DNS Server Lists

ProviderPrimary IPv4Secondary IPv4IPv6 (example)Country (HQ ISO)Primary RegionCoverage Notes (countries/anycast)DoH Endpoint (https URL)DoT Hostname (port 853)StatusFilteringLogging/PrivacyNotesLast Verified (UTC ISO8601)
Google Public DNS8.8.8.88.8.4.42001:4860:4860::8888, 2001:4860:4860::8844USGlobalAnycast; POPs on all continentshttps://dns.google/dns-querydns.googleActiveNoneSee Google Public DNS privacy docsDNSSEC; high performance
Cloudflare DNS (Standard)1.1.1.11.0.0.12606:4700:4700::1111, 2606:4700:4700::1001USGlobalAnycast; broad worldwide footprinthttps://cloudflare-dns.com/dns-query1dot1dot1dot1.cloudflare-dns.comActiveNonePrivacy-focused; minimal logs per policyDoH/DoT; optional DoQ via apps
Cloudflare DNS (Malware)1.1.1.21.0.0.22606:4700:4700::1112, 2606:4700:4700::1002USGlobalAnycasthttps://security.cloudflare-dns.com/dns-querysecurity.cloudflare-dns.comActiveMalwarePer Cloudflare policyBlocks known malicious domains
Cloudflare DNS (Family)1.1.1.31.0.0.32606:4700:4700::1113, 2606:4700:4700::1003USGlobalAnycasthttps://family.cloudflare-dns.com/dns-queryfamily.cloudflare-dns.comActiveMalware+AdultPer Cloudflare policyFamily filter
Quad9 (Secure)9.9.9.9149.112.112.1122620:fe::feCHGlobalAnycast clusters in many countrieshttps://dns.quad9.net/dns-querydns.quad9.netActiveMalware/PhishingNon-profit; privacy-focusedSwiss foundation; DNSSEC validation
OpenDNS Home208.67.222.222208.67.220.2202620:119:35::35, 2620:119:53::53USGlobalAnycast via Cisco Umbrella networkActiveOptional (acct)See OpenDNS/Umbrella privacyConsumer OpenDNS; encrypted via Umbrella
OpenDNS FamilyShield208.67.222.123208.67.220.123USGlobalAnycast via Cisco Umbrella networkActiveAdultSee OpenDNS/Umbrella privacyPreconfigured adult-content blocking
CleanBrowsing (Family)185.228.168.168185.228.169.168USGlobalAnycast; multiple profileshttps://doh.cleanbrowsing.org/doh/family-filterfamily-filter-dns.cleanbrowsing.orgActiveAdult+Some malwareProvider: no IP logs for DoH/DoTFamily filter
CleanBrowsing (Adult Filter)185.228.168.10185.228.169.11USGlobalAnycasthttps://doh.cleanbrowsing.org/doh/adult-filteradult-filter-dns.cleanbrowsing.orgActiveAdultProvider policyBlocks adult domains
CleanBrowsing (Security)185.228.168.9185.228.169.9USGlobalAnycasthttps://doh.cleanbrowsing.org/doh/security-filtersecurity-filter-dns.cleanbrowsing.orgActiveMalware/PhishingProvider policySecurity-focused blocking
AdGuard DNS (Default)94.140.14.1494.140.15.152a10:50c0::ad1:ff, 2a10:50c0::ad2:ffCYGlobalAnycasthttps://dns.adguard-dns.com/dns-querydns.adguard-dns.comActiveAds/Tracking/MalwarePer AdGuard policyAlso supports DoQ
AdGuard DNS (Family)94.140.14.1594.140.15.162a10:50c0::bad1:ff, 2a10:50c0::bad2:ffCYGlobalAnycasthttps://family.adguard-dns.com/dns-queryfamily.adguard-dns.comActiveAdult + Ads/TrackingPer AdGuard policyFamily filter
AdGuard DNS (Non-filtering)94.140.14.14094.140.14.141CYGlobalAnycasthttps://unfiltered.adguard-dns.com/dns-queryunfiltered.adguard-dns.comActiveNonePer AdGuard policyNeutral resolver
ControlD (Free - Unfiltered)76.76.2.1176.76.10.112606:1a40::11, 2606:1a40:1::11CAGlobalAnycasthttps://freedns.controld.com/dns-querydot.freedns.controld.comActiveConfigurable (paid)Provider policyFree unfiltered endpoints
Vercara UltraDNS Public156.154.70.1156.154.71.12610:a1:1018::1, 2610:a1:1019::1USGlobalAnycast on UltraDNS networkActiveNoneProvider policyPublic resolvers from UltraDNS
Gcore Public DNS95.85.95.852.56.220.22a03:90c0:999d::1, 2a03:90c0:9992::1LUGlobalAnycast; strong EU/US coverageActiveNoneProvider policyEdge network with many POPs
Hurricane Electric (ordns.he.net)74.82.42.422001:470:20::2USGlobalAnycast; strong IPv6 presenceActiveNoneUnknownGeneral-purpose resolver
Yandex.DNS (Standard)77.88.8.877.88.8.12a02:6b8::feed:0ffRURussia/CISAnycast within region; some global POPsActiveNoneSubject to regional policyUnfiltered
