VPN
Photo of author

Best DNS Servers for Homelabs & Pi-hole Setups (2026)

This guide walks through best dns servers step by step, with the exact settings and gotchas that trip up first-timers. DNS, or Domain Name System, is the internet’s address book. Every time you type a URL, your device asks a DNS resolver to translate that name into an IP address. The resolver you use determines how fast that lookup happens, who sees your query, and whether malicious domains get blocked before they can cause harm.

Most people never change the DNS server assigned by their internet service provider. That default resolver is often slow, logs your queries, and offers no protection against phishing or malware. Switching to a better public DNS service takes about two minutes and delivers immediate improvements in speed, privacy, and security.

For data hoarders managing large archives, syncing datasets across multiple locations, and regularly querying remote servers, a reliable and private DNS resolver is not optional. It is part of a responsible infrastructure setup. A slow or logging resolver means every archival pull, every remote access session, and every sync job leaks information to a third party.

This guide covers the best DNS servers available in 2026, how to choose the right one for your specific needs, and how to configure and verify your setup across devices and routers.

How To Choose The Best DNS Servers

The right public DNS provider depends on what you value most. Speed, privacy, and filtering each pull in slightly different directions, and the best free DNS servers for one use case may be a poor fit for another.

Speed Vs Privacy Vs Filtering

Raw DNS speed matters for anyone running automated archival jobs or querying large datasets repeatedly throughout the day. Cloudflare’s 1.1.1.1 and Google’s 8.8.8.8 consistently lead in latency benchmarks globally. Both operate anycast networks spanning hundreds of cities, so your queries almost always hit a nearby node.

Privacy-focused DNS providers like Mullvad and Quad9 prioritize zero-log or minimal-log policies over squeezing out the last millisecond of speed. In practice, the latency difference is often negligible. For most data hoarders, Quad9 hits a useful middle ground, offering strong privacy alongside active malware blocking.

Filtering DNS servers add content blocking at the resolver level. This is useful for shared networks or family setups, but can sometimes interfere with resolving legitimate archival domains. If you run a home lab pulling from diverse sources, test any filtering resolver carefully before committing.

When ISP DNS Is Good Enough

ISP DNS is rarely the best public DNS option. It is often slower than major public DNS providers, and most ISPs log queries by default with no public audit or commitment to data minimization. Some ISPs also practice NXDOMAIN hijacking, redirecting failed lookups to ad-laden search pages rather than returning proper errors.

For casual browsing, ISP DNS may be adequate. For data hoarding workflows where consistency and privacy matter, it is worth replacing.

What Data Hoarders Should Prioritize

When building or maintaining a digital archive, a few DNS qualities become especially important:

  • No-log policy: Every query to a remote dataset source is a record of your archival activity. Choose a DNS provider that does not retain personally identifiable query data.
  • Fast DNS speed: Repeated lookups during large sync operations compound quickly. Even a 20ms improvement per query adds up across thousands of requests.
  • DNSSEC validation: Archives pulled from spoofed domains are a real risk. A resolver that validates DNSSEC signatures protects the integrity of every connection.
  • Reliability and uptime: A flaky resolver stalls your entire pipeline. Stick with providers operating proven anycast networks and publishing uptime data.

Best DNS Servers By Use Case

Different scenarios call for different resolvers. The list below covers the strongest options across privacy, security, family filtering, and raw performance, with the specific IP addresses you will actually enter into your device or router settings.

Best For Privacy-Focused Browsing

Mullvad DNS (194.242.2.2) is the strongest privacy-first choice available. Operated by the same Swedish team behind the Mullvad VPN, it requires no account, retains zero query logs, and supports both DoH and DoT. There is no mechanism to link a query back to you.

Quad9 (9.9.9.9 / 149.112.112.112) is based in Switzerland under Swiss privacy law. It does not log personal data, publishes transparency reports, and blocks known malicious domains by default. The privacy protections and security filtering work simultaneously, which makes it ideal for data hoarders who want both without running two separate tools.

Cloudflare 1.1.1.1 (1.1.1.1 / 1.0.0.1) purges all query logs within 24 hours and submits to annual third-party audits by KPMG. It supports DoH, DoT, and the 1.1.1.1 app for mobile. The speed advantage over other privacy-focused resolvers is measurable in real-world testing.

