
How to Change DNS Settings on Windows, Mac, iPhone, and Android?
Every device you own asks a DNS resolver to turn names like example.com into IP addresses, and by default that resolver is whatever your router or mobile carrier hands out. Usually that means your ISP's servers, which may be slower, less private, or less reliable than the alternatives (if you're not sure whether that matters for you, see whether your ISP's DNS server is slowing you down). Changing DNS on a single device is a quick way to test a different resolver, work around a broken one, or apply filtering without touching the rest of the network.
This guide walks through changing DNS settings on Windows 11 and 10, macOS, iPhone and iPad, and Android — through the normal settings screens and, where it's useful, from the command line. It also covers encrypted DNS options built into each platform and how to confirm that your device is actually using the new servers.
Before You Start: Pick Your DNS Servers
You need two things before you change anything: a primary and secondary resolver address, and an idea of whether you want plain DNS or encrypted DNS. The three most widely used public resolvers are listed below. For a deeper comparison of their privacy policies, filtering, and performance, read Cloudflare DNS vs Google Public DNS vs Quad9.
| Provider | IPv4 | IPv6 | Encrypted DNS hostname |
|---|---|---|---|
| Cloudflare | 1.1.1.1, 1.0.0.1 | 2606:4700:4700::1111, 2606:4700:4700::1001 | one.one.one.one |
| Google Public DNS | 8.8.8.8, 8.8.4.4 | 2001:4860:4860::8888, 2001:4860:4860::8844 | dns.google |
| Quad9 (malware blocking) | 9.9.9.9, 149.112.112.112 | 2620:fe::fe, 2620:fe::9 | dns.quad9.net |
A few points that save confusion later:
- Per-device vs network-wide. Changing DNS on one device affects only that device. If you want every phone, laptop, and smart TV on your network to use the same resolver, change it once on the router instead — see how to change DNS servers on your router.
- Per-network on most platforms. Windows, macOS, and iOS store DNS settings per network interface or per Wi-Fi network. A setting you apply on your home Wi-Fi won't follow you to a coffee shop network unless you configure that too.
- Write down the current values. If your current setting is "automatic" (DHCP), you can always switch back to that. If it's already manual, note the existing addresses — some corporate or school networks need their internal resolvers to reach private hostnames.
How to Change DNS Settings on Windows
Windows 11 (Settings app)
- Open Settings and go to Network & internet.
- Select Wi-Fi (then your connected network's Hardware properties) or Ethernet for a wired connection.
- Next to DNS server assignment, select Edit.
- Change the dropdown from Automatic (DHCP) to Manual.
- Turn on IPv4, then enter your Preferred DNS and Alternate DNS addresses.
- Optionally turn on IPv6 and enter the IPv6 addresses for the same provider.
- Select Save.
Windows 11 also supports DNS over HTTPS directly in this dialog. Once you enter a known provider's address (such as 1.1.1.1 or 8.8.8.8), the DNS over HTTPS option becomes available; set it to On (automatic template) to encrypt queries to that resolver. Choosing the option that allows fallback to plain text keeps DNS working on networks that block DoH, at the cost of silently losing encryption. If you want to know what DoH actually protects, see what DNS over HTTPS is.
Windows 10 (Control Panel)
- Open Control Panel and go to Network and Sharing Center, then Change adapter settings.
- Right-click your active adapter (Wi-Fi or Ethernet) and choose Properties.
- Select Internet Protocol Version 4 (TCP/IPv4) and click Properties.
- Choose Use the following DNS server addresses and enter the preferred and alternate servers.
- Click OK, then repeat for Internet Protocol Version 6 (TCP/IPv6) if you use IPv6.
The same Control Panel dialog still exists in Windows 11 if you prefer it.
Windows from PowerShell
PowerShell is faster when you manage several machines or want a repeatable script. First, find the exact name of the interface you want to change:
Get-NetAdapter | Where-Object Status -eq "Up" | Select-Object Name, InterfaceDescription, ifIndex
This lists the connected adapters with their names (commonly Wi-Fi or Ethernet) and interface indexes.
