Hacker News June 28, 2026 17 min signal 2026-06-28

Choosing a public DNS resolver

Archived text mirror, captured for personal reading when the Signal ran. Formatting is approximate — read the original at the source.

DNS Resolver Guide

Independent reference

Pick what matters to you, such as privacy, malware blocking, parental controls, speed, IPv6, or a specific jurisdiction, and the finder narrows 29 global public resolvers to the ones that fit. A full comparison table and research-backed decision notes follow.

29 public resolvers

15 jurisdictions

DoH/DoT/DoQ encrypted transports

12 studies cited

Step 1 · Interactive finder

Find a resolver for your requirements

Check what matters to you. Transport, DNSSEC, IPv6, jurisdiction and operator type are hard filters. The priorities are scored and ranked.

My priorities

Maximum privacy and no logging Minimal or no query logging, privacy-first operator Block malware and phishing Security blocklist on by default or via a simple variant Block ads and trackers Network-wide ad and tracker filtering Parental controls and adult-content blocking Family or adult-content filter available No filtering (unaltered DNS)Returns answers exactly as published Fully customizable filtering Choose your own blocklists or rules via an account Top-tier speed (global anycast)Large low-latency anycast network Non-commercial operator Nonprofit, registry, community or public-interest, not a for-profit company

Must support encrypted DNS

DNS-over-HTTPS (DoH) DNS-over-TLS (DoT) DNS-over-QUIC (DoQ) DNSCrypt

Other requirements

Must validate DNSSEC Must offer IPv6 Provides IPv6 resolver addresses Operator jurisdiction Operator type

Recommended resolvers

29 shown

Showing all **29** resolvers that pass your requirements.

IPv4 94.140.14.14 94.140.15.15

IPv6 2a10:50c0::ad1:ff 2a10:50c0::ad2:ff

**Filtering:** Ads and trackers (default). Family: 94.140.14.15. Non-filtering: 94.140.14.140.

**Logging:** No PII (per policy) · **ECS:** No

DoH ✓DoT ✓DoQ ✓DNSCrypt ✓DNSSEC ✓IPv6 ✓

IPv4 149.112.121.10 149.112.122.10

IPv6 2620:10a:80bb::10 2620:10a:80bc::10

**Filtering:** Private (none, default). Protected (malware): .121.20/.122.20. Family (adult too): .121.30/.122.30.

**Logging:** Canadian privacy policy; no monetization · **ECS:** No

DoH ✓DoT ✓DoQ ✗DNSCrypt ✗DNSSEC ✓IPv6 ✓

IPv4 1.1.1.1 1.0.0.1

IPv6 2606:4700:4700::1111 2606:4700:4700::1001

**Filtering:** None (1.1.1.1). Malware: 1.1.1.2. Malware and adult (Family): 1.1.1.3.

**Logging:** No PII; limited data ~25h (audited) · **ECS:** No

DoH ✓DoT ✓DoQ ✗DNSCrypt ✗DNSSEC ✓IPv6 ✓

IPv4 76.76.2.0 76.76.10.0

IPv6 2606:1a40::2606:1a40:1::

**Filtering:** Free filtered profiles (malware, ads, social and more) plus fully custom resolvers. Unfiltered: 76.76.2.0.

**Logging:** Configurable, off available · **ECS:** Optional

DoH ✓DoT ✓DoQ ✓DNSCrypt ✓DNSSEC ✓IPv6 ✓

DNS.SB

Germany (EU) · Commercial (privacy)

IPv4 185.222.222.222 45.11.45.11

IPv6 2a09::2a11::

**Filtering:** None.

**Logging:** No logging (policy) · **ECS:** No · Privacy-first resolver by xTom GmbH; global anycast across 30 locations.

DoH ✓DoT ✓DoQ ✗DNSCrypt ✗DNSSEC ✓IPv6 ✓

DNS4EU

European Union · EU-funded

IPv4 86.54.11.1 86.54.11.201

IPv6 2a13:1001::86:54:11:1 2a13:1001::86:54:11:201

**Filtering:** Protective: malware and phishing (default). Variants add ads, add adult (child), or unfiltered 86.54.11.100.

