Every time someone in your office opens a website, their device first asks a DNS resolver to translate the name into an IP address. By default that resolver belongs to your internet provider, and its quality varies. Switching to a public resolver is free and takes minutes, which is why "what is the best public DNS server?" is such a common question. The honest answer is that the four big options are all reliable; they differ in privacy commitments, security filtering and features, and the right choice depends on what you value.
What a public resolver actually changes
A resolver (also called a recursive DNS server) does the legwork of finding answers on behalf of your devices and caching them. Changing it affects:
- Who sees your browsing destinations. The resolver operator sees every domain your network looks up.
- Security. Some resolvers refuse to resolve known malware and phishing domains.
- Reliability. Large anycast networks, where the same IP address is served from many locations, tend to be very resilient.
- Speed, slightly. Lookup time depends on how close the nearest server is and how often answers are already cached. Differences are usually small, and they vary by location, so test from your own network rather than trusting general rankings.
It does not change your internet speed, hide your IP address from websites, or replace a VPN.
The four resolvers at a glance
| Google Public DNS | Cloudflare | Quad9 | OpenDNS (Cisco) | |
|---|---|---|---|---|
| IPv4 | 8.8.8.8, 8.8.4.4 | 1.1.1.1, 1.0.0.1 | 9.9.9.9, 149.112.112.112 | 208.67.222.222, 208.67.220.220 |
| IPv6 | 2001:4860:4860::8888, ::8844 | 2606:4700:4700::1111, ::1001 | 2620:fe::fe, 2620:fe::9 | 2620:119:35::35, 2620:119:53::53 |
| Blocks malicious domains | No | Optional (1.1.1.2) | Yes, by default | Yes, with account options |
| Family / adult filtering | No | Optional (1.1.1.3) | No | FamilyShield (208.67.222.123) or custom categories |
| Encrypted DNS (DoH/DoT) | Yes | Yes | Yes | DoH supported |
| Operator | Cloudflare | Non-profit foundation based in Switzerland | Cisco |
Addresses and features can change, so confirm them in each provider's own documentation before rolling them out across an office.
Google Public DNS
The longest-established of the large public resolvers. It validates DNSSEC, supports DNS over HTTPS and DNS over TLS, and returns answers without filtering. Google publishes a privacy page describing what it logs and for how long. It is a solid neutral choice when you simply want a fast, unfiltered resolver from an operator with a large global network.
Cloudflare 1.1.1.1
Cloudflare positions its resolver on privacy, publicly committing to limited logging and to independent audits of those commitments. It validates DNSSEC and supports encrypted DNS. The useful extra for businesses is choice: 1.1.1.1 is unfiltered, 1.1.1.2 blocks malware, and 1.1.1.3 blocks malware and adult content, all with no account required. For more control, such as custom block lists and per-office policies, Cloudflare sells a separate Zero Trust gateway product.
Quad9
Quad9 is run by a non-profit and blocks domains that appear in threat-intelligence feeds by default. If a domain is known to host malware or phishing, Quad9 returns no answer, so a click on a bad link in an email simply fails to load. It also validates DNSSEC. If you need an unfiltered variant for troubleshooting, Quad9 provides 9.9.9.10. For small offices without other security tooling, a resolver that blocks known-bad domains by default is a cheap extra layer of protection.
OpenDNS
OpenDNS, owned by Cisco, has the most configurable filtering of the four. With a free account linked to your office's IP address you can block whole categories of sites, and FamilyShield addresses block adult content with no setup at all. Cisco also sells a business security product built on the same platform. The trade-off is that account-based policies depend on OpenDNS recognising your public IP, which needs extra software or router support if your IP changes.
Which is best for a business?
- Small office wanting free malware protection: Quad9 or Cloudflare's
1.1.1.2. - Need content filtering by category: OpenDNS, or a paid DNS security service.
- Privacy is the priority: read each provider's privacy policy; Cloudflare and Quad9 make the strongest public commitments about minimal logging.
- Plain, unfiltered resolution: Google or Cloudflare
1.1.1.1.
If your network uses Active Directory or other internal DNS, do not point PCs directly at a public resolver; they will lose access to internal names. Instead configure your internal DNS servers to forward external queries to the public resolver of your choice.
How to switch
- At the router (affects every device on the network): in the router's WAN or DHCP settings, set the primary and secondary DNS servers to your chosen provider's two addresses.
- On a single Windows PC: Settings, Network and internet, your connection, DNS server assignment, Edit, Manual. Windows 11 also lets you enable DNS over HTTPS there for supported providers.
- On macOS: System Settings, Network, your connection, Details, DNS.
Use two addresses from the same provider rather than mixing providers, so filtering and behaviour are consistent. Then verify:
nslookup example.com 9.9.9.9
dig @1.1.1.1 example.com +short
Our DNS lookup tool lets you compare answers from different resolvers, and the DNS propagation checker shows whether resolvers around the world agree after you change your own domain's records.
Key takeaways
- Google, Cloudflare, Quad9 and OpenDNS are all reliable; choose on privacy, filtering and features rather than raw speed.
- Quad9 and Cloudflare's
1.1.1.2give free malware blocking with no account. - OpenDNS offers the richest category filtering.
- In networks with internal DNS, set public resolvers as forwarders, not on individual PCs.