Type something to search...
How to Change DNS Servers on Your Router?

How to Change DNS Servers on Your Router?

Changing DNS on each laptop, phone, console, and smart TV in a household is tedious, and it misses every device a guest brings over. Changing it once on the router covers the whole network in a single step. The catch is that router DNS settings are more subtle than they look: most routers have two different DNS settings that do different things, IPv6 can quietly keep your devices on the old resolver, and some ISP-supplied routers do not let you change the setting at all. If you have not decided which resolver to use yet, read Cloudflare DNS vs Google Public DNS vs Quad9 first, and if you are not sure switching is worth it, test your ISP's DNS server before you start.

This guide covers how router DNS works, how to find and log in to your router, the difference between WAN DNS and DHCP DNS, step-by-step changes in the web interface and on OpenWrt from the command line, the IPv6 settings most guides skip, how to confirm the change worked, and what to do when your router will not cooperate.

How DNS Works on a Home Network

When a device joins your network, the router's DHCP server gives it an IP address, a default gateway, and one or more DNS server addresses (DHCP option 6). On IPv6, the router advertises DNS servers through router advertisements (the RDNSS option) or DHCPv6. Devices then send their DNS queries to whatever they were told.

Most consumer routers tell devices to use the router itself as the DNS server, for example 192.168.1.1. The router runs a small DNS forwarder (often dnsmasq) that caches answers and forwards anything it does not know to its own upstream resolvers, which by default are your ISP's.

That gives you two separate places to change DNS:

SettingUsually found underWhat it changesEffect on devices
WAN / Internet DNSInternet, WAN, or Broadband settingsThe upstream resolvers the router forwards toDevices still use the router as DNS; the router forwards to your chosen resolver
LAN / DHCP DNSLAN, DHCP server, or Local network settingsThe DNS address handed to devicesDevices query your chosen resolver directly, bypassing the router's forwarder

Change the WAN DNS if you simply want a different public resolver for everyone. Devices keep using the router's cache, and nothing changes on the devices themselves.

Change the DHCP DNS if you want devices to talk to a specific server directly — typically a local filter like Pi-hole, so it can see per-device queries. When you do this, remove any secondary public resolver, or devices will use it to bypass the filter.

Step 1: Find Your Router's IP Address

The router's admin page is at its LAN IP address, which is your default gateway.

Windows:

Get-NetRoute -DestinationPrefix "0.0.0.0/0" | Select-Object NextHop

macOS:

route -n get default | grep gateway

Linux:

ip route show default

Each command prints the default gateway, commonly 192.168.1.1, 192.168.0.1, or 10.0.0.1. Open that address in a browser, for example http://192.168.1.1. Many routers also have a friendly hostname or a mobile app; mesh systems such as Eero, Google Nest Wifi, and Deco are managed almost entirely through their apps.

Step 2: Log In

Use the admin credentials printed on the router's label, or the password you set when you installed it. If you still use the default password, change it now — anyone who can log into your router can change its DNS and silently redirect every device on your network, a technique known as DNS hijacking. While you are in there, make sure remote (WAN-side) administration is disabled and the firmware is up to date.

Step 3: Change the WAN (Upstream) DNS

Menu names vary by manufacturer, but the setting is nearly always on the page where you configure your internet connection.

  1. Open the Internet, WAN, or Broadband section.
  2. Find the DNS setting. It is often a toggle like "Get DNS automatically," "Connect to DNS server automatically," or "Use ISP DNS."
  3. Switch it to manual and enter your chosen servers. For example, Cloudflare's 1.1.1.1 and 1.0.0.1, Google's 8.8.8.8 and 8.8.4.4, or Quad9's 9.9.9.9 and 149.112.112.112.
  4. If there are IPv6 DNS fields on the same page or on a separate IPv6 page, fill those in too (for example 2606:4700:4700::1111 and 2606:4700:4700::1001 for Cloudflare). More on why this matters below.
  5. Save or apply. Some routers reconnect the WAN, which drops the internet for a few seconds.

Use primary and secondary servers from the same provider and the same filtering tier. Mixing a filtering resolver with an unfiltered one makes filtering inconsistent, and mixing providers makes troubleshooting harder.