**Logging:** EU and GDPR; no commercial use of data · **ECS:** No

DoH ✓DoT ✓DoQ ✗DNSCrypt ✗DNSSEC ✓IPv6 ✓

IPv4 194.242.2.2

IPv6 2a07:e340::2

**Filtering:** Base unfiltered (194.242.2.2). adblock .2.3, base with malware .2.4, extended .2.5, all with adult .2.9.

**Logging:** No logging · **ECS:** No

DoH ✓DoT ✓DoQ ✓DNSCrypt ✗DNSSEC ✓IPv6 ✓

IPv4 Personalized config (trial: 45.90.28.0 / 45.90.30.0)

IPv6 2a07:a8c0:: (personalized)

**Filtering:** Fully customizable: ads, trackers, parental, security blocklists.

**Logging:** Configurable, can disable all logging · **ECS:** Optional

DoH ✓DoT ✓DoQ ✓DNSCrypt ✓DNSSEC ✓IPv6 ✓

IPv4 101.101.101.101 101.102.103.104

IPv6 2001:de4::101 2001:de4::102

**Filtering:** None.

**Logging:** No logging · **ECS:** No

DoH ✓DoT ✓DoQ ✗DNSCrypt ✗DNSSEC ✓IPv6 ✓

Quad9

Switzerland · Nonprofit

IPv4 9.9.9.9 149.112.112.112

IPv6 2620:fe::9 2620:fe::fe

**Filtering:** Malware and phishing blocklist (default). Unfiltered: 9.9.9.10. Filtered with ECS: 9.9.9.11.

**Logging:** No PII, no IP retention · **ECS:** No (ECS on 9.9.9.11)

DoH ✓DoT ✓DoQ ✓DNSCrypt ✓DNSSEC ✓IPv6 ✓

IPv4 193.17.47.1 185.43.135.1

IPv6 2001:148f:ffff::1 2001:148f:fffe::1

**Filtering:** None.

**Logging:** IP held minutes only, never logged; anonymized research samples · **ECS:** No · Czech registry's Open DNSSEC-Validating Resolvers; DoT and DoH at odvr.nic.cz.

DoH ✓DoT ✓DoQ ✗DNSCrypt ✗DNSSEC ✓IPv6 ✓

IPv4 84.200.69.80 84.200.70.40

IPv6 2001:1608:10:25::1c04:b12f 2001:1608:10:25::9249:d69b

**Filtering:** None. No filtering, no censorship.

**Logging:** No logging · **ECS:** No · Plain DNS only (no DoH/DoT).

DoH ✗DoT ✗DoQ ✗DNSCrypt ✗DNSSEC ✓IPv6 ✓

OpenNIC

Global (volunteer) · Community

IPv4 Varies (pick nearby volunteer servers)

IPv6 varies by node

**Filtering:** No central filtering; also resolves alternative and peer TLDs.

**Logging:** Operator-dependent (varies) · **ECS:** No · Decentralized volunteer network; per-server policies vary, so choose a trusted nearby node.

DoH ✓DoT ✓DoQ ✗DNSCrypt ✗DNSSEC ✓IPv6 ✓

IPv4 91.239.100.100 (anycast)89.233.43.71 (unicast)

IPv6 2001:67c:28a4::2a01:3a0:53:53::

**Filtering:** None. Anti-censorship, no filtering.

**Logging:** No logging · **ECS:** No · Encrypted-only: cleartext port 53 disabled (2022). DoH/DoT/DoQ/DoH3. Run by one individual in Denmark.

