LookMyIPLookMyIP
Blog/Best Free DNS Servers: Google, Cloudflare, Quad9 & OpenDNS Compared
DNS8 min read

Best Free DNS Servers: Google, Cloudflare, Quad9 & OpenDNS Compared

By LookMyIP Editorial

A detailed comparison of the best free public DNS servers including speed, privacy, security features, and which one to choose for your needs.

Why Public DNS Servers Matter

Your DNS server affects every website you visit. It determines how fast domain names are resolved, whether you're protected from known malicious sites, and who can see your browsing activity (at the DNS level).

Most people use their ISP's default DNS without thinking about it. But ISP DNS servers are often slower than public alternatives, may log and sell your query data, and sometimes redirect failed queries to ad-laden search pages.

Switching to a reputable public DNS takes about 2 minutes and can noticeably improve your browsing speed and privacy. You can verify your DNS is working correctly using LookMyIP's DNS Lookup tool.

Cloudflare DNS (1.1.1.1)

Addresses: 1.1.1.1 / 1.0.0.1 (IPv6: 2606:4700:4700::1111 / 2606:4700:4700::1001)

Speed: Consistently the fastest public DNS resolver globally, with average response times under 12ms. Cloudflare operates one of the world's largest CDN networks, which gives their DNS infrastructure a geographic advantage.

Privacy: Industry-leading privacy commitment. Cloudflare pledges not to sell query data or use it for advertising. DNS query logs are purged within 24 hours. Audited annually by KPMG to verify compliance.

Security features: Supports DNS over HTTPS (DoH) and DNS over TLS (DoT) for encrypted queries. No built-in malware blocking on the standard service, but Cloudflare offers "1.1.1.1 for Families" (1.1.1.2 / 1.1.1.3) which blocks malware and optionally adult content.

WARP VPN: Cloudflare offers a free VPN-like service called WARP that works alongside 1.1.1.1, encrypting all your traffic (not just DNS).

Best for: Users who prioritize speed and privacy. The strongest choice for most people.

Google Public DNS (8.8.8.8)

Addresses: 8.8.8.8 / 8.8.4.4 (IPv6: 2001:4860:4860::8888 / 2001:4860:4860::8844)

Speed: Very fast, typically just behind Cloudflare. Google's massive infrastructure ensures low latency from almost anywhere in the world.

Privacy: Google logs query data temporarily (claimed 24-48 hours for full records) and retains anonymized data longer. Google states this data isn't correlated with Google accounts or used for ad targeting, but Google's core business is advertising, so privacy-conscious users may prefer Cloudflare or Quad9.

Security features: Supports DoH and DoT. DNSSEC validation is enabled. No built-in malware or content blocking.

Reliability: Arguably the most reliable DNS service available, backed by Google's global infrastructure. Has been operational since 2009 with a near-perfect uptime record.

Best for: Users who want rock-solid reliability and fast speeds. The most widely used public DNS service in the world.

Quad9 (9.9.9.9)

Addresses: 9.9.9.9 / 149.112.112.112 (IPv6: 2620:fe::fe / 2620:fe::9)

Speed: Slightly slower than Cloudflare and Google, but still faster than most ISP DNS servers. Performance has improved significantly since launch.

Privacy: Operated by the Quad9 Foundation, a Swiss non-profit. Does not log user IP addresses. Subject to Swiss privacy laws (among the strictest in the world). Independently audited.

Security features: The standout feature — Quad9 blocks known malicious domains using threat intelligence from over 25 cybersecurity partners (including IBM X-Force, Proofpoint, and F-Secure). When you try to visit a known phishing or malware domain, Quad9 returns an empty response instead of the malicious IP.

Unfiltered option: 9.9.9.10 provides Quad9's DNS without malware blocking, for users who want the privacy without the filtering.

Best for: Users who want automatic protection against malicious domains. The best security-focused DNS option.

Comparison Summary

FeatureCloudflare (1.1.1.1)Google (8.8.8.8)Quad9 (9.9.9.9)OpenDNS (208.67.222.222)
SpeedFastestVery fastFastFast
PrivacyExcellent (audited)Good (Google data practices)Excellent (Swiss non-profit)Moderate (owned by Cisco)
Malware blockingVia 1.1.1.2 variantNoYes (default)Via FamilyShield variant
Content filteringVia 1.1.1.3 variantNoNoVia dashboard
DoH/DoTYesYesYesYes
DNSSECYesYesYesYes
Uptime99.99%+99.99%+99.99%+99.99%+
Best forSpeed + privacyReliabilitySecurityCustom filtering

Bottom line recommendation:

  • For most people: Cloudflare 1.1.1.1 — fastest, excellent privacy
  • For security-first: Quad9 9.9.9.9 — automatic malware blocking
  • For families: Cloudflare 1.1.1.3 or OpenDNS FamilyShield — content filtering
  • For maximum reliability: Google 8.8.8.8 — longest track record

You can change your DNS server at the router level (protects all devices) or per device. See our guide on How to Change Your DNS Server for step-by-step instructions.

Beyond the Big Three

Cloudflare, Google and Quad9 dominate the conversation, but several other resolvers are better fits for specific needs.

AdGuard DNS — `94.140.14.14` / `94.140.15.15`. Blocks advertising and tracking domains network-wide, which covers devices that cannot run a content blocker: smart TVs, consoles, IoT hardware. A separate family-protection pair adds adult content filtering. The trade-off is inherent to DNS blocking — you get one global policy with no per-site exceptions, and occasional false positives break a page in ways that are hard to diagnose unless you remember DNS filtering is on.