Step 4 (Optional): Change the DHCP DNS Handed to Devices

If you run a local DNS server such as Pi-hole or your own resolver:

  1. Open the LAN or DHCP Server settings.
  2. Find the fields labelled "DNS server," "Primary DNS," or "DHCP DNS."
  3. Enter the local server's IP address, for example 192.168.1.2. Leave the secondary empty, or set it to a second local server, not a public resolver.
  4. Save, then reconnect devices or wait for them to renew their DHCP lease.

Some ISP routers hide or lock this field. If yours does, see the troubleshooting section at the end.

Changing DNS on OpenWrt from the Command Line

OpenWrt is common on enthusiast routers and some commercial ones, and its UCI system makes DNS changes scriptable. Connect with ssh root@192.168.1.1 and run:

# Stop using the ISP's DNS and set custom upstream servers
uci set network.wan.peerdns='0'
uci add_list network.wan.dns='1.1.1.1'
uci add_list network.wan.dns='1.0.0.1'

# Same for IPv6
uci set network.wan6.peerdns='0'
uci add_list network.wan6.dns='2606:4700:4700::1111'
uci add_list network.wan6.dns='2606:4700:4700::1001'

uci commit network
/etc/init.d/network restart

Setting peerdns to 0 tells OpenWrt to ignore the DNS servers the ISP provides over DHCP or PPPoE, and the dns lists define the upstream resolvers that dnsmasq will forward to. Interface names wan and wan6 are the defaults; check yours with uci show network.

To make the router advertise a different DNS server to LAN clients — for example a Pi-hole at 192.168.1.2 — add DHCP option 6:

uci add_list dhcp.lan.dhcp_option='6,192.168.1.2'
uci commit dhcp
/etc/init.d/dnsmasq restart

Devices that renew their lease will now receive 192.168.1.2 as their DNS server instead of the router. Confirm what the router is forwarding to at any time with cat /tmp/resolv.conf.d/resolv.conf.auto.

Do Not Forget IPv6

This is the most common reason a router DNS change "does not work." If your ISP provides IPv6, your router may advertise the ISP's IPv6 DNS servers to devices through router advertisements or DHCPv6, independently of the IPv4 settings you changed. Devices with both an IPv4 and an IPv6 DNS server will happily use either, so some of your queries keep going to the ISP.

To fix it, do one of the following:

  • Set custom IPv6 DNS servers in the router's IPv6 settings, matching your IPv4 choice.
  • Set the router to advertise itself as the IPv6 DNS server (many do this by default, and the router then forwards to your WAN DNS choice).
  • On OpenWrt, use the wan6 settings above; odhcpd advertises the router's own address to LAN clients by default, which is what you want.

Only disable IPv6 as a last resort; it is increasingly important for performance and some services.

Step 5: Make Devices Pick Up the Change

Devices keep their DHCP settings until the lease renews, and they cache DNS answers. The quickest approach is to toggle Wi-Fi off and on, or reboot the device. To renew from the command line:

Windows:

ipconfig /release
ipconfig /renew
Clear-DnsClientCache

macOS (replace en0 with your interface name):

sudo ipconfig set en0 DHCP

Linux with NetworkManager:

nmcli connection down "Your Connection" && nmcli connection up "Your Connection"

If you only changed the WAN DNS, devices do not need a new lease at all, because they still query the router — but the router's own cache may hold old answers for a while. Rebooting the router clears it. For more on clearing device caches, see how to flush the DNS cache.

Step 6: Verify the Change Worked

Check which DNS server a device received:

# macOS
scutil --dns | grep "nameserver\[[0-9]*\]" | sort -u

# Linux
resolvectl status | grep "DNS Servers"

On Windows, Get-DnsClientServerAddress shows the same information. Then confirm which resolver is actually answering on the internet side:

dig whoami.akamai.net A +short

This returns the IP address of the resolver that contacted Akamai's servers. If it belongs to the provider you chose, the change is working end to end. Cloudflare users can also open https://1.1.1.1/help in a browser. If the result still shows your ISP, check IPv6, check for a secondary DNS left in place, and check whether the device has its own DNS override.

Repeat the check from a couple of different devices — a phone on Wi-Fi and a laptop — because some devices ignore DHCP DNS entirely.