DoH ✓DoT ✓DoQ ✓DNSCrypt ✗DNSSEC ✓IPv6 ✓

IPv4 185.71.138.138

IPv6 2001:67c:930::1

**Filtering:** None.

**Logging:** No logging (policy) · **ECS:** No · Encrypted-transport focused (DoH/DoT).

DoH ✓DoT ✓DoQ ✗DNSCrypt ✗DNSSEC ✓IPv6 ✓

IPv4 114.114.114.114 114.114.115.115

**Filtering:** Basic (default). Block malicious sites: 114.114.114.119. Family and anti-fraud: 114.114.114.110.

**Logging:** Logs; subject to local regulations · **ECS:** Unknown · One of the most-used resolvers in China; IPv4-only, no encrypted transport; operates under Chinese regulations.

DoH ✗DoT ✗DoQ ✗DNSCrypt ✗DNSSEC ✗IPv6 ✗

IPv4 101.226.4.6 218.30.118.6

**Filtering:** Security and malware filtering; subject to Chinese regulations.

**Logging:** Logs; subject to local regulations · **ECS:** Unknown · Security-oriented; published addresses are IPv4-only; operates under Chinese regulations.

DoH ✗DoT ✗DoQ ✗DNSCrypt ✗DNSSEC ✗IPv6 ✗

IPv4 223.5.5.5 223.6.6.6

IPv6 2400:3200::1 2400:3200:baba::1

**Filtering:** None advertised; subject to Chinese regulations.

**Logging:** Logs; subject to local regulations · **ECS:** Yes · Operates under Chinese regulations (may reflect local filtering).

DoH ✓DoT ✓DoQ ✓DNSCrypt ✗DNSSEC ✓IPv6 ✓

IPv4 180.76.76.76

**Filtering:** None advertised; subject to Chinese regulations.

**Logging:** Logs; subject to local regulations · **ECS:** Unknown · IPv4-only (per Baidu's own docs); operates under Chinese regulations.

DoH ✗DoT ✗DoQ ✗DNSCrypt ✗DNSSEC ✗IPv6 ✗

IPv4 119.29.29.29

IPv6 2402:4e00::

**Filtering:** None advertised; subject to Chinese regulations.

**Logging:** Logs; subject to local regulations · **ECS:** Yes · Operates under Chinese regulations.

DoH ✓DoT ✓DoQ ✓DNSCrypt ✗DNSSEC ✓IPv6 ✓

IPv4 95.85.95.85 2.56.220.2

IPv6 2a03:90c0:999d::1 2a03:90c0:9992::1

**Filtering:** None.

**Logging:** Privacy policy · **ECS:** No · Plain DNS with EDNS padding; no DoH/DoT per latest data.

DoH ✗DoT ✗DoQ ✗DNSCrypt ✗DNSSEC ✓IPv6 ✓

IPv4 8.8.8.8 8.8.4.4

IPv6 2001:4860:4860::8888 2001:4860:4860::8844

**Filtering:** None.

**Logging:** Anonymized samples; no PII correlation · **ECS:** Yes

DoH ✓DoT ✓DoQ ✗DNSCrypt ✗DNSSEC ✓IPv6 ✓

IPv4 208.67.222.222 208.67.220.220

IPv6 2620:119:35::35 2620:119:53::53

**Filtering:** Account-configurable. FamilyShield (adult): 208.67.222.123 / 208.67.220.123.

**Logging:** Logs query data (Cisco) · **ECS:** Yes

DoH ✗DoT ✓DoQ ✗DNSCrypt ✓DNSSEC ✓IPv6 ✓

IPv4 64.6.64.6 64.6.65.6

IPv6 2620:74:1b::1:1 2620:74:1c::2:2

**Filtering:** Tiered: threat (156.154.70.2), family and security tiers (.70.3/.70.4), no-redirect (.70.5).

**Logging:** Logs · **ECS:** No · Verisign's former public DNS, now operated by Vercara.

DoH ✗DoT ✗DoQ ✗DNSCrypt ✗DNSSEC ✓IPv6 ✓

IPv4 77.88.8.8 77.88.8.1

IPv6 2a02:6b8::feed:0ff 2a02:6b8:0:1::feed:0ff

**Filtering:** Basic (default). Safe: 77.88.8.88. Family: 77.88.8.7.

**Logging:** Logs (Russian jurisdiction) · **ECS:** Yes · Russian jurisdiction; weigh data-governance implications.

DoH ✓DoT ✓DoQ ✗DNSCrypt ✓DNSSEC ✗IPv6 ✓

IPv4 185.228.168.9 185.228.169.9

IPv6 2a0d:2a00:1::2a0d:2a00:2::

