Public recursive name server
A public recursive name server is a name server service that networked computers may use to query the Domain Name System, the decentralized Internet naming system, in place of name servers operated by the local Internet service provider to which the devices are connected. Reasons for using these services include:
- speed, compared to using ISP DNS services
- filtering
- reporting
- avoiding censorship
- redundancy
- access to unofficial alternative top level domains not found in the official DNS root zone
- temporary unavailability of the ISP's name server
Public DNS resolvers are operated either by commercial companies, offering their service for free use to the public, or by private enthusiasts to help spread new technologies and support non-profit communities.
Notable public DNS service operators
| Provider | Privacy policy | DNS over UDP/TCP (Do53) | DNSSEC | DNS over TLS (DoT) | DNS over HTTPS (DoH) | DNS over QUIC (DoQ) | EDNS Padding | DNSCrypt | Hostname | IPv4 addresses | IPv6 addresses | Filters | Remarks |
| AdGuard | rowspan="3" ! | rowspan="3" ! | rowspan="3" ! | rowspan="3" ! | rowspan="3" ! | rowspan="3" ! | rowspan="3" ! | rowspan="3" ! | dns.adguard-dns.com | Default: ads and trackers | |||
| AdGuard | family.adguard-dns.com | Family: ads, trackers, and adult content | - | - | - | - | - | - | - | - | |||
| AdGuard | unfiltered.adguard-dns.com | - | - | - | - | - | - | - | - | - | |||
| Alibaba | ! | ! | ! | ! | ! | dns.alidns.com | Chinese regulations | ||||||
| Cloudflare | rowspan="4" ! | rowspan="4" ! | rowspan="4" ! | rowspan="4" ! | rowspan="4" ! | rowspan="4" ! | rowspan="4" ! | rowspan="4" ! | one.one.one.one 1dot1dot1dot1.cloudflare-dns.com | - | |||
| Cloudflare | security.cloudflare-dns.com | Malware, Phishing | - | - | - | - | - | - | - | - | |||
| Cloudflare | family.cloudflare-dns.com | Malware, Phishing, Adult content | - | - | - | - | - | - | - | - | |||
| Cloudflare | dns64.cloudflare-dns.com | - | Intended to be IPv6-only. See NAT64 and DNS64. | - | - | - | - | - | - | - | - | ||
| DNS4EU | rowspan="5" | rowspan="5" | rowspan="5" | rowspan="5" | rowspan="5" | rowspan="5" | rowspan="5" | protective.joindns4.eu | Malware, phishing | Developed for EU citizens | |||
| DNS4EU | child-noads.joindns4.eu | Malware, phishing, adult content, ads | - | - | - | - | - | - | - | Developed for EU citizens | |||
| DNS4EU | child.joindns4.eu | Malware, phishing, adult content | - | - | - | - | - | - | - | Developed for EU citizens | |||
| DNS4EU | noads.joindns4.eu | Malware, phishing, ads | - | - | - | - | - | - | - | Developed for EU citizens | |||
| DNS4EU | unfiltered.joindns4.eu | - | - | - | - | - | - | - | - | Developed for EU citizens | |||
| rowspan="2" ! | rowspan="2" ! | rowspan="2" ! | rowspan="2" ! | rowspan="2" ! | rowspan="2" ! | rowspan="2" ! | rowspan="2" ! | dns.google | - | ||||
| dns64.dns.google | - | Intended for networks with NAT64 gateway. | - | - | - | - | - | - | - | - | |||
| Gcore | ! | ! | ! | ! | ! | ! | ! | ! | - | ||||
| Mullvad | rowspan="5" | rowspan="5" | rowspan="5" | rowspan="5" | rowspan="5" | rowspan="5" | rowspan="5" | rowspan="5" | dns.mullvad.net | - | Can be used without its VPN service | ||
| Mullvad | adblock.dns.mullvad.net | Ads, and trackers | - | - | - | - | - | - | - | - | Can be used without its VPN service | ||
| Mullvad | base.dns.mullvad.net | Ads, trackers, and malware | - | - | - | - | - | - | - | - | Can be used without its VPN service | ||
| Mullvad | extended.dns.mullvad.net | Ads, trackers, malware, and social media | - | - | - | - | - | - | - | - | Can be used without its VPN service | ||
| Mullvad | all.dns.mullvad.net | Ads, trackers, malware, social media, gambling and adult content | - | - | - | - | - | - | - | - | Can be used without its VPN service | ||
| Vercara | rowspan="6" ! | rowspan="6" ! | rowspan="6" ! | rowspan="6" ! | rowspan="6" ! | rowspan="6" ! | rowspan="6" ! | rowspan="6" ! | rowspan="6" | 64.6.64.6 64.6.65.6 | 2620:74:1b::1:1 2620:74:1c::2:2 | - | Verisign transferred its public DNS to Neustar. |
| Vercara | - | - | - | - | - | - | - | - | - | - | |||
| Vercara | Malware, ransomware, spyware, phishing | - | - | - | - | - | - | - | - | - | |||
| Vercara | Low security + gambling, pornography, violence, hate | - | - | - | - | - | - | - | - | - | |||
| Vercara | Medium security + gaming, adult, drugs, alcohol, anonymous proxies | - | - | - | - | - | - | - | - | - | |||
| Vercara | - | Will not redirect non-existent domains to a landing page. | - | - | - | - | - | - | - | - | - | ||
| Cisco Umbrella | rowspan="3" ! | rowspan="3" ! | rowspan="3" ! | rowspan="3" ! | rowspan="3" ! | rowspan="3" ! | rowspan="3" ! | rowspan="3" ! | dns.opendns.com dns.umbrella.com | Basic Security filtering + user defined policies | |||
| Cisco Umbrella | familyshield.opendns.com | FamilyShield: adult content | - | - | - | - | - | - | - | - | |||
| Cisco Umbrella | sandbox.opendns.com | - | Sandbox addresses that provide no filtering. | - | - | - | - | - | - | - | - | ||
| Oracle | resolver1.dyndnsinternetguide.com resolver2.dyndnsinternetguide.com rdns.dynect.net | - | |||||||||||
| Quad9 | rowspan="3" ! | rowspan="3" ! | rowspan="3" ! | rowspan="3" ! | rowspan="3" ! | rowspan="3" ! | rowspan="3" ! | dns.quad9.net | Phishing, malware, and exploit kit domains | ||||
| Quad9 | dns11.quad9.net | Phishing, malware, and exploit kit domains | Passes EDNS Client Subnet. | - | - | - | - | - | - | - | |||
| Quad9 | dns10.quad9.net | - | - | - | - | - | - | - | - | ||||
| Tencent | ! | ! | ! | ! | ! | ! | dns.pub | Chinese regulations | |||||
| Wikimedia | wikimedia-dns.org | - | |||||||||||
| Yandex | rowspan="3" ! | rowspan="3" ! | rowspan="3" ! | rowspan="3" ! | rowspan="3" ! | rowspan="3" ! | rowspan="3" ! | rowspan="3" ! | common.dot.dns.yandex.net | - | |||
| Yandex | safe.dot.dns.yandex.net | Safe: fraudulent / infected / bot sites | - | - | - | - | - | - | - | - | |||
| Yandex | family.dot.dns.yandex.net | Family: fraudulent / infected / bot / adult sites | - | - | - | - | - | - | - | - |