ProviderPrimary IPSecondary IPLog PolicyJurisdiction
Mullvad DNS194.242.2.2Zero logsSweden
Quad99.9.9.9149.112.112.112No personal dataSwitzerland
Cloudflare1.1.1.11.0.0.1Purged <24hUnited States

Best For Malware And Phishing Protection

Quad9 (9.9.9.9) integrates threat intelligence from more than 25 feeds including IBM X-Force. Any query to a known-malicious domain returns NXDOMAIN, stopping the connection before it is established. DNSSEC validation runs on every response. For a non-filtered variant, Quad9 also offers 9.9.9.10.

OpenDNS Home (208.67.222.222 / 208.67.220.220) has operated since 2006 and maintains one of the largest threat databases in the industry. The free tier blocks phishing and malware domains. Configuration is done through an online dashboard, which also provides basic reporting.

AdGuard DNS (94.140.14.14 / 94.140.15.15) blocks ads, trackers, and known malicious domains simultaneously. It supports DNSSEC and a wide range of encrypted protocols. For data hoarders pulling content from varied sources, the tracker and ad blocking at the DNS level reduces noise in archival pipelines.

Comodo Secure DNS and Control D (76.76.2.0 / 76.76.10.0) are also solid security-focused options. Control D in particular offers granular blocking categories and supports DoH, making it adaptable for more complex home lab setups.

Best For Families And Content Controls

OpenDNS FamilyShield (208.67.222.123 / 208.67.220.123) is the simplest option. It is preconfigured with no account required and blocks adult content domains automatically at the resolver level.

CleanBrowsing DNS (185.228.168.9 / 185.228.169.9) offers multiple filtering presets. The Family Filter is the most restrictive, blocking adult content, VPN and proxy domains, and mixed-content sites. It works well on routers where you want whole-network filtering without managing individual device settings.

AdGuard Family (94.140.14.15) adds tracker and ad blocking on top of content filtering, which makes it more comprehensive than simpler family-safe options.

Cloudflare for Families (1.1.1.3) blocks malware and adult content without requiring any account setup. It is a lightweight option that benefits from Cloudflare’s global anycast network.

ProviderPrimary IPSecondary IPBlocks Adult ContentBlocks Malware
OpenDNS FamilyShield208.67.222.123208.67.220.123YesYes
CleanBrowsing185.228.168.9185.228.169.9YesYes
AdGuard Family94.140.14.15YesYes
Cloudflare Family1.1.1.3YesYes

Best For Low-Latency Performance

For applications where DNS speed is the primary concern, including home lab setups running frequent remote lookups, gaming, or large automated archival jobs, Cloudflare 1.1.1.1 and Google Public DNS (8.8.8.8 / 8.8.4.4) are the fastest DNS servers available globally.

Cloudflare’s anycast network spans over 300 cities. In North America, typical response times run between 1 and 5 milliseconds. Google runs a comparable global network and is a close second in most regions, with a slight edge in parts of Asia-Pacific.

Fastest DNS servers by region:

  • North America: Cloudflare (1-5ms), Google (3-8ms)
  • Europe: Cloudflare (2-8ms), Quad9 (5-12ms)
  • Asia-Pacific: Google (5-15ms), Cloudflare (5-20ms)
  • South America: Cloudflare (8-20ms), Google (10-25ms)

These are typical values. The only reliable way to confirm which is fastest for your specific network is to run a DNS benchmark from your location.

Privacy And Security Features That Matter

Encrypted DNS and DNSSEC address two separate but related problems: who can read your queries in transit, and whether the responses you receive are authentic. Logging policies determine what a provider retains after the query completes.

DoH Vs DoT Vs DoQ

DNS over HTTPS (DoH) sends queries inside standard HTTPS traffic on port 443. Because it looks identical to normal web traffic, it is difficult for ISPs or network administrators to identify or block specifically. Most major browsers now support DoH natively.

DNS over TLS (DoT) uses a dedicated port (853) and wraps queries in TLS encryption. It is easier for network administrators to identify and filter than DoH, but it is widely supported across operating systems and routers. For router-level configuration in a home lab, DoT is often the more practical choice.

DNS over QUIC (DoQ) is a newer protocol that runs encrypted DNS over the QUIC transport layer. It offers lower latency than DoH or DoT in some conditions. AdGuard DNS is one of the few providers that currently supports DoQ alongside the older protocols.

