Type something to search...
Cloudflare DNS vs Google Public DNS vs Quad9: Which Should You Use?

Cloudflare DNS vs Google Public DNS vs Quad9: Which Should You Use?

Cloudflare's 1.1.1.1, Google Public DNS at 8.8.8.8, and Quad9 at 9.9.9.9 are the three public resolvers most people consider when they decide to stop using their ISP's default. All three are free, fast, global, and support encrypted DNS, so on the surface the choice looks arbitrary. The real differences are in what each one does with your queries, whether it filters malicious domains, and how it treats the location data that CDNs use to pick a nearby server. If you are not yet sure whether switching away from your ISP is worthwhile, read is your ISP's default DNS server slowing you down first.

This article compares the three on the things that are well documented — addresses, filtering variants, privacy commitments, DNSSEC, encrypted transport, and EDNS Client Subnet — and then shows you how to benchmark them from your own network, because the speed result that matters is yours, not anyone else's.

The Short Version

CloudflareGoogle Public DNSQuad9
Primary IPv41.1.1.1, 1.0.0.18.8.8.8, 8.8.4.49.9.9.9, 149.112.112.112
Primary IPv62606:4700:4700::1111, 2606:4700:4700::10012001:4860:4860::8888, 2001:4860:4860::88442620:fe::fe, 2620:fe::9
Malware blocking on main addressNoNoYes
Filtering variants1.1.1.2 (malware), 1.1.1.3 (malware + adult)None9.9.9.10 (no blocking), 9.9.9.11 (blocking + ECS)
DNSSEC validationYesYesYes (not on 9.9.9.10)
DNS over HTTPShttps://cloudflare-dns.com/dns-queryhttps://dns.google/dns-queryhttps://dns.quad9.net/dns-query
DNS over TLS hostnameone.one.one.onedns.googledns.quad9.net
EDNS Client SubnetNot sentSent (truncated)Not sent on main address
OperatorCommercial (Cloudflare)Commercial (Google)Non-profit foundation based in Switzerland

The rest of the article explains what each row means in practice.

Cloudflare 1.1.1.1

Cloudflare launched 1.1.1.1 in 2018 with privacy as its headline feature. Its public commitments are that it does not sell user data or use it for ad targeting, does not write the querying IP address to disk, and deletes its limited transaction logs within 24 hours. The resolver has been independently audited against those commitments.

Cloudflare offers three tiers on different addresses:

  • 1.1.1.1 / 1.0.0.1 — no filtering.
  • 1.1.1.2 / 1.0.0.2 — blocks known malware domains ("1.1.1.1 for Families" security tier). IPv6: 2606:4700:4700::1112 and 2606:4700:4700::1002.
  • 1.1.1.3 / 1.0.0.3 — blocks malware and adult content. IPv6: 2606:4700:4700::1113 and 2606:4700:4700::1003.

The filtering tiers have their own DoH endpoints, https://security.cloudflare-dns.com/dns-query and https://family.cloudflare-dns.com/dns-query. Cloudflare does not send EDNS Client Subnet to authoritative servers, which is a privacy benefit but occasionally means a CDN picks an edge server based on Cloudflare's location rather than yours. Because Cloudflare's resolver runs on the same large anycast network as its CDN, you are usually close to a node.

You can confirm you are actually using it by visiting https://1.1.1.1/help, which reports whether your queries reach Cloudflare and over which protocol.

Google Public DNS 8.8.8.8

Google Public DNS has been running since 2009 and is probably the most widely configured public resolver in the world, partly because many devices and apps use it as a hardcoded fallback.

Google's privacy policy for the service says it keeps temporary logs that include the full IP address for a short period (it states 24 to 48 hours) for debugging and abuse protection, and permanent logs that drop the IP address and retain only coarse location information such as city or metro area. It also states that it does not correlate this data with other Google account information.