NextDNS — configurable endpoints. Effectively a hosted Pi-hole with per-device profiles, custom blocklists, allowlists, logging you control, and analytics. Free up to 300,000 queries a month, then inexpensive. The best choice if you want filtering with granular control rather than a fixed policy, and the logging is genuinely useful for finding which device is talking to what.

Mullvad DNS — `194.242.2.2`. From the VPN provider, with an unusually strong privacy posture: no logging, no accounts, DoH and DoT only. Variants offer ad, tracker and malware blocking. Attractive if the resolver operator's incentives matter to you — Mullvad's business is privacy rather than advertising.

OpenDNS — `208.67.222.222` / `208.67.220.220`. Now part of Cisco. Long-established, with category-based content filtering configurable through a free account, which makes it a common choice for schools and small businesses that need policy rather than just resolution.

Control D — configurable. Fine-grained per-service rules, including the ability to redirect specific services through different exit locations.

Your ISP's resolver deserves one honest mention: it is usually the closest to you physically and therefore often the fastest, and it sends EDNS Client Subnet so CDN routing is accurate. The reasons to leave are privacy, reliability, and the habit some ISPs have of redirecting NXDOMAIN responses to advertising pages.

Measuring Speed Yourself

Published benchmarks measure someone else's network. The only number that matters is the one from where you actually sit, and measuring it takes two minutes.

Single lookup, uncached:

dig @1.1.1.1 $(openssl rand -hex 6).example.com +stats | grep 'Query time'

The random subdomain guarantees a cache miss, which measures the resolver's full recursion path rather than a cache hit.

Compare several resolvers over repeated queries:

for r in 1.1.1.1 8.8.8.8 9.9.9.9 208.67.222.222; do
  total=0
  for i in $(seq 1 10); do
    t=$(dig @$r $(openssl rand -hex 6).example.com +stats \
        | awk '/Query time/{print $4}')
    total=$((total + t))
  done
  echo "$r: $((total / 10)) ms average"
done

Run this at different times of day. A resolver that is fastest at 3am may not be fastest at peak.

Interpreting the result. Differences under about 10ms are irrelevant — they are lost in the noise of everything else a page load does. A resolver 50ms slower than another is worth switching away from. Cached responses from any resolver will be 1–5ms, so if all your numbers are tiny, your random-subdomain trick is not working.

What DNS speed does not affect. Throughput, video quality, download speed, gaming latency during play. It affects the time to first byte on the first request to each new domain, and nothing else. A page pulling resources from twelve domains pays the cost twelve times on first visit and zero times thereafter.

This is worth stating plainly because DNS benchmarking attracts far more attention than the effect size justifies. Choose a resolver on privacy policy, filtering behaviour and reliability; treat speed as a tiebreaker unless one option is dramatically worse.

Running Your Own Resolver

For a home network, running your own resolver is a genuine alternative to picking a public one, and it changes the privacy calculation entirely.

Pi-hole is the well-known option: a DNS server that blocks advertising and tracking domains at the network level, with a web interface showing exactly what every device is querying. It runs comfortably on a Raspberry Pi or in a container. What most Pi-hole setups get wrong is the upstream — by default it forwards to a public resolver, so you have added filtering and logging while your queries still go to Cloudflare or Google.

Pi-hole plus Unbound closes that gap. Unbound performs full recursion itself, querying the root servers, then the TLD servers, then the authoritative servers, and caching the results locally. No single upstream ever sees your complete query history. The configuration is well documented and the resource requirements are trivial.

AdGuard Home is a single-binary alternative that combines both roles, with built-in DoH and DoT support both upstream and for clients. For most people it is the easier path to the same outcome.

What you gain: no third party sees your queries, complete visibility into what every device on your network is doing (which is frequently alarming the first time), network-wide filtering including devices that cannot be configured, and a local cache that makes repeat lookups instant.

What you take on: the resolver becomes a single point of failure for your entire network, so configure a secondary and make sure DHCP advertises it. Recursive resolution from cold is slower than a large shared cache for the first lookup of any domain. And DNS filtering breaks things occasionally — when a device misbehaves, "is it Pi-hole?" needs to be an early question rather than a late one.

The honest recommendation: if you enjoy running infrastructure, Pi-hole with Unbound is the best privacy outcome available. If you do not, NextDNS gets you most of the benefit with none of the maintenance.

Frequently Asked Questions

Which resolver is best for privacy?

Running your own with full recursion, because no third party sees your queries at all. Among public options, Mullvad and Quad9 have the strongest positions — both are non-profit or privacy-focused rather than advertising-funded. Cloudflare's no-logging claim has been independently audited, which is more than most can say. Google's is operated by an advertising company, though it does commit to not using resolver data for ad targeting.

Should I use different primary and secondary providers?

No. There is no guarantee which one is queried, so you get the weaker provider's privacy and filtering properties some fraction of the time. Use both addresses from one operator.

Does Quad9's malware blocking actually work?

It blocks domains on threat intelligence feeds, which catches a meaningful share of malware command-and-control and phishing before a connection is made. It is a useful layer, not a replacement for endpoint protection, and it is reactive — new domains are not on any feed yet.

Will a filtering resolver break websites?

Occasionally. Ad and tracker blocking sometimes catches a domain a site genuinely depends on, typically for analytics-gated content, embedded video or payment flows. AdGuard Home and NextDNS support allowlists; the fixed public endpoints do not. This is the main argument for a self-hosted or account-based option over a fixed filtering address.

Is 1.1.1.1 or 8.8.8.8 faster?

It depends entirely on where you are, and the difference is usually small enough not to matter. Measure it with the loop above rather than trusting a benchmark from another continent.

Try It Yourself

Use LookMyIP's free tools to look up IP addresses, check DNS records, verify SSL certificates, and more.