For most setups, DoH or DoT are sufficient. Use DoH when you need queries to blend with standard HTTPS traffic. Use DoT when configuring at the router or operating system level where dedicated port support is reliable.

DNSSEC And DNSSEC Validation

DNSSEC adds cryptographic signatures to DNS records. A resolver that performs DNSSEC validation checks those signatures before returning a result. If the signature fails, the resolver refuses to return the spoofed response.

This matters for anyone pulling data from remote archival sources. Without DNSSEC validation, a DNS cache poisoning attack can silently redirect your connections to a malicious server while appearing to resolve the correct domain.

Quad9, AdGuard DNS, and Cloudflare all validate DNSSEC on responses. OpenDNS also supports DNSSEC validation. If your current resolver skips this check, your entire archival pipeline is exposed to spoofing.

Logging Policies And Threat Intelligence

A DNS provider’s logging policy determines what survives after your query is processed. There are three broad categories:

  • Zero logs: No query data is retained. Mullvad operates this way.
  • Aggregated, no PII: Usage statistics are collected but stripped of identifying information. AdGuard DNS falls here.
  • Time-limited logs: Query data is held briefly and then purged. Cloudflare purges within 24 hours and audits this with KPMG.

Threat intelligence feeds power the blocking capabilities of security-focused resolvers. Quad9 draws from 25-plus feeds including IBM X-Force. OpenDNS uses one of the largest threat databases in the industry. The quality and breadth of these feeds directly determines how reliably malicious domains get blocked before any connection is established.

Filtering, Controls, And Safe Browsing

DNS filtering blocks categories of domains at the resolver level, before any content is loaded. Speed and simplicity make it an appealing first layer of network protection, though it works best in combination with other controls.

Content Filtering For Shared Networks

Setting a filtering DNS resolver on your router applies the rules to every device on the network automatically. Phones, tablets, smart speakers, and consoles all go through the same filter without requiring individual configuration.

This is particularly useful in shared living situations or small office environments. CleanBrowsing and OpenDNS both support router-level deployment with no special hardware required. Quad9 can serve a similar function if your primary concern is blocking malicious domains rather than content categories.

Blocking Adult Content And Malicious Domains

Safe DNS services that block adult content and malicious domains operate by maintaining blocklists of domain names. When a device queries a blocked domain, the resolver returns NXDOMAIN or a redirect instead of the real IP, and the connection never completes.

The distinction between adult content filtering and malware blocking matters in practice. Some resolvers do both together (AdGuard Family, CleanBrowsing Family Filter), while others focus purely on security (Quad9, standard AdGuard DNS). Choose based on what you actually need to block.

A determined user on the network can bypass DNS-level filtering by manually setting a different resolver on their device. DNS filtering is effective as a first layer but is not a complete solution on its own.

Custom Rules Vs Simple Presets

Simple presets like OpenDNS FamilyShield and Cloudflare for Families require no account and no configuration. You enter the IP addresses and the filtering is active immediately. This is the right approach for households that need basic protection with minimal setup.

Custom rule systems like Control D and NextDNS let you build your own blocking categories, whitelist specific domains, and review per-device query logs through a dashboard. For home lab operators managing complex archival workflows, the ability to whitelist specific dataset sources while blocking everything else in a category is genuinely useful.

The tradeoff is setup time and ongoing maintenance. Presets are set and forgotten. Custom systems require periodic review to make sure your rules are not blocking legitimate sources.

Pairing These DNS Servers With Pi-hole Or AdGuard Home

If you’re running a homelab, there’s a good chance you already run (or are considering) Pi-hole or AdGuard Home for network-wide ad and tracker blocking. Neither one replaces the resolvers above — they sit in front of them. Pi-hole and AdGuard Home filter and log queries locally on your own hardware, then forward whatever isn’t blocked to an upstream DNS server for the actual lookup.

That upstream choice matters more than most guides mention. A slow or logging-heavy upstream resolver undoes a lot of what a local ad-blocker is trying to accomplish. For most homelab setups, Cloudflare (1.1.1.1) or Quad9 make solid upstream picks behind Pi-hole: fast, widely available DoH/DoT support, and no meaningful logging beyond what your local install already sees. If your Pi-hole box is also fielding archival traffic, Quad9’s active malware blocking is a reasonable second layer on top of whatever categories you’re already filtering locally.