Notable characteristics:

  • No filtering. Google returns what the authoritative servers say. There is no malware-blocking variant.
  • EDNS Client Subnet (ECS). Google forwards a truncated portion of your IP address to authoritative servers that support it, so CDNs can choose an edge close to you. This can improve CDN routing, at the cost of revealing your approximate network location to the authoritative server.
  • Strict standards behaviour. Google validates DNSSEC and returns SERVFAIL for domains with broken signatures.
  • A JSON API. In addition to standard DoH, https://dns.google/resolve?name=example.com&type=A returns answers as JSON, which is handy for scripts and debugging.

Quad9 9.9.9.9

Quad9 is run by a non-profit foundation headquartered in Switzerland, and its main selling point is security filtering combined with privacy. Its primary address blocks domains that appear on threat intelligence feeds from a range of security partners, so phishing and malware domains return a blocked response instead of an IP address.

Quad9 states that it does not log or store users' IP addresses. Moving its legal home to Switzerland in 2021 placed the service under Swiss data protection law.

Quad9 offers three main services:

ServiceIPv4IPv6BlockingDNSSECECS
Recommended9.9.9.9, 149.112.112.1122620:fe::fe, 2620:fe::9YesYesNo
Unsecured9.9.9.10, 149.112.112.102620:fe::10, 2620:fe::fe:10NoNoNo
Secured with ECS9.9.9.11, 149.112.112.112620:fe::11, 2620:fe::fe:11YesYesYes

The unsecured 9.9.9.10 service is mostly useful for troubleshooting: if a domain works on 9.9.9.10 but not on 9.9.9.9, Quad9's filtering or DNSSEC validation is the reason. The ECS variant trades a little privacy for better CDN mapping, similar to Google's approach.

Privacy: What Actually Differs

All three providers publish privacy policies and none of them sell query data for advertising. The meaningful differences are:

  • Retention of IP addresses. Cloudflare says it does not write IPs to disk and purges logs within 24 hours. Google keeps full IPs in temporary logs for a short period. Quad9 says it does not store IPs at all.
  • Organisational incentives. Google and Cloudflare are commercial companies with many other products; Quad9 is a non-profit whose only product is the resolver.
  • ECS exposure. Google sends part of your IP to authoritative servers by default; Cloudflare and Quad9 (on its main address) do not.

Remember that any resolver can see the domains you look up. Encrypted DNS protects queries from your ISP and anyone on the local network, but the resolver itself still sees them. Choosing a resolver is choosing whom you trust with that information.

Security Filtering

If you want malicious domains blocked at the DNS layer without running your own infrastructure, Quad9's main address and Cloudflare's 1.1.1.2 both do it, and Cloudflare's 1.1.1.3 adds adult-content filtering for family networks. Google does not offer filtering. This is a lightweight form of DNS filtering and is no substitute for endpoint security, but it does stop many phishing links from resolving at all. For full control over what gets blocked on a home network, a self-hosted option like Pi-hole can forward to any of these resolvers upstream.

You can see DNSSEC validation in action with a deliberately broken test domain:

dig @9.9.9.9 dnssec-failed.org A +short     # no answer: validation fails (SERVFAIL)
dig @9.9.9.10 dnssec-failed.org A +short    # returns an address: no validation
dig @1.1.1.1 dnssec-failed.org A | grep status

The first and third queries should fail with SERVFAIL because the domain's signatures are intentionally invalid, while Quad9's unsecured service returns an answer. That is exactly what a validating resolver is supposed to do. See what DNSSEC is for the background.

Encrypted DNS Support

All three support both DNS over HTTPS and DNS over TLS. You can test them directly.