**Filtering:** Security (default). Family: 185.228.168.168. Adult: 185.228.168.10.

**Logging:** Minimal · **ECS:** No

DoH ✓DoT ✓DoQ ✗DNSCrypt ✗DNSSEC ✓IPv6 ✓

IPv4 8.26.56.26 8.20.247.20

**Filtering:** Malware and phishing blocking.

**Logging:** Logs · **ECS:** No · Legacy service. No encrypted transport, limited maintenance.

DoH ✗DoT ✗DoQ ✗DNSCrypt ✗DNSSEC ✗IPv6 ✗

IPv4 74.82.42.42

IPv6 2001:470:20::2

**Filtering:** None.

**Logging:** No stated policy · **ECS:** No · Free recursive resolver from a major backbone operator; plain DNS only, no published filtering or logging policy.

DoH ✗DoT ✗DoQ ✗DNSCrypt ✗DNSSEC ✗IPv6 ✓

IPv4 195.46.39.39 195.46.39.40

IPv6 2a05:d014:939:3300::39 2a05:d014:939:3300::40

**Filtering:** Content filtering (family and business categories, account-based).

**Logging:** Logs (filtering service) · **ECS:** No · Commercial content-filtering service; free tier is limited.

DoH ✓DoT ✓DoQ ✗DNSCrypt ✗DNSSEC ✓IPv6 ✓

Step 2 · Live latency test

Test DNS speed from your location

This measures DNS-over-HTTPS round-trip time from your browser to each DoH-capable resolver, so you can see which is fastest where you actually are. Plain-DNS-only resolvers cannot be tested this way. Results are a relative guide and include TLS and HTTP overhead, so run it a couple of times. Your browser queries each resolver directly, which reveals your IP address to them; nothing is sent anywhere else.

Benchmarks the DoH-capable resolvers, takes a few seconds.

| # | Resolver | Median | Latency | Best | | --- | --- | --- | --- | --- | | Press Run to benchmark from your location. |

Technique inspired by the open-source DNS Speed Test by Silviu Stroe (GPL-3.0); this is an independent implementation. It runs only when this page is served over HTTPS. For resolvers not testable here, that dedicated tool benchmarks a wider DoH set.

Step 3 · Full comparison

All 29 global public resolvers

Click a column header to sort. Search by name, operator, jurisdiction, or feature. Filter-variant addresses (malware, family, unfiltered) are listed in the Filtering cell.

