DNS is the internet's phone book. When you type a site name, your device asks a DNS server: what is its IP address? That answer is used to open the connection.

By default, that question is answered by your ISP's servers. Switching to another provider is advice that surfaces for all sorts of complaints, from slow internet to sites that will not open. Some of the claims have basis, some do not.

What happens when you open a site

The sequence runs roughly like this:

  1. The device checks its local cache. If the address was looked up recently, the process stops here.
  2. If not, the question goes to the configured DNS server, the ISP's default, or one you chose.
  3. That server answers, or asks a more authoritative server in turn.
  4. The device receives the IP address and starts opening a connection to it.

The whole process usually takes 10–80 milliseconds, and happens only once per domain until the cache expires. This matters for understanding the limits of the benefit.

On speed

The claim that "changing DNS makes the internet fly" needs putting in proportion. What changes is the address lookup time, not the data transfer rate.

ActivityEffect of DNS
Opening a site with many third-party domainsSlightly noticeable
Moving between new sitesSlightly noticeable
Video streamingPractically none
Downloading large filesPractically none
Video callsPractically none

A news page can load resources from twenty different domains. Saving 30 milliseconds per domain is genuinely noticeable. But if your complaint is stuttering video, DNS is not where to look, see the guide to slow Wi-Fi instead.

One exception: if your ISP's DNS servers are having trouble, the symptom is sites taking an age to open then suddenly appearing, or "server not found" messages that disappear on retry. In that case changing DNS genuinely helps.

On privacy

This is the most misunderstood part.

With ordinary DNS, queries are sent unencrypted. Anyone on the path, including your ISP and the Wi-Fi operator whose network you are using, can read them. Changing the DNS server does not alter this, the queries remain open, only their destination moves.

What does alter it is DNS over HTTPS (DoH) or DNS over TLS (DoT). Both wrap the query in an encrypted connection.

But there is a limit. Once the IP address is obtained, your device still opens a connection to it. The ISP sees that destination IP address. For many sites, the IP address alone is enough to reveal which site was opened.

So DoH hides the question, not the destination. If what you want is to hide where a connection is going from the network operator, a VPN is what answers that need.

Content filtering

Some DNS providers offer versions that block malicious domains, ads, or adult content. This is a real benefit and easy to apply to a whole household at once through the router's settings.

ProviderAddressNotes
Cloudflare1.1.1.1No filtering
Cloudflare Family1.1.1.3Blocks malware and adult content
Google8.8.8.8No filtering
Quad99.9.9.9Blocks malicious domains
AdGuard DNS94.140.14.14Blocks ads and trackers

DNS-based filtering works at the domain name level, so it cannot block ads served from the same domain as the content. Effectiveness varies.

On blocked sites

Changing DNS sometimes opens sites that were previously inaccessible. This works when the blocking is done the simplest way, by having the provider's DNS server answer with the address of a notice page.

Newer blocking methods no longer depend on DNS. If the filtering reads the domain name inside the connection or blocks the destination IP address, changing DNS makes no difference.

It is also worth noting that opening access to officially blocked services carries its own consequences. This article explains how the mechanism works; it does not recommend using it for any particular purpose.

How to change it

On the router, applies to the whole house

Sign into the admin page, find the WAN or Internet menu, then fill in the "Primary DNS" and "Secondary DNS" fields. Every connected device follows, except those with their own setting.

On Windows

Settings › Network & Internet › select the adapter › Edit DNS server assignment › Manual › enter the addresses. There is an "Encrypted only" option to enable DoH.

On Android

Settings › Network & internet › Private DNS › enter a hostname, for example one.one.one.one. This setting uses DoT and applies on every network, including mobile data.

On iOS and macOS

For a single network: Settings › Wi-Fi › the (i) icon › Configure DNS › Manual. To apply it system-wide, providers usually supply a configuration profile that can be installed.

In the browser

Chrome and Firefox have their own DoH settings that ignore the system setting. This can be confusing: filtering you set up on the router then does not apply to browser traffic. If you rely on router-level filtering, turn DoH off in the browser.

In conclusion

Changing DNS is a small change with a benefit that is also small but real: address lookups get slightly faster, and filtering of malicious domains can be added for the whole house at once.

What it does not do: speed up downloads, hide your activity from your ISP, or replace a VPN. Those are the claims that leave people disappointed after trying it.

Frequently asked questions

Does changing DNS make the internet faster?

The effect exists but is small, and only at the address lookup stage. The saving is usually tens of milliseconds per new domain and is not felt in downloads or streaming. If your internet is slow, DNS is most likely not the cause.

Does public DNS hide my activity from my ISP?

Not entirely. With ordinary DNS, the ISP can still read the queries because they are unencrypted. With DNS over HTTPS the query contents are hidden, but the ISP still sees the destination IP addresses you connect to. To hide where a connection is going, what you need is a VPN.

Is it safe to use free third-party DNS?

It depends on the provider. You are moving trust from your ISP to another company, which now sees every domain you open. Choose a provider that publishes its data retention policy clearly and has it audited externally.

Why do some sites still not open after changing DNS?

Because the blocking is not done at the DNS layer. If filtering works by inspecting the domain name inside the connection or by blocking destination IP addresses, changing DNS makes no difference.