Going Further: Skipping The Upstream Provider Entirely With Unbound

Pointing Pi-hole at Cloudflare or Quad9 still means a third party sees every query that isn’t blocked locally — you’ve moved the visibility, not eliminated it. Unbound removes that dependency by acting as its own validating, recursive resolver: instead of forwarding your queries to someone else’s DNS server, it talks directly to the domain’s authoritative root servers and resolves the lookup itself.

The tradeoff is speed versus independence. A big anycast provider like Cloudflare has a warm cache serving millions of users, so a first-time lookup often comes back faster than Unbound resolving it cold. But for a homelab where privacy and self-reliance matter more than shaving milliseconds off an uncached query, Unbound is the more complete answer than any public resolver on this list.

Unbound is lightweight enough to run alongside Pi-hole on the same box (a Raspberry Pi or small NAS handles both without strain), and the two are commonly paired: Pi-hole handles local filtering and ad-blocking, then forwards whatever survives that filter to a local Unbound instance instead of an external provider. That combination is one of the most-recommended homelab DNS setups for exactly this reason — it’s the only configuration here that never sends a query to anyone else’s server at all.

How To Configure DNS On Your Devices And Router

Changing DNS settings takes a few minutes on any platform. The most important decision is whether to configure it at the router level or on individual devices.

Primary And Secondary DNS Basics

Every DNS configuration requires a primary DNS address and a secondary DNS address. The primary and secondary DNS are not a primary-backup relationship exactly. Your device may query either one at any time, and both should point to the same provider to avoid inconsistent behavior.

For example, Cloudflare’s primary DNS is 1.1.1.1 and its secondary is 1.0.0.1. Quad9’s primary and secondary are 9.9.9.9 and 149.112.112.112. Always enter both. Relying on a single preferred DNS server leaves you with no fallback if that resolver becomes temporarily unreachable.

Router-Wide Setup Vs Per-Device Setup

Configuring DNS at the router level is the most efficient approach. All devices on the network inherit the new DNS IP addresses automatically. You change two fields in your router’s admin panel, and every connected device benefits without further action.

Per-device setup gives you more granularity. You can point your archival workstation at a privacy-focused resolver like Mullvad while leaving other devices on Cloudflare. This is useful in home lab environments where different machines have different requirements.

On most routers, the DNS fields are found in the WAN settings or Internet settings section. Enter your chosen public DNS servers in the primary and secondary fields. Save and reboot the router for changes to take full effect.

On Windows, DNS is set under Network Adapter Properties. On macOS, it is in System Settings under Network. On Android and iOS, per-connection DNS is set in the WiFi network details, and both platforms support private DNS (DoT) system-wide in their settings.

How To Verify Your Resolver Is Working

After changing your DNS settings, verify that traffic is actually going through the new resolver. Several free browser-based tools let you check which DNS server is being used and whether encrypted DNS is active.

A quick command-line check on any platform:

On Windows, open Command Prompt and run nslookup datahoarder.io. The response will show which server handled the lookup.
On macOS or Linux, run dig datahoarder.io in Terminal. Look for the SERVER: line in the output.

If the resolver IP shown does not match what you configured, flush your DNS cache (details in the next section) and recheck.

Testing Performance And Fixing Common Problems

Performance testing tells you which of the fastest DNS servers actually performs best from your specific network. Troubleshooting tools help when DNS server not responding errors appear or when lookups are unexpectedly slow.

How To Benchmark DNS Speed

DNS speed testing tools send queries to multiple resolvers simultaneously from your location and measure round-trip times in milliseconds. Running a benchmark before and after switching lets you confirm the change made a real difference.

Browser-based tools like the ones referenced in our research sources test 24-plus resolvers in seconds. Desktop tools like Gibson Research Corporation’s DNS Benchmark (Windows) let you run more thorough tests including cached and uncached lookups.

Run benchmarks at different times of day. A resolver that is fast during off-peak hours may slow down under heavier evening traffic. The anycast network architecture used by Cloudflare and Google helps flatten this variation, but local network conditions still affect your results.

DNS Cache And Lookup Checks

Your operating system and your router both maintain a DNS cache. This cache stores recent lookup results to avoid querying the resolver for every repeated request. A stale or corrupt cache entry can cause browsing problems even when the resolver itself is working correctly.