| Resolver | Jurisdiction | Type | Primary IPs (v4 / v6) | Filtering (default and variants) | DNSSEC | Transports | Logging | ECS | | --- | --- | --- | --- | --- | --- | --- | --- | --- | | **114DNS** One of the most-used resolvers in China; IPv4-only, no encrypted transport; operates under Chinese regulations. | China | Commercial | 114.114.114.114 114.114.115.115 IPv4 only | Basic (default). Block malicious sites: 114.114.114.119. Family and anti-fraud: 114.114.114.110. | No | plain only | Logs; subject to local regulations | Unknown | | **360 Secure DNS** Security-oriented; published addresses are IPv4-only; operates under Chinese regulations. | China | Commercial | 101.226.4.6 218.30.118.6 IPv4 only | Security and malware filtering; subject to Chinese regulations. | No | plain only | Logs; subject to local regulations | Unknown | | **AdGuard DNS** | Cyprus (EU) | Commercial | 94.140.14.14 94.140.15.15 2a10:50c0::ad1:ff 2a10:50c0::ad2:ff | Ads and trackers (default). Family: 94.140.14.15. Non-filtering: 94.140.14.140. | Yes | DoH DoT DoQ DNSCrypt | No PII (per policy) | No | | **AliDNS (Alibaba)** Operates under Chinese regulations (may reflect local filtering). | China | Commercial | 223.5.5.5 223.6.6.6 2400:3200::1 2400:3200:baba::1 | None advertised; subject to Chinese regulations. | Yes | DoH DoT DoQ | Logs; subject to local regulations | Yes | | **Baidu DNS** IPv4-only (per Baidu's own docs); operates under Chinese regulations. | China | Commercial | 180.76.76.76 IPv4 only | None advertised; subject to Chinese regulations. | No | plain only | Logs; subject to local regulations | Unknown | | **CIRA Canadian Shield** | Canada | Nonprofit (registry) | 149.112.121.10 149.112.122.10 2620:10a:80bb::10 2620:10a:80bc::10 | Private (none, default). Protected (malware): .121.20/.122.20. Family (adult too): .121.30/.122.30. | Yes | DoH DoT | Canadian privacy policy; no monetization | No | | **CleanBrowsing** | United States | Commercial | 185.228.168.9 185.228.169.9 2a0d:2a00:1:: 2a0d:2a00:2:: | Security (default). Family: 185.228.168.168. Adult: 185.228.168.10. | Yes | DoH DoT | Minimal | No | | **Cloudflare 1.1.1.1** | United States | Commercial | 1.1.1.1 1.0.0.1 2606:4700:4700::1111 2606:4700:4700::1001 | None (1.1.1.1). Malware: 1.1.1.2. Malware and adult (Family): 1.1.1.3. | Yes | DoH DoT | No PII; limited data ~25h (audited) | No | | **Comodo Secure DNS** Legacy service. No encrypted transport, limited maintenance. | United States | Commercial | 8.26.56.26 8.20.247.20 IPv4 only | Malware and phishing blocking. | No | plain only | Logs | No | | **Control D** | Canada | Commercial | 76.76.2.0 76.76.10.0 2606:1a40:: 2606:1a40:1:: | Free filtered profiles (malware, ads, social and more) plus fully custom resolvers. Unfiltered: 76.76.2.0. | Yes | DoH DoT DoQ DNSCrypt | Configurable, off available | Optional | | **CZ.NIC ODVR** Czech registry's Open DNSSEC-Validating Resolvers; DoT and DoH at odvr.nic.cz. | Czech Republic (EU) | Nonprofit (registry) | 193.17.47.1 185.43.135.1 2001:148f:ffff::1 2001:148f:fffe::1 | None. | Yes | DoH DoT | IP held minutes only, never logged; anonymized research samples | No | | **DNS.SB** Privacy-first resolver by xTom GmbH; global anycast across 30 locations. | Germany (EU) | Commercial (privacy) | 185.222.222.222 45.11.45.11 2a09:: 2a11:: | None. | Yes | DoH DoT | No logging (policy) | No | | **DNS.WATCH** Plain DNS only (no DoH/DoT). | Germany (EU) | Community / free | 84.200.69.80 84.200.70.40 2001:1608:10:25::1c04:b12f 2001:1608:10:25::9249:d69b | None. No filtering, no censorship. | Yes | plain only | No logging | No | | **DNS4EU** | European Union | EU-funded | 86.54.11.1 86.54.11.201 2a13:1001::86:54:11:1 2a13:1001::86:54:11:201 | Protective: malware and phishing (default). Variants add ads, add adult (child), or unfiltered 