Yandex.DNS (Secure)77.88.8.8877.88.8.22a02:6b8::feed:badRURussia/CISAnycast within regionActiveMalwareSubject to regional policySecurity filter
Yandex.DNS (Family)77.88.8.777.88.8.32a02:6b8:0:1::feed:badRURussia/CISAnycast within regionActiveAdultSubject to regional policyFamily filter
AliDNS (Alibaba)223.5.5.5223.6.6.62400:3200::1, 2400:3200:baba::1CNAsia (Global Anycast)China nationwide; global POPshttps://dns.alidns.com/dns-querydns.alidns.comActiveNoneProvider policyHTTPDNS also available
114DNS (China)114.114.114.114114.114.115.115CNChinaNationwide anycastActiveUnknownUnknownWidely used in mainland China
Baidu Public DNS180.76.76.76CNChinaAnycast within CNActiveUnknownUnknownOperated by Baidu
Quad101 (TWNIC/Taiwan)101.101.101.101101.102.103.1042001:de4::101, 2001:de4::102TWAsiaAnycast with global presenceActiveNonePrivacy-centric missionRun by TWNIC
DNS.Watch84.200.69.8084.200.70.40DEEurope (Global)Anycast; Germany-basedActiveNoneNo logging (per policy)Neutral resolver
UncensoredDNS (Censurfridns)91.239.100.10089.233.43.71DKEurope (Global)Anycast/single-homed mixhttps://unicast.censurfridns.dk/dns-queryActiveNoneNo logging (per policy)Operated by Thomas R.
Digitale Gesellschaft (CH)185.95.218.42185.95.218.432a05:fc84::42, 2a05:fc84::43CHEuropeSwitzerland; privacy NGOhttps://dns.digitale-gesellschaft.ch/dns-querydns.digitale-gesellschaft.chActiveNonePrivacy-firstDNSSEC-validating resolvers
Foundation for Applied Privacy (AT)ATEuropeAustria; privacy orghttps://doh.applied-privacy.net/querydot1.applied-privacy.netActiveNonePrivacy-firstDoH/DoT endpoints only
FDN (French Data Network)80.67.169.4080.67.169.122001:910:800::40, 2001:910:800::12FREuropeFrance; community ISP/NGOActiveNonePer FDN policyNeutral resolver
Mullvad DNS194.242.2.22a07:a8c0::SEGlobal (EU-based)Anycast and regional ingresshttps://doh.mullvad.net/dns-querydot.mullvad.netActiveNoneNo activity logs (per policy)Works best with Mullvad apps/WG
DNS.SB (public-a)185.222.222.2222a09::SCGlobalAnycasthttps://doh.dns.sb/dns-queryActiveNoneNo logging (per policy)DNSSEC validation
DNS.SB (public-b)45.11.45.112a11::SCGlobalAnycasthttps://doh.dns.sb/dns-queryActiveNoneNo logging (per policy)DNSSEC validation
Comodo Secure DNS8.26.56.268.20.247.20USGlobalAnycastActiveSecurityProvider policySecurity-focused filtering
CIRA Canadian Shield (Private)149.112.121.10149.112.122.102620:10A:80BB::10, 2620:10A:80BC::10CACanada (Global Anycast)Anycast with Canadian focushttps://private.canadianshield.cira.ca/dns-queryprivate.canadianshield.cira.caActiveNonePrivacy-firstAlso has Protected and Family profiles
CIRA Canadian Shield (Protected)149.112.121.20149.112.122.202620:10A:80BB::20, 2620:10A:80BC::20CACanadaAnycast with Canadian focushttps://protected.canadianshield.cira.ca/dns-queryprotected.canadianshield.cira.caActiveMalwarePrivacy-firstMalware blocking
CIRA Canadian Shield (Family)149.112.121.30149.112.122.302620:10A:80BB::30, 2620:10A:80BC::30CACanadaAnycast with Canadian focushttps://family.canadianshield.cira.ca/dns-queryfamily.canadianshield.cira.caActiveMalware+AdultPrivacy-firstFamily filter
DNSPod (Tencent)119.29.29.29CNAsiaChina nationwide; some global POPsActiveNoneProvider policyPublic recursive resolver
Verisign Public DNS (retired)64.6.64.664.6.65.62620:74:1b::1:1, 2620:74:1c::2:2USGlobalAnycast (service retired)DiscontinuedNoneRetired Oct 2025Historical reference only
Norton ConnectSafe (retired)199.85.126.10199.85.127.10USGlobalAnycast (service retired)DiscontinuedMalware/Adult (legacy)RetiredHistorical reference only
Level3/CenturyLink (legacy)4.2.2.14.2.2.2USGlobal/USLegacy public resolvers; may still answerLegacy/UnmanagedNoneUnclear policyUse with caution; not officially public now
Freenom World (uncertain)80.80.80.8080.80.81.81NLGlobal/EuropeService status uncertainUncertainNoneUnclear statusVerify before use