Then set the DNS servers on that adapter. Run PowerShell as Administrator:
Set-DnsClientServerAddress -InterfaceAlias "Wi-Fi" -ServerAddresses ("1.1.1.1","1.0.0.1","2606:4700:4700::1111","2606:4700:4700::1001")
Set-DnsClientServerAddress replaces the server list for the named interface; you can mix IPv4 and IPv6 addresses in the same list. To go back to the DNS servers your router provides:
Set-DnsClientServerAddress -InterfaceAlias "Wi-Fi" -ResetServerAddresses
And to confirm what each interface is using now:
Get-DnsClientServerAddress -InterfaceAlias "Wi-Fi"
Windows with netsh (Command Prompt)
On older systems or in batch scripts, netsh does the same job from an elevated Command Prompt:
netsh interface ipv4 set dnsservers name="Wi-Fi" source=static address=9.9.9.9 register=primary validate=no
netsh interface ipv4 add dnsservers name="Wi-Fi" address=149.112.112.112 index=2 validate=no
The first command sets the primary server and the second appends a secondary one. To revert to automatic DNS, run netsh interface ipv4 set dnsservers name="Wi-Fi" source=dhcp.
After any change on Windows, clear the resolver cache with ipconfig /flushdns (or Clear-DnsClientCache in PowerShell) so old answers don't hide the effect. The full set of cache-clearing commands for each OS is in how to flush the DNS cache.
How to Change DNS Settings on a Mac
macOS Ventura and later (System Settings)
- Open System Settings and select Network.
- Click the network service you use — Wi-Fi or Ethernet.
- For Wi-Fi, click Details next to the connected network. For Ethernet, click Details on the service.
- Select the DNS tab in the sidebar.
- Under DNS Servers, click + and add each resolver address. Remove any existing entries with − if you don't want them used.
- Click OK.
Entries shown in grey were supplied by DHCP; once you add your own, macOS uses yours instead. On older versions (Monterey and earlier), the same settings live under System Preferences, then Network, then Advanced, then DNS.
macOS from Terminal
The networksetup tool changes DNS for a network service without opening the GUI. Start by listing the service names:
networksetup -listallnetworkservices
The output includes names like Wi-Fi, Ethernet, or USB 10/100/1000 LAN. Use the exact name in the next commands:
sudo networksetup -setdnsservers Wi-Fi 1.1.1.1 1.0.0.1 2606:4700:4700::1111
networksetup -getdnsservers Wi-Fi
The first command replaces the DNS server list for the Wi-Fi service; the second prints the current list. To return to the DHCP-provided servers, pass the special value empty:
sudo networksetup -setdnsservers Wi-Fi empty
For a full view of the resolver configuration macOS is actually using — including per-domain resolvers added by VPN clients — run scutil --dns. This is worth checking if your change seems to be ignored, because a VPN or a security agent can install its own resolver that takes priority.
Encrypted DNS on macOS
macOS supports DNS over HTTPS and DNS over TLS system-wide, but not through the Network settings screen. You enable it by installing a configuration profile (a .mobileconfig file) published by your DNS provider or generated by a tool you trust. Once installed, it appears under System Settings, then General, then Device Management (labelled Profiles on some versions), and you can remove it from there. Some providers also offer a small app that installs and manages the profile for you.
How to Change DNS Settings on iPhone and iPad
Per Wi-Fi network
- Open Settings and tap Wi-Fi.
- Tap the info (i) button next to the network you want to change.
- Scroll down and tap Configure DNS.
- Choose Manual.
- Delete the existing servers (tap the red minus icon) and tap Add Server to enter each new address.
- Tap Save.
This setting applies only to that specific Wi-Fi network. iOS remembers it, so you'll need to repeat the steps for each network where you want custom DNS.
Cellular data and system-wide DNS
iOS has no setting for changing DNS on cellular connections. To use a custom resolver everywhere — on mobile data and every Wi-Fi network — you need encrypted DNS delivered through a configuration profile or an app that uses Apple's DNS settings framework. Cloudflare's 1.1.1.1 app and similar apps from other providers work this way. After installing, you'll find the DNS entry under Settings, then General, then VPN & Device Management, where you can switch between installed DNS configurations or remove them.
Two things to watch on iOS:
- Private Wi-Fi Address and iCloud Private Relay don't change your DNS server, but Private Relay does route