86.54.11.100. | Yes | DoH DoT | EU and GDPR; no commercial use of data | No | | **DNSPod (Tencent)** Operates under Chinese regulations. | China | Commercial | 119.29.29.29 2402:4e00:: | None advertised; subject to Chinese regulations. | Yes | DoH DoT DoQ | Logs; subject to local regulations | Yes | | **Gcore DNS** Plain DNS with EDNS padding; no DoH/DoT per latest data. | Luxembourg (EU) | Commercial | 95.85.95.85 2.56.220.2 2a03:90c0:999d::1 2a03:90c0:9992::1 | None. | Yes | plain only | Privacy policy | No | | **Google Public DNS** | United States | Commercial | 8.8.8.8 8.8.4.4 2001:4860:4860::8888 2001:4860:4860::8844 | None. | Yes | DoH DoT | Anonymized samples; no PII correlation | Yes | | **Hurricane Electric** Free recursive resolver from a major backbone operator; plain DNS only, no published filtering or logging policy. | United States | Commercial (backbone) | 74.82.42.42 2001:470:20::2 | None. | No | plain only | No stated policy | No | | **Mullvad DNS** | Sweden (EU) | Commercial (privacy) | 194.242.2.2 2a07:e340::2 | Base unfiltered (194.242.2.2). adblock .2.3, base with malware .2.4, extended .2.5, all with adult .2.9. | Yes | DoH DoT DoQ | No logging | No | | **NextDNS** | United States | Commercial | Personalized config (trial: 45.90.28.0 / 45.90.30.0) 2a07:a8c0:: (personalized) | Fully customizable: ads, trackers, parental, security blocklists. | Yes | DoH DoT DoQ DNSCrypt | Configurable, can disable all logging | Optional | | **OpenDNS / Cisco Umbrella** | United States | Commercial | 208.67.222.222 208.67.220.220 2620:119:35::35 2620:119:53::53 | Account-configurable. FamilyShield (adult): 208.67.222.123 / 208.67.220.123. | Yes | DoT DNSCrypt | Logs query data (Cisco) | Yes | | **OpenNIC** Decentralized volunteer network; per-server policies vary, so choose a trusted nearby node. | Global (volunteer) | Community | Varies (pick nearby volunteer servers) varies by node | No central filtering; also resolves alternative and peer TLDs. | Yes | DoH DoT | Operator-dependent (varies) | No | | **Quad101 (TWNIC)** | Taiwan | Nonprofit (registry) | 101.101.101.101 101.102.103.104 2001:de4::101 2001:de4::102 | None. | Yes | DoH DoT | No logging | No | | **Quad9** | Switzerland | Nonprofit | 9.9.9.9 149.112.112.112 2620:fe::9 2620:fe::fe | Malware and phishing blocklist (default). Unfiltered: 9.9.9.10. Filtered with ECS: 9.9.9.11. | Yes | DoH DoT DoQ DNSCrypt | No PII, no IP retention | No (ECS on 9.9.9.11) | | **SafeDNS** Commercial content-filtering service; free tier is limited. | United States | Commercial | 195.46.39.39 195.46.39.40 2a05:d014:939:3300::39 2a05:d014:939:3300::40 | Content filtering (family and business categories, account-based). | Yes | DoH DoT | Logs (filtering service) | No | | **UncensoredDNS** Encrypted-only: cleartext port 53 disabled (2022). DoH/DoT/DoQ/DoH3. Run by one individual in Denmark. | Denmark (EU) | Community / free | 91.239.100.100 (anycast) 89.233.43.71 (unicast) 2001:67c:28a4:: 2a01:3a0:53:53:: | None. Anti-censorship, no filtering. | Yes | DoH DoT DoQ | No logging | No | | **Vercara UltraDNS (ex-Neustar)** Verisign's former public DNS, now operated by Vercara. | United States | Commercial | 64.6.64.6 64.6.65.6 2620:74:1b::1:1 2620:74:1c::2:2 | Tiered: threat (156.154.70.2), family and security tiers (.70.3/.70.4), no-redirect (.70.5). | Yes | plain only | Logs | No | | **Wikimedia DNS** Encrypted-transport focused (DoH/DoT). | Global (nonprofit) | Nonprofit | 185.71.138.138 2001:67c:930::1 | None. | Yes | DoH DoT | No logging (policy) | No | | **Yandex DNS** Russian jurisdiction; weigh data-governance implications. | Russia | Commercial | 77.88.8.8 77.88.8.1 2a02:6b8::feed:0ff 2a02:6b8:0:1::feed:0ff | Basic (default). Safe: 77.88.8.88. Family: 77.88.8.7. | No | DoH DoT DNSCrypt | Logs (Russian jurisdiction) | Yes |