When Your Router Will Not Cooperate

  • ISP router with locked DNS settings. Many ISP-supplied gateways hide the DNS fields. Options include putting the ISP gateway in bridge or modem mode and using your own router behind it, or connecting your own router to the ISP gateway and running your network from it (accepting double NAT). Alternatively, set DNS on individual devices; see how to change DNS settings on Windows, Mac, iPhone, and Android.
  • ISP intercepts port 53. If you set a public resolver but whoami.akamai.net still shows an ISP address on every device, the ISP may be transparently redirecting DNS. Encrypted DNS defeats this. Some routers (and OpenWrt via packages such as https-dns-proxy with its LuCI app) can forward queries upstream over DNS over HTTPS.
  • Devices with hardcoded DNS. Some smart TVs and streaming devices ignore DHCP and query public resolvers directly. Advanced routers can redirect or block outbound port 53 from everything except your chosen server.
  • Internal names stop resolving. dnsmasq's DNS rebinding protection blocks upstream answers that contain private IP addresses. If you rely on public names that resolve to internal IPs — a form of split-horizon DNS — add those domains to the router's rebind protection allowlist.

Router DNS FAQ

On the router if you want every device, including guests and smart TVs, to use the new resolver with one change. On individual devices if you cannot change the router, or you want encrypted DNS on a specific laptop or phone.

WAN DNS sets which upstream resolvers the router forwards to, while devices still ask the router. DHCP DNS changes the server address handed to devices, so they query that server directly.

Common causes are IPv6 DNS servers still advertised by the router, devices that have not renewed their DHCP lease, devices with a manual DNS override, or an ISP that intercepts DNS traffic. Check IPv6 first.

Usually not, since applying the setting takes effect immediately. A restart clears the router's DNS cache and forces devices to reconnect, which can make the change apply faster.

The secondary address from the same provider and filtering tier, such as 1.0.0.1 with 1.1.1.1. If the primary is a local filter like Pi-hole, leave the secondary empty or use a second local filter.

Some routers support DoH or DoT natively, and OpenWrt can add it with packages. Many consumer routers do not, in which case you can enable encrypted DNS on individual devices or browsers instead.

It only affects how quickly hostnames are looked up, mostly on the first visit to a site. It does not change bandwidth. Test before and after to see whether your connection benefits.

Yes, and it is easy to revert by switching back to automatic DNS. Keep a note of the original settings, and protect the router with a strong admin password so nobody else can change it.

Conclusion

Changing DNS on your router is the most efficient way to move a whole network to a better resolver, but doing it properly means understanding which setting you are changing. Use the WAN DNS setting to change the router's upstream for everyone while keeping its local cache, or the DHCP DNS setting to send devices straight to a specific server such as Pi-hole. Set IPv6 DNS to match, or your devices will quietly keep using the ISP over IPv6.

Once the change is applied, renew leases on a few devices and verify with whoami.akamai.net or the provider's check page rather than assuming it worked. If your router locks the setting or your ISP intercepts DNS, you still have options — bridge mode with your own router, encrypted DNS, or per-device settings — so you can use whichever resolver you choose.

Here are some useful references for configuring DNS at the router level:

  1. OpenWrt Documentation: DNS and DHCP configuration — the UCI options for dnsmasq, DHCP options, and rebind protection.
  2. RFC 2132: DHCP Options and BOOTP Vendor Extensions — defines option 6, which routers use to hand DNS servers to devices.
  3. RFC 8106: IPv6 Router Advertisement Options for DNS Configuration — how routers advertise IPv6 DNS servers through RDNSS.
  4. Cloudflare Developers: Set up 1.1.1.1 on a router — Cloudflare's general router setup instructions and addresses.
  5. Google Developers: Get started with Google Public DNS — addresses and configuration guidance, including routers.
Tags :
Share :

Related Posts

What Is the Difference Between Authoritative and Recursive DNS Servers?

What Is the Difference Between Authoritative and Recursive DNS Servers?

When someone says "the DNS server," they could mean two completely different machines doing two completely different jobs. One kind of server holds t

Continue Reading
Can DNS settings affect website speed?

Can DNS settings affect website speed?

Yes, DNS settings can significantly affect the speed at which a website loads for its users. DNS, or Domain Name System, is often likened to the inte

Continue Reading
Can You Use a CNAME Record on the Root Domain?

Can You Use a CNAME Record on the Root Domain?

It is one of the most common DNS questions there is. Your hosting platform says "add a CNAME pointing to myapp.example-cdn.net," it works perfectly

Continue Reading