Public DNS Resolver Dataset – Disclaimer & Notes

Purpose

This dataset is intended for educational, research, and network diagnostic use only.
It lists publicly accessible DNS resolvers gathered from verified sources, vendor documentation, and community-maintained lists. It is not a guarantee of performance, uptime, or privacy.

Anycast & Geography

  • Many resolvers listed are anycast — a single IP served from multiple global points of presence.
    The “region” and “country” columns reflect the provider’s headquarters or registered ASN, not the physical server location.

  • Actual response latency and jurisdiction may vary depending on your location and routing policy.

Security & Privacy

  • Encryption: Some resolvers support DNS over HTTPS (DoH), DNS over TLS (DoT), or DNS over QUIC (DoQ). Where these are listed, endpoints were verified from public documentation.

  • Privacy: Inclusion in this list does not mean a provider offers private or anonymous service. Review each provider’s published privacy policy before using in production or compliance-bound environments (HIPAA, PCI, CJIS, etc.).

  • Logging: Some providers log query metadata for debugging, analytics, or abuse prevention.

  • Verification: Always confirm endpoints directly from the official provider documentation or security whitepaper.

Operational & Filtering Notes

  • Filtered resolvers (e.g., Family, Security, or Malware variants) intentionally block certain domains.
    This may break SaaS applications, update services, or authentication flows. Test critical systems before deployment.

  • Legacy or retired services (e.g., Verisign Public DNS, Norton ConnectSafe, Level3) are included for historical awareness only and should not be used in production.

  • ISP or national resolvers (e.g., 114DNS, AliDNS) may enforce regional filtering based on local law.

Verification & Maintenance

Each entry includes a Last Verified (UTC ISO8601) column.
To maintain your own copy:

  1. Run automated reachability checks (dig @IP example.com +short) on UDP/53 and TCP/53.

  2. For encrypted endpoints, test with curl (DoH) or openssl s_client (DoT).

  3. Replace or flag any non-responsive resolvers.

  4. Update timestamps after each verification run.

It’s recommended to revalidate at least once every 90 days or before major DNS changes.

Legal Disclaimer

  • This dataset is provided “as-is” without warranty of any kind, express or implied.

  • Neither the compiler nor hosting site is responsible for misuse, damage, or data interception resulting from using these endpoints.

  • Always comply with local regulations and network security policies before routing DNS through external resolvers.

Suggested Safe Defaults

If you’re building tutorials, lab guides, or plugin defaults:

  • Use Quad9 (9.9.9.9) or Cloudflare (1.1.1.1) for neutral, privacy-conscious global coverage.

  • For filtering: AdGuard Family or CleanBrowsing Family.

  • For privacy-first research setups: Mullvad DNS, Applied Privacy, or Digitale Gesellschaft.