DoH with curl, using Cloudflare's JSON format:

curl -s -H "accept: application/dns-json" \
  "https://cloudflare-dns.com/dns-query?name=example.com&type=A"

Google's JSON API:

curl -s "https://dns.google/resolve?name=example.com&type=A"

DoT with kdig from the Knot DNS utilities:

kdig @9.9.9.9 +tls-hostname=dns.quad9.net +tls-ca example.com A
kdig @1.1.1.1 +tls-hostname=one.one.one.one +tls-ca example.com A
kdig @8.8.8.8 +tls-hostname=dns.google +tls-ca example.com A

The +tls-ca and +tls-hostname options make kdig verify the server's certificate against the system trust store and the expected hostname, so a successful answer proves you reached the real resolver over an authenticated, encrypted channel. Android's Private DNS setting expects the DoT hostname, which is why each provider publishes one.

How to Benchmark Them Yourself

Published speed rankings are measured from someone else's network and go stale quickly as providers add locations. The only result that matters is how each resolver performs from your connection, so test it.

Quick Test with dig

for server in 1.1.1.1 8.8.8.8 9.9.9.9; do
  echo -n "$server: "
  dig @"$server" wikipedia.org A +noall +stats | awk '/Query time/ {print $4 " ms"}'
done

This prints the response time for one query to each resolver. Run it several times: the first query may be a cache miss, and later ones show how quickly the nearest node responds from cache.

A More Reliable Benchmark in Python

A single query tells you little. The script below sends repeated queries for a list of domains to each resolver and reports the median and 90th percentile, which are much more stable than averages. It needs dnspython (pip install dnspython):

import statistics
import time

import dns.resolver

RESOLVERS = {
    "Cloudflare": "1.1.1.1",
    "Google": "8.8.8.8",
    "Quad9": "9.9.9.9",
}

DOMAINS = [
    "wikipedia.org", "github.com", "bbc.co.uk", "mozilla.org",
    "stackoverflow.com", "python.org", "cloudflare.com", "apple.com",
]
ROUNDS = 5

for name, ip in RESOLVERS.items():
    resolver = dns.resolver.Resolver(configure=False)
    resolver.nameservers = [ip]
    resolver.lifetime = 3
    timings = []
    failures = 0
    for _ in range(ROUNDS):
        for domain in DOMAINS:
            start = time.perf_counter()
            try:
                resolver.resolve(domain, "A")
                timings.append((time.perf_counter() - start) * 1000)
            except Exception:
                failures += 1
    median = statistics.median(timings)
    p90 = statistics.quantiles(timings, n=10)[8]
    print(f"{name:11} median {median:6.1f} ms   p90 {p90:6.1f} ms   failures {failures}")

Each resolver gets 40 queries. The median shows typical performance, the 90th percentile shows how bad the slow lookups are, and the failure count reveals timeouts. Include your ISP's resolver (often your router's IP) in RESOLVERS for a fair baseline.

Benchmarking Tips

  • Test at different times of day. Evening congestion on your ISP's network can change results.
  • Test cache misses too. Popular domains are almost always cached at every large resolver. Adding a few less popular domains you actually visit gives a more realistic picture of recursive performance.
  • Test over the protocol you will use. If you plan to use DoH in the browser, plain UDP results are only a rough proxy.
  • Ignore single-digit differences. A 3 ms gap between resolvers is invisible next to everything else in a page load, and your OS and browser cache most lookups anyway.
  • Consider GRC's DNS Benchmark on Windows if you prefer a graphical tool that tests many resolvers at once.

Which Should You Use?

There is no universally best choice, but the decision is usually straightforward:

  1. Choose Quad9 (9.9.9.9) if you want malware and phishing protection by default from a non-profit with a strong no-IP-logging stance.
  2. Choose Cloudflare (1.1.1.1) if you want unfiltered results with strong privacy commitments and a very large anycast footprint. Switch to 1.1.1.2 or 1.1.1.3 for security or family filtering.
  3. Choose Google (8.8.8.8) if you value CDN-friendly routing via ECS, very mature standards compliance, and handy debugging tools like the JSON API.
  4. Mix them carefully. Using one provider's primary and another's secondary works, but if one filters and the other does not, a blocked domain will sometimes resolve through the other. Pick secondaries from the same provider and tier.