Evidence

How to decide: what the research says

Findings from peer-reviewed DNS measurement studies that should shape the trade-offs above.

Speed: plain DNS has the lowest latency, but encrypted keeps up

Encrypted transports (DoH and DoT) add latency per query, yet whole-page load times are often close to plain DNS, and DoH's overhead is small in practice. On lossy or high-latency links, plain Do53 still wins. Performance also varies by provider and region, so the fastest resolver depends on where you are.

Hounsel et al., WWW 2020; Böttger et al., IMC 2019; Chhabra et al., IMC 2021.

Encrypted DNS resists tampering, not just snooping

The largest end-to-end study of encrypted DNS found queries are far less likely to be intercepted or altered in transit than plain DNS, with only minor overhead. Operator quality varies, though: about 25% of DoT providers in that study served invalid TLS certificates, so favour well-run providers.

Lu et al., IMC 2019.

Encryption hides queries from the network, not from the resolver

Whichever provider you choose still sees every domain you look up. If that worries you, prefer no-logging operators, or an oblivious design (ODoH) where a proxy separates your identity from your queries so no single party sees both. Cloudflare and Apple have deployed ODoH.

Schmitt, Edmundson & Feamster, PoPETS 2019; Singanamalla et al., 2021.

DNSSEC validation is what stops forged answers

Only a validating resolver protects you from spoofed records. Google, Cloudflare and Quad9 all validate, and they handled the first root-key (KSK) rollover without breaking users. If integrity matters, treat DNSSEC validation as a must.

Müller et al., IMC 2019.

ECS trades speed for privacy

EDNS Client Subnet sends part of your IP to CDNs for better geo-routing. Google and OpenDNS send it for sharper CDN mapping; Cloudflare and standard Quad9 leave it off for privacy. Pick based on which you value more.

"A Look at the ECS Behavior of DNS Resolvers", IMC 2019.

Jurisdiction and centralization matter too

The operator's legal home governs what can be compelled or logged, and a handful of providers now carry a large share of the world's recursive traffic. The U.S. NSA has also warned that external resolvers bypass internal DNS filtering and inspection, so weigh control against convenience.

Moura et al., IMC 2020; NSA guidance, 2021.

DNS-over-QUIC is now the fastest encrypted transport

A 2022 measurement of DoQ found it already beats both DoT and DoH on response time, though about 40% of handshakes were slowed by QUIC's address-validation limit. Where your client and resolver both support it (Quad9, AdGuard, NextDNS, Control D, Mullvad, UncensoredDNS, and the Chinese majors here), DoQ is the encrypted option to prefer.

Kosek et al., PAM 2022.

DNSCrypt: the oldest encrypted option, and the hardest to measure

DNSCrypt predates DoH, DoT, and DoQ (version 2 dates to 2013). It encrypts from the first packet using a resolver's pre-shared public key, so there is no plaintext hostname lookup and no dependency on certificate authorities, and its Anonymized DNS mode (2019) also hides client IPs. Among the resolvers here it is offered by Quad9, OpenDNS, AdGuard, NextDNS, Control D, and Yandex. Reliable usage numbers are scarce, though: population-scale measurements such as APNIC Labs track DoH and DoT but not DNSCrypt, so there is no trustworthy public figure for how many people use it.

DNSCrypt Project; APNIC Labs encrypted-DNS measurement.

Encryption does not hide which sites you visit

Even over DoH, traffic analysis can identify the domains you visit with high accuracy, and the standard EDNS padding does not fully prevent it. If that threat model applies to you, pair encrypted DNS with Tor or an oblivious design rather than relying on padding.

Siby et al., NDSS 2020.

Public resolvers do not behave the same way

A 2023 study of Extended DNS Errors across major resolvers found they disagreed on diagnostic error reporting in 94% of test cases, with Cloudflare the most precise. Implementation quality and standards compliance differ between providers, which affects troubleshooting and reliability.

Nosyk, Korczyński & Duda, IMC 2023.

