Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Security-focused DNS can help block connections to known malicious or phishing domains before a device reaches them. It is a useful extra layer—not a replacement for antivirus, browser protections, software updates, a firewall, or a VPN. For a simple free malware filter, consider Cloudflare 1.1.1.1 for Families; for privacy-focused threat blocking, Quad9; for detailed controls, NextDNS; for ads and trackers as well as threats, AdGuard DNS; or, for straightforward home filtering, OpenDNS FamilyShield.

What security-focused DNS can—and cannot—do

DNS, or the Domain Name System, looks up the address associated with a domain name such as example.com. A filtering resolver checks the requested domain against its threat or content categories before answering. Depending on the service, it may refuse to resolve a known malware or phishing domain, or block advertising, tracking, or adult-content domains.

That check happens at the domain level. It can help prevent a connection to a domain already identified as dangerous, but it does not inspect every page, URL, download, or application session. A new phishing domain, a compromised legitimate site, a direct connection to an IP address, or malware already on a device may evade DNS filtering. Treat DNS as one layer in a broader security setup.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some services also support encrypted DNS, including DNS-over-HTTPS (DoH) and DNS-over-TLS (DoT). Encryption protects queries between your device and the resolver from being read directly by observers on that network path. The resolver still receives the queries, and encryption does not make browsing anonymous or hide all destination-related traffic metadata. See Cloudflare’s explanation of DNS encryption.

At a glance

Service Good fit for Filtering focus Trade-off
Cloudflare 1.1.1.1 for Families Simple free malware filtering Known malicious domains; optional adult-content filtering Few customization options
Quad9 Privacy-conscious users wanting threat blocking Malware and phishing domains Limited household controls and customization
NextDNS Users who want detailed policies and profiles Configurable security, privacy, and content lists Free plan has a monthly query limit
AdGuard DNS People seeking ad and tracker filtering too Ads, trackers, malware, phishing; optional family mode Blocking can disrupt sites and apps
OpenDNS FamilyShield / OpenDNS Home Simple home-network or family filtering Threat protection and adult-content categories Less granular than configurable services; assess privacy terms

These are different kinds of services, not a universal performance ranking. DNS speed varies by location, internet provider, routing, cache state, and time; there is no reliable fastest choice for everyone.

1. Cloudflare 1.1.1.1 for Families: the straightforward malware filter

Best for: Someone who wants a free, simple resolver with malware blocking and an optional adult-content filter.

Cloudflare’s regular 1.1.1.1 resolver is not the same as its family-filtering variants. For malware blocking, enter these IPv4 addresses:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
1.1.1.2
1.0.0.2

For malware plus adult-content filtering, use:

1.1.1.3
1.0.0.3

IPv6 addresses and encrypted DNS endpoints are listed in Cloudflare’s setup guide. For DoH, the malware endpoint is https://security.cloudflare-dns.com/dns-query; the family-filtering endpoint is https://family.cloudflare-dns.com/dns-query. DoT uses the matching hostnames security.cloudflare-dns.com and family.cloudflare-dns.com.

The main advantage is ease: basic resolver use does not require an account. Family filtering is category-based, however, not full parental supervision. It cannot enforce screen-time limits or prevent a child from changing networks or using another resolver. Cloudflare’s privacy documentation distinguishes aggregate resolver statistics from identifiable query data, so avoid treating its policy as a blanket “no data” promise; review the current privacy details.

2. Quad9: security-focused resolving with a privacy emphasis

Best for: Users who primarily want known malicious-domain blocking and place weight on the provider’s privacy mission.

Quad9 is a nonprofit DNS operator that says it blocks domains associated with malware, phishing, and other threats. It is a good candidate for a set-and-forget security resolver if you do not need ad blocking, per-device profiles, or a detailed family dashboard. Its published privacy and service explanations are available on Quad9’s site.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Threat blocking depends on domain classification and intelligence sources; no resolver catches every harmful site. Quad9 is also not a detailed parental-control platform. For exact current IPv4/IPv6 addresses and encrypted-DNS setup, follow Quad9’s live service addresses and features documentation rather than copying an address from an old guide.

3. NextDNS: the most configurable option

Best for: Households or technical users who want custom blocklists, allowlists, profiles, and reporting.

NextDNS lets you create configurations for different needs—for example, a stricter profile for a child’s device and a less restrictive one for a work laptop. You can select security and privacy lists, inspect requests to troubleshoot a block, and allow specific domains when a site or app stops working. Setup differs from entering a universal pair of IP addresses: create a configuration, then use the generated device, browser, router, or client instructions.

  1. Create an account and configuration.
  2. Choose security, privacy, or parental-control lists appropriate to your household.
  3. Apply the configuration to each device or to a compatible router/client.
  4. Use the dashboard to confirm queries are reaching the intended configuration.
  5. If a needed service fails, review the blocked domain and allowlist it only if you trust it.

More control also means more ways to block something a site or app needs. NextDNS’s pricing page lists a free plan with 300,000 queries per month; after the quota, queries continue in non-blocking mode according to the page. Paid-plan prices and availability can change, so consult the current pricing page. Logs and analytics are useful for troubleshooting, but users who want minimal visibility should examine the provider’s current privacy and retention terms before enabling them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

4. AdGuard DNS: threats plus ads and trackers

Best for: People who want DNS-level ad and tracker reduction alongside malware and phishing filtering.

