πŸ”’ Your ISP Logs Every Domain You Visit. Here's How to Stop It (Router DNS Guide)

:globe_with_meridians: Change Your Router’s DNS β€” Faster, Private, and Free Forever

Your ISP reads every website you visit. A 2-minute router change fixes that for every device in your home.

Every DNS request you make goes to your ISP by default β€” they see every domain you visit, every time, and can log, sell, or throttle it.

DNS is the internet’s phone book β€” it turns β€œgoogle.com” into an IP address your device can connect to. Your ISP controls which phone book you use by default. Changing your router’s DNS takes 2 minutes and instantly applies to every phone, laptop, TV, and smart device on your network. No apps. No subscriptions. No accounts.


πŸ“– What Is DNS and Why Does It Matter?

Every time you type a website address, your device asks a DNS server: β€œWhat’s the IP for this domain?” Your ISP answers that question by default β€” and logs the answer.

What Your ISP Sees What It Means
Every domain you visit Full browsing history β€” not just URLs, but every site every device touches
Timestamps Exactly when you visit what
All devices on your network Every phone, TV, gaming console, smart home device
Sellable data Many ISPs sell anonymized DNS logs to advertisers

Changing DNS doesn’t hide your IP address β€” for that you need a VPN. But it stops your ISP from seeing your domain requests, speeds up browsing, and can block malware before it even loads.

⚑ The DNS Servers β€” Complete List With Addresses

:1st_place_medal: Cloudflare β€” Fastest + Privacy Focused

IPv4 IPv6
Primary 1.1.1.1 2606:4700:4700::1111
Secondary 1.0.0.1 2606:4700:4700::1001
Malware blocking 1.1.1.2 / 1.0.0.2 β€”
Family (adult filter) 1.1.1.3 / 1.0.0.3 β€”

:white_check_mark: Fastest DNS globally β€” 4.98ms average. No query logging. Annual KPMG audit to verify privacy claims. Free.


:2nd_place_medal: Google Public DNS β€” Most Reliable Uptime

IPv4 IPv6
Primary 8.8.8.8 2001:4860:4860::8888
Secondary 8.8.4.4 2001:4860:4860::8844

:white_check_mark: Extremely stable. 100% uptime track record. Fast globally. Google does log queries for security analysis β€” tradeoff to be aware of.


:3rd_place_medal: Quad9 β€” Best for Security + Privacy

IPv4 IPv6
Primary 9.9.9.9 2620:fe::fe
Secondary 149.112.112.112 2620:fe::9
Unfiltered (no blocking) 9.9.9.10 2620:fe::10

:white_check_mark: Swiss non-profit. Blocks malicious domains using threat intelligence from 20+ cybersecurity companies. Strict no-logging policy. Operates under Swiss privacy law. 20–25ms average globally.


:locked: Surfshark DNS β€” Privacy First, No Logs

IPv4 IPv6
Primary 194.169.169.169 2a09:a707:169::

:white_check_mark: Free for everyone β€” no Surfshark subscription needed. Never logs or tracks queries. Supports UDP, TCP, TLS, HTTPS, QUIC protocols. Good for privacy-focused setups.


:shield: OpenDNS β€” Best Parental Controls + Filtering

IPv4
Primary 208.67.222.222
Secondary 208.67.220.220
FamilyShield (auto adult block) 208.67.222.123 / 208.67.220.123

:white_check_mark: Owned by Cisco. Resolves 620 billion queries/day. 100% uptime since 2006. Free tier includes anti-phishing and configurable content filtering. Dashboard to customize block categories.


:brick: AdGuard DNS β€” Built-In Ad Blocking

IPv4 IPv6
Default (ad + tracker blocking) 94.140.14.14 2a10:50c0::ad1:ff
Secondary 94.140.15.15 2a10:50c0::ad2:ff
Family (adult + malware + ads) 94.140.14.15 2a10:50c0::bad1:ff
Unfiltered 94.140.14.140 2a10:50c0::1:ff

:white_check_mark: Blocks ads and trackers at DNS level β€” for every device on your network without installing anything. Free. Supports DoH, DoT, DoQ, DNSCrypt.


:microscope: NextDNS β€” Most Customizable (Power Users)

IPv4
Primary 45.90.28.0
Secondary 45.90.30.0

:white_check_mark: 300,000 free queries/month then $1.99/month unlimited. Per-device settings, custom blocklists, analytics dashboard β€” basically Pi-hole in the cloud without self-hosting. Best for families and power users who want full control.


:broom: CleanBrowsing β€” Best for Families

Filter Primary Secondary
Family (adult + proxy + mixed) 185.228.168.168 185.228.169.168
Adult (adult content only) 185.228.168.10 185.228.169.11
Security (malware only) 185.228.168.9 185.228.169.9

:white_check_mark: Free. Enforces Google/YouTube/Bing SafeSearch automatically. Blocks adult content, proxies, and VPN bypass attempts. Best set-and-forget family filter.

πŸ”€ Which DNS Should YOU Use?
Your Priority Best Pick Why
:rocket: Raw speed Cloudflare 1.1.1.1 Fastest globally β€” 4.98ms average, wins 72% of locations tested
:locked: Maximum privacy Quad9 Swiss non-profit, Swiss law, strict no-log, malware blocking included
:shield: Malware + phishing blocking Quad9 or Cloudflare 1.1.1.2 Blocks known bad domains before your browser loads them
:prohibited: Block ads for whole house AdGuard DNS Ad/tracker blocking at DNS level β€” no app installs on any device
:family_man_woman_girl: Family / kids network CleanBrowsing Family or OpenDNS FamilyShield Adult content blocked, SafeSearch enforced, no config needed
:gear: Full control + analytics NextDNS Per-device rules, logs, custom lists β€” Pi-hole without the hardware
:person_running: Simple privacy upgrade Surfshark DNS Free, no account, no logs, set and forget
:white_check_mark: Most trusted/stable Google 8.8.8.8 100% uptime since forever β€” if everything else fails, this works
πŸ”§ How to Set DNS on Your Router β€” Step by Step

Setting it on your router means every device in your home (phones, TVs, laptops, consoles, smart home devices) gets the new DNS automatically. You only do this once.