**References**

  • A. Hounsel et al., "Comparing the Effects of DNS, DoT, and DoH on Web Performance", WWW 2020 (arXiv:1907.08089).
  • T. Böttger et al., "An Empirical Study of the Cost of DNS-over-HTTPS", ACM IMC 2019.
  • R. Chhabra, P. Murley, D. Kumar, M. Bailey, G. Wang, "Measuring DNS-over-HTTPS Performance Around the World", ACM IMC 2021.
  • C. Lu et al., "An End-to-End, Large-Scale Measurement of DNS-over-Encryption: How Far Have We Come?", ACM IMC 2019.
  • M. Kosek et al., "One to Rule Them All? A First Look at DNS over QUIC", PAM 2022 (arXiv:2202.02987).
  • S. Siby et al., "Encrypted DNS => Privacy? A Traffic Analysis Perspective", NDSS 2020 (arXiv:1906.09682).
  • P. Schmitt, A. Edmundson, N. Feamster, "Oblivious DNS: Practical Privacy for DNS Queries", PoPETS 2019 (arXiv:1806.00276).
  • S. Singanamalla et al., "Oblivious DNS over HTTPS (ODoH)", arXiv:2011.10121.
  • M. Müller et al., "Roll, Roll, Roll your Root: Analysis of the First Ever DNSSEC Root KSK Rollover", ACM IMC 2019.
  • "A Look at the ECS Behavior of DNS Resolvers", ACM IMC 2019.
  • G. Moura, S. Castro, W. Hardaker, M. Wullink, C. Hesselman, "Clouding up the Internet: how centralized is DNS traffic becoming?", ACM IMC 2020.
  • Y. Nosyk, M. Korczyński, A. Duda, "Extended DNS Errors: Unlocking the Full Potential of DNS Troubleshooting", ACM IMC 2023.

**Smaller, community-run, and regional resolvers**

Niche, hobby, community, or country-specific services that are not in the comparison above. Worth knowing about, but check their current status and policies before relying on them. The European entries are catalogued by European Alternatives. Resolvers based in heavily censored or sanctioned regions may enforce local content rules or, conversely, exist mainly to bypass geo-blocks, so treat those with extra care.

  • DNS4all (194.0.5.3): European resolver focused on neutrality and performance; unfiltered.
  • BlahDNS: open-source hobby ad-blocking project with DoH, DoT, and DoQ, run on small regional servers.
  • LibreDNS: community resolver by LibreOps with ad-blocking and a no-logging policy; DoH and DoT.
  • Dismail.de: privacy-focused German community resolver with no logging; DoH and DoT.
  • Foundation for Applied Privacy (Austria): non-profit, no-logging; DoH and DoT.
  • Freifunk München (FFMUC) (Germany): community non-profit, open source; plaintext plus DoH and DoT.
  • Restena (Luxembourg): the Restena Foundation national research network; DoH and DoT.
  • Digitale Gesellschaft (Switzerland): non-profit with DNSSEC, DoH and DoT (German-language site).
  • dnsforge (Germany): community resolver that filters ads, tracking, and malware; open source.
  • Digitalcourage and Artikel10 (Germany): privacy-focused non-profit resolvers with DoH and DoT (German-language sites).
  • FDN (France): long-running associative ISP with a no-logging, no-censorship open resolver.
  • IIJ Public DNS (Japan): public DoH and DoT resolver from Internet Initiative Japan, a major operator.
  • CNNIC sDNS (China): the Chinese registry's public resolver (the well-known 1.2.4.8); subject to local regulations.
  • Comss.one DNS (Russia): ad-blocking resolver popular in the Russian-speaking community.
  • Shecan, Electro, Begzar, and 403.online (Iran): widely used inside Iran mainly to reach developer and cloud services that block Iranian IP addresses; special-purpose, with limited published policy.
  • **Legacy or discontinued services to avoid:** Oracle Dyn, Level3 (4.2.2.x), Freenom World, dns0.eu (use DNS4EU or NextDNS instead), and Norton ConnectSafe appear in older lists but are legacy, unofficial, or discontinued.
← latest Signal