AdGuard DNS offers three modes: Default filtering for ads, trackers, malware, and phishing; Family protection, which adds adult-content blocking and SafeSearch enforcement where supported; and Non-filtering, for DNS resolution without content blocking. It supports DNSCrypt, DoH, DoT, and DNS-over-QUIC. Find its current configuration details on the AdGuard DNS service page.

DNS ad blocking is not a complete ad blocker. It cannot reliably remove ads served from the same domain as wanted content, and tracker lists can interfere with login, payments, embedded media, or smart-home apps. If a service breaks, temporarily switch to a less restrictive mode or use the provider’s exception controls. AdGuard DNS is not a VPN: it changes DNS resolution and can encrypt DNS queries, but it does not automatically route all device traffic through a VPN tunnel.

5. OpenDNS FamilyShield or OpenDNS Home: simple household filtering

Best for: Families who want straightforward filtering across devices that use their home router’s DNS settings.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

OpenDNS FamilyShield is preconfigured to block adult content. OpenDNS Home offers more customizable filtering. OpenDNS lists these standard resolver addresses:

208.67.222.222
208.67.220.220

FamilyShield uses:

208.67.222.123
208.67.220.123

Use the OpenDNS setup guide for current instructions and the home product overview for plan details. Router-level filtering is convenient, but it does not cover a phone on cellular data or a device using a VPN, another Wi-Fi network, browser-level DoH, or its own resolver. FamilyShield is also relatively blunt compared with a custom profile service. OpenDNS’s consumer terms state that absolute security or protection against all malware and attacks is not guaranteed; it should not be treated as such.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to choose

  • Want the simplest free malware filter? Start with Cloudflare 1.1.1.1 for Families’ malware-only addresses.
  • Prioritize a privacy-oriented security resolver? Compare Quad9’s current policy and setup details.
  • Need profiles, custom lists, and diagnostics? Choose NextDNS, especially if you are willing to manage exceptions and monitor the free quota.
  • Want DNS-level ad and tracker filtering? Try AdGuard DNS, and be prepared to adjust filtering if sites misbehave.
  • Want basic adult-content filtering across a home router? Consider OpenDNS FamilyShield; use device-level parental controls for stronger supervision.
  • Managing a business? Consumer resolvers are not full secure web gateways. Business services such as Cisco Umbrella or Cloudflare Gateway offer a different administration and policy scope.

Set it up, test it, and know how to undo it

Router setup

Router labels vary by manufacturer and firmware. In the router app or administrator page, look under Internet, WAN, Network, or DNS. Replace automatic or ISP-provided DNS with the selected service’s primary and secondary addresses, save the change, and reconnect devices or restart the router if needed. Router setup is efficient for home devices using that router, but it is not an enforcement guarantee.

Device setup and encrypted DNS

Use device-level setup when you cannot change the router, want a policy on just one device, or need the setting to travel with a laptop. A plain DNS address entered in network settings usually means ordinary DNS unless that operating system, browser, or client is separately configured for an encrypted protocol. Use the provider’s current DoH or DoT instructions for the device. A browser’s own secure-DNS setting, VPN, or security app may override system DNS.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check both IPv4 and IPv6. Changing only IPv4 settings can leave a device querying an ISP-provided IPv6 resolver. Also check browsers and VPNs: a router’s DNS setting may not control their separate resolver choices.

Testing and troubleshooting

  1. Use the provider’s own diagnostic page or test instructions to confirm the device is reaching the expected resolver. Cloudflare publishes category test domains in its setup documentation.
  2. Test only with provider-supplied diagnostic domains, not real malicious sites. Verify malware and family-filter modes separately if you enabled both.
  3. If filtering does not appear to work, check browser DoH, VPN or security software, IPv6 DNS, and whether the device is actually on the configured network.
  4. If a trusted site or app fails, check the provider’s dashboard or allowlist, or temporarily choose a less restrictive mode.
  5. To undo the change, restore Automatic DNS or Obtain DNS server address automatically in the same router or device settings. On Windows, you can then clear the local DNS cache with ipconfig /flushdns.

Common false positives affect payment flows, captchas, streaming, software updates, games, workplace tools, and smart-home devices. If many unrelated services fail, revert first and reapply a less restrictive configuration rather than repeatedly adding exceptions.

What DNS filtering is not

  • Not a complete phishing defense: It may block known phishing domains, but new, compromised, or uncategorized domains can get through.
  • Not antivirus: It does not inspect every file, process, browser exploit, or local infection.
  • Not a full ad blocker: DNS cannot reliably distinguish every unwanted element from wanted content served by the same host.
  • Not anonymity: Encrypted DNS protects the query on its path to the resolver, not from the resolver itself or every other source of traffic metadata.
  • Not foolproof parental control: Cellular data, VPNs, alternate networks, manual settings, and app-specific DNS can bypass a home resolver.

Use DNS filtering alongside updated devices, reputable endpoint protection, browser defenses, strong unique passwords, and multifactor authentication. If a VPN is appropriate for your privacy needs, choose it for its traffic-routing and privacy properties—not as a synonym for DNS filtering.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.