Step 1 β€” Open Your Router Settings
Open a browser and go to your router’s admin panel. Common addresses:

192.168.1.1 192.168.0.1 192.168.1.254 10.0.0.1
Not sure? On Windows: open Command Prompt β†’ type ipconfig β†’ look for Default Gateway. That’s your router’s IP.

Step 2 β€” Log In
Username and password are usually printed on the bottom of your router. Common defaults: admin / admin or admin / password. Check your router’s label first.

Step 3 β€” Find DNS Settings
Look under one of these menu sections depending on your router brand:

Internet β†’ DNS WAN Settings β†’ DNS Advanced β†’ DNS Network β†’ WAN β†’ DNS Server

Step 4 β€” Enter Your DNS Addresses
Replace whatever is there with your chosen DNS. Example using Cloudflare:

Primary DNS: 1.1.1.1 Secondary DNS: 1.0.0.1

Step 5 β€” Save and Reboot
Click Save. Reboot your router if prompted. Done β€” every device on your network now uses the new DNS.

πŸ”§ How to Set DNS Per Device (Without Router Access)

If you don’t control the router (rental, office, shared network), set DNS per device instead.

Windows 10/11
Control Panel β†’ Network & Internet β†’ Network and Sharing Center β†’ Change adapter settings β†’ Right-click connection β†’ Properties β†’ Internet Protocol Version 4 (TCP/IPv4) β†’ Properties β†’ Use the following DNS server addresses

macOS
Apple Menu β†’ System Settings β†’ Network β†’ Select connection β†’ Details β†’ DNS tab β†’ Click + β†’ Add addresses

Android
Settings β†’ Network & Internet β†’ Private DNS β†’ Enter hostname (for DoT):

Cloudflare: one.one.one.one Quad9: dns.quad9.net AdGuard: dns.adguard.com NextDNS: your-id.dns.nextdns.io

iOS
Settings β†’ Wi-Fi β†’ Tap (i) next to network β†’ Configure DNS β†’ Manual β†’ Add Server

⚠️ Why Your ISP's Default DNS Is a Problem
ISP DNS Problem Why It’s a Problem
Full browsing log Every domain every device visits β€” logged with timestamps
Sold to advertisers ISPs in many countries legally sell anonymized DNS data
Slower than alternatives ISP DNS servers are rarely optimized β€” Cloudflare is 3–10x faster
No malware blocking ISP DNS resolves every domain including malicious ones
DNS hijacking Some ISPs redirect failed lookups to ad-filled search pages
No encryption by default Plain DNS (Do53) is unencrypted β€” anyone on the network can see it

Changing to a public DNS provider costs nothing and takes 2 minutes. Your ISP still sees your IP connections β€” but not which domains you’re resolving.


:high_voltage: Quick Hits

Want Do
:rocket: Fastest DNS, no questions β†’ 1.1.1.1 / 1.0.0.1 β€” Cloudflare, set it and forget it
:locked: Best privacy + malware blocking β†’ 9.9.9.9 / 149.112.112.112 β€” Quad9, Swiss non-profit
:prohibited: Block ads on every device β†’ 94.140.14.14 / 94.140.15.15 β€” AdGuard DNS
:family_man_woman_girl: Family-safe network β†’ 185.228.168.168 / 185.228.169.168 β€” CleanBrowsing Family
:gear: Full control + logs + per-device β†’ NextDNS β€” free up to 300k queries/month
:test_tube: Test what DNS you’re using now β†’ dnsleaktest.com β€” run Standard Test

Your ISP’s DNS knows every site you visit. A 2-minute router change means they don’t.

what about DoH and DoT ? is it better to setup in the windows 11 settings (to enable DNS over HTTPS) instead of control panel and set secure DNS in chrome browser ? will it be slower ? I am speaking about cloudflare.

@Ultra Changing the DNS in your router (like setting Cloudflare 1.1.1.1 / 1.0.0.1) mainly changes which DNS server answers your requests, but it’s still the traditional DNS protocol unless your router specifically supports DoH or DoT.

If you enable DNS over HTTPS (DoH) in Windows 11 settings, your DNS queries are actually encrypted, so your ISP or anyone on the network can’t easily read them. That’s a privacy improvement compared to plain DNS.

Chrome’s Secure DNS does the same thing (DoH), but only inside the browser. Other apps on your computer would still use normal DNS unless the OS-level setting is enabled.

So generally:

  • Router DNS change β†’ affects all devices on the network but usually not encrypted
  • Windows 11 DoH β†’ encrypted DNS for the whole system on that device
  • Chrome Secure DNS β†’ encrypted DNS only for the browser

In terms of speed, using DoH with Cloudflare usually isn’t noticeably slower. The difference is typically just a couple milliseconds, and in many cases it’s about the same.

So if someone wants better privacy on a specific device, enabling DoH in Windows 11 is a good option. If they want a simple improvement for every device in the house, changing the router DNS is still useful.

Both approaches can even be used together without problems.