Whatever you pick, set it on your router to cover the whole network — see how to change DNS servers on your router — or per device if you want encrypted DNS everywhere.


Public DNS Resolver FAQ

It depends on where you are and how your ISP connects to each network. All three are fast globally, and the differences are often a few milliseconds. Run the benchmark scripts above from your own connection to find out which is fastest for you.

Based on their published policies, Cloudflare commits to not writing querying IP addresses to disk and deleting logs within 24 hours, while Google keeps full IPs in temporary logs for a short period. Both say they do not use the data for advertising.

Its main address, 9.9.9.9, blocks domains identified as malicious by threat intelligence feeds. It does not block ads or adult content. Use 9.9.9.10 if you want an unfiltered Quad9 service.

1.1.1.1 is unfiltered. 1.1.1.2 blocks known malware domains. 1.1.1.3 blocks malware and adult content. All three use the same network and privacy policy.

Yes, it works technically. Devices may use either server at any time, so you will get a mix of both providers' behaviour and privacy policies. If one of them filters and the other does not, filtering becomes unreliable.

Yes. All three support both protocols, with DoH at cloudflare-dns.com, dns.google, and dns.quad9.net, and DoT hostnames one.one.one.one, dns.google, and dns.quad9.net.

ECS lets a resolver pass part of your IP address to authoritative servers so CDNs can return a nearby edge server. Google sends it, Cloudflare does not, and Quad9 only sends it on its 9.9.9.11 service. It trades a small amount of privacy for potentially better CDN routing.

Visit 1.1.1.1/help for Cloudflare, or query whoami.akamai.net with dig, which returns the IP address of the resolver that reached Akamai's servers. Comparing that IP to known provider ranges shows which service handled your query.

Conclusion

Cloudflare, Google, and Quad9 are all reliable, globally distributed, standards-compliant resolvers, and any of them is a reasonable upgrade from a poorly run ISP resolver. The meaningful differences are philosophical and practical rather than speed: Quad9 filters threats by default and is run by a non-profit, Cloudflare emphasises minimal logging and offers opt-in filtering tiers, and Google provides ECS-based CDN accuracy and excellent tooling with a somewhat longer short-term log retention.

Decide what matters to you — privacy, filtering, or CDN routing — and then benchmark the candidates from your own network rather than trusting a chart from someone else's. Whichever you choose, use the encrypted endpoints where you can, keep primary and secondary from the same provider tier, and recheck occasionally, because networks and policies evolve.

Here are some useful references for comparing public DNS resolvers:

  1. Cloudflare Developers: 1.1.1.1 documentation — addresses, Families tiers, DoH and DoT setup, and the privacy commitment.
  2. Google Developers: Google Public DNS — setup instructions, DoH and DoT details, and the JSON API.
  3. Google Developers: Google Public DNS privacy — what Google logs and for how long.
  4. Quad9: Quad9 service addresses and features — the full list of Quad9 IPs, blocking, DNSSEC, and ECS options.
  5. RFC 7871: Client Subnet in DNS Queries — the specification for EDNS Client Subnet.
Tags :
Share :

Related Posts

What Is the Difference Between Authoritative and Recursive DNS Servers?

What Is the Difference Between Authoritative and Recursive DNS Servers?

When someone says "the DNS server," they could mean two completely different machines doing two completely different jobs. One kind of server holds t

Continue Reading
Can DNS settings affect website speed?

Can DNS settings affect website speed?

Yes, DNS settings can significantly affect the speed at which a website loads for its users. DNS, or Domain Name System, is often likened to the inte

Continue Reading
Can You Use a CNAME Record on the Root Domain?

Can You Use a CNAME Record on the Root Domain?

It is one of the most common DNS questions there is. Your hosting platform says "add a CNAME pointing to myapp.example-cdn.net," it works perfectly

Continue Reading