cons
Google Public DNS - 8.8.8.8 / 8.8.4.4
Fast, reliable, widely used. The tradeoff: Google is an advertising company, and DNS queries add to the data it already has about you if you're logged into any Google service. Reliable is not the same thing as private - if privacy is your goal here, consider one of the alternatives below instead.
Cloudflare - 1.1.1.1 / 1.0.0.1
Also very fast, and Cloudflare has committed to a strict no-logging privacy policy audited by a third party. A commonly recommended default if privacy is your main concern.
Quad9 - 9.9.9.9 / 149.112.112.112
Run by a nonprofit security foundation; blocks known-malicious domains by default and doesn't sell data. A solid privacy- and security-focused choice.
OpenDNS (Cisco) - 208.67.222.222 / 208.67.220.220
Reliable and offers optional content filtering, which makes it a popular choice for families. Now owned by Cisco, so weigh that the same way you would any large-company-operated service.
Where do you actually set this?
You have two places to do it, and they serve different purposes rather than being either/or:
- On your router - covers every device on your home network automatically: phones, laptops, smart TVs, game consoles, anything that connects. This is the easiest way to protect devices you can't configure individually.
- On the device itself (in its network settings) - only affects that one device, but it travels with it. Router-level DNS only applies while you're on your home network; a phone or laptop's own DNS setting keeps working at a coffee shop, airport, or anywhere else.
Doing both makes sense and isn't redundant - the router handles your whole home, the device setting picks up the slack the moment that device leaves it.
Can you mix two different providers?
Most routers and devices give you two slots - a primary and a secondary address - and yes, technically you can put a different provider in each. It's not actually a good idea, though. Your device doesn't reliably alternate between the two in order - it just uses whichever answers first - so you end up with inconsistent behavior depending on which server happens to be faster at that moment. It also means two separate companies now see fragments of your browsing pattern instead of one you've actually chosen to trust. Better practice: use the same provider's own primary and secondary pair instead of mixing brands - Cloudflare's 1.1.1.1 + 1.0.0.1 together, or Quad9's 9.9.9.9 + 149.112.112.112 together.
If you're weighing this because you're worried about a DNS server going down, that's actually what the second slot is already for. The primary and secondary addresses from the same provider run on separate, independent infrastructure - if your device can't reach the primary, it automatically tries the secondary, so you already have fallback built in without needing to mix providers. Splitting between two different companies would only add protection against the rarer case of one provider's entire network going down at once (not just a single server) - uncommon enough that it's rarely worth the inconsistency and split trust it costs the rest of the time.
One more thing: the address alone doesn't encrypt anything
Pointing your device at a different DNS provider's IP address does not, by itself, encrypt your DNS traffic - plain DNS is still sent unencrypted, visible to your ISP or anyone else on the network path, no matter whose server you're asking. The privacy-focused providers above all support encrypted DNS - DNS-over-HTTPS (DoH) or DNS-over-TLS (DoT) - and most modern devices have a setting for this built in already (look for "Private DNS" on Android, "Encrypted DNS" in Windows 11's network settings, or "Secure DNS" in Firefox/Chrome). Turning that on alongside picking a provider is what actually stops your ISP from seeing your DNS queries - changing the address alone is only half the job.
If your DNS ever stops resolving sites, OpenDNS has a decent how-to guide if you get stuck.