To flush the DNS cache:

  • Windows: Run ipconfig /flushdns in an elevated Command Prompt
  • macOS: Run sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder in Terminal
  • Linux: Run sudo systemctl restart systemd-resolved if using systemd-resolved

After flushing, run a DNS lookup for a known domain to confirm the resolver is responding. If queries time out after a flush, the issue is likely with the resolver or your network configuration rather than a stale cache entry.

What To Do When DNS Server Not Responding Appears

A “DNS server not responding” error means your device queried the resolver and received no answer within the timeout window. Start with the simplest possible checks:

  1. Confirm your primary and secondary DNS IP addresses are entered correctly. A single digit typo is a common cause.
  2. Ping the resolver IP directly to check basic reachability: ping 1.1.1.1 or ping 8.8.8.8 from Command Prompt or Terminal.
  3. Temporarily switch to a different public DNS service to determine whether the issue is with the specific resolver or with your broader network connection.
  4. Restart your router and modem. DHCP lease issues can sometimes corrupt DNS assignments at the router level.

If the error persists across multiple resolvers, the issue is likely upstream of DNS. Check your internet connection status with your ISP before continuing to troubleshoot the resolver.

Frequently Asked Questions

Which public DNS providers are most reliable for speed and uptime?

Cloudflare (1.1.1.1) and Google Public DNS (8.8.8.8) are the most consistently reliable public DNS providers globally. Both operate large anycast networks spanning hundreds of cities, which distributes load and minimizes single points of failure. Quad9 has significantly expanded its anycast footprint in recent years and is a strong third option.

How do I find the fastest DNS server for my location and ISP?

Run a DNS benchmark tool from your specific network. Browser-based tools and desktop utilities like GRC’s DNS Benchmark send real queries to dozens of resolvers and return actual latency measurements from your location. The fastest DNS servers globally, such as Cloudflare and Google, may not always be fastest for a specific ISP due to peering arrangements.

Which DNS settings should I use as primary and secondary on my router?

Enter the primary and secondary DNS addresses from the same provider. For Cloudflare, that is 1.1.1.1 as primary and 1.0.0.1 as secondary. For Quad9, use 9.9.9.9 as primary and 149.112.112.112 as secondary. For Google Public DNS, use 8.8.8.8 as primary and 8.8.4.4 as secondary. Always populate both fields for redundancy.

What DNS servers should I use for gaming to reduce latency on PC and consoles?

Cloudflare 1.1.1.1 and Google 8.8.8.8 are the best choices for gaming. DNS does not affect in-game ping once a session is established, but a fast resolver reduces matchmaking and server lookup times. Set DNS at the router level for PC, but configure it directly on the console since many consoles handle DNS independently of router settings.

Which DNS servers support IPv6 and how do I configure them?

Cloudflare, Google, Quad9, AdGuard, and OpenDNS all support IPv6. Cloudflare’s IPv6 addresses are 2606:4700:4700::1111 and 2606:4700:4700::1001. Google’s are 2001:4860:4860::8888 and 2001:4860:4860::8844. Enter these in the IPv6 DNS fields on your router or device alongside the standard IPv4 addresses. Check your router’s WAN settings for a dedicated IPv6 DNS field.

What DNS servers are good for ad blocking and privacy?

AdGuard DNS (94.140.14.14 / 94.140.15.15) blocks ads, trackers, and malicious domains at the resolver level with no software installation required. Mullvad DNS (194.242.2.2) is the strongest pure-privacy option with zero query logging. For a combination of privacy and security blocking, Quad9 (9.9.9.9) is a reliable choice that does not log personal data and blocks known-malicious domains automatically.

About the Author

Don is a tech enthusiast with a passion for datahoarding, privacy, and security. He has been involved in technology for over a decade, working in various roles such as a desktop support engineer, network administrator, and IT consultant. Don's extensive experience in the tech industry has given him a deep understanding of how technology works and how to use it to its fullest potential.

Don is particularly interested in topics such as VPNs, privacy and IRC, which are all related to data privacy and security. He believes that protecting our digital privacy is essential, especially in today's world where data breaches and cyber attacks are becoming more common. Don has dedicated himself to educating himself and others on how to protect their digital privacy and stay safe online.

In addition to his tech expertise, Don is also an avid gamer. He enjoys playing video games in his free time, and is also a family man who enjoys spending time with his wife and children. He believes that technology should enhance our lives and bring us closer together, and he strives to promote this message through his work.