Your DNS settings decide which server translates domain names into IP addresses — and therefore who sees a list of every site you visit. Checking them takes about thirty seconds, and it’s the first step in diagnosing slow browsing, “server not found” errors, and a surprising number of privacy problems.
There’s a catch worth knowing before you start: what your settings say and what your device actually uses are often different things. This guide covers both — how to read the configuration, and how to verify what’s really happening.
Key Takeaway:
Your device settings show what was configured. Your router, DHCP, your browser and your VPN can each override that. The only reliable answer comes from a live lookup test.
Why Your DNS Server Matters
- Privacy. Whoever runs your resolver sees every domain you request. By default that’s your ISP — see what your ISP does with that.
- Speed. A slow or distant resolver adds delay to every new domain you visit.
- Reliability. Most “the internet is down” moments are actually DNS failing, not the connection.
- Filtering. Some resolvers block malicious domains; some ISPs block other things.
- VPN integrity. If your VPN isn’t handling DNS, lookups escape the tunnel — a DNS leak.
How to Check Your DNS Settings
Windows
Command Prompt — fastest and most accurate:
- Run
ipconfig /all - Find your active adapter and look for DNS Servers
Or via Settings: Settings → Network & Internet → your connection → Hardware properties → DNS server assignment.
macOS
- System Settings → Network → your connection → Details → DNS
- Or in Terminal:
scutil --dns | grep nameserver
iPhone / iPad
Settings → Wi-Fi → tap the ⓘ beside your network → scroll to Configure DNS. “Automatic” means you’re using whatever your router hands out.
Android
Settings → Network & internet → Wi-Fi → your network → Advanced → IP settings. Note that Android also has a separate Private DNS setting (Settings → Network → Private DNS) which applies system-wide and overrides per-network settings.
Your Router
Log into the admin panel (usually 192.168.1.1) and look under WAN, Internet or DHCP settings. This is the one that matters most — it’s what every device on your network inherits by default.
⚠️ Configured vs Actually Used
This is where people get misled. Your device can show one thing while using another, because DNS is resolved through several layers that can each override the one below:
- Your router hands out a DNS server via DHCP — usually itself, forwarding to your ISP.
- Your browser may run its own encrypted DNS. Chrome and Firefox both ship DNS over HTTPS, which bypasses your system settings entirely for browser traffic.
- Your VPN should replace your DNS while connected — and if it doesn’t, that’s a leak.
- Your ISP may transparently intercept DNS traffic and redirect it to its own servers regardless of what you set.
So the only trustworthy answer comes from asking the internet which resolver actually served your query. Run our DNS Checker — it reports the resolver that genuinely handled the lookup, not the one your settings claim.
What the Result Means
| What You See | Meaning |
|---|---|
1.1.1.1 / 1.0.0.1 | Cloudflare — fast, privacy-focused, independently audited |
8.8.8.8 / 8.8.4.4 | Google Public DNS — fast and reliable, logged by Google |
9.9.9.9 | Quad9 — blocks known malicious domains |
192.168.x.x | Your router, which forwards to your ISP |
| Your ISP’s name | Default setup — they see every domain you request |
| Your ISP while on a VPN | ⚠️ A DNS leak — fix this |
How to Change Your DNS
Change it once at the router and every device inherits it. Change it per-device when you only want it on one machine, or your router won’t allow it.
- Router (best): admin panel → WAN or DHCP settings → set primary and secondary DNS → save and reboot.
- Windows: Settings → Network & Internet → your connection → Hardware properties → DNS server assignment → Edit → Manual → enter your servers.
- macOS: System Settings → Network → Details → DNS → + to add, and remove the old entries.
- iPhone: Settings → Wi-Fi → ⓘ → Configure DNS → Manual.
- Android: use Private DNS with a hostname such as
one.one.one.one— this also encrypts your lookups, which the per-network setting does not.
Always set a secondary server as a fallback, and flush your DNS cache afterwards so old results don’t mask the change.
Changing DNS Alone Doesn’t Hide You
Worth being blunt about, because plenty of guides imply otherwise.
Standard DNS is unencrypted. If you switch from your ISP’s resolver to 1.1.1.1, your ISP no longer answers your queries — but it still carries them across its network, in plain text, and can read every one. You’ve changed who resolves your lookups, not who can see them.
To actually hide them you need encrypted DNS — DNS over HTTPS or DNS over TLS. That’s what Android’s Private DNS does, and what your browser’s “Secure DNS” setting enables. Switching resolvers is still worthwhile for speed and reliability; just don’t mistake it for privacy on its own.
Which DNS Should You Use?
| Choose | If You Want |
|---|---|
Cloudflare 1.1.1.1 | Best general choice — fast, with audited privacy commitments |
Quad9 9.9.9.9 | Automatic blocking of known malicious domains |
Google 8.8.8.8 | Maximum reliability, if Google logging doesn’t bother you |
| Your ISP | Nothing in particular — it’s the default for a reason |
When DNS Is Your Problem
Suspect DNS when:
- Some sites load and others don’t, with no obvious pattern
- You get “server not found” while the connection is clearly working — see DNS_PROBE_FINISHED_NXDOMAIN
- Sites load slowly the first time but quickly afterwards
- Apps work while browsers don’t
- You get “DNS server not responding”
The quick test: switch to 1.1.1.1, flush your cache, and retry. If the problem disappears, it was DNS. Broader diagnosis: Wi-Fi connected but no internet.
Frequently Asked Questions
Why do my settings show one DNS but the test shows another?
Because something is overriding it — usually your router handing out its own address via DHCP, your browser’s built-in secure DNS, or a VPN. The live test is the truth; your settings are just a request.
Is changing my DNS safe?
Yes, and it’s trivially reversible — set it back to automatic. The main risk is typing an address wrong, which breaks name resolution until you correct it.
Will changing DNS make my internet faster?
It can shave time off the first visit to each new domain, which makes browsing feel snappier. It doesn’t change your bandwidth at all — see latency vs speed.
Router or device — where should I change it?
The router, so everything inherits it, including devices you can’t configure like TVs and consoles. Use per-device settings when you want one machine to differ.
Does my VPN change my DNS?
It should — a good VPN routes lookups through its own resolvers inside the tunnel. If a test still shows your ISP while connected, that’s a leak and worth fixing.
What’s Private DNS on Android?
Encrypted DNS (DNS over TLS), applied system-wide. It’s the easiest way to get encrypted lookups on a phone — enter a hostname like one.one.one.one rather than an IP address.
Can my ISP force its own DNS?
Some do, by intercepting DNS traffic and redirecting it regardless of your settings. Encrypted DNS defeats this, because the queries can no longer be read or rewritten in transit.
Do I need to restart after changing DNS?
Not usually, but flush your DNS cache — otherwise cached results from the old server keep answering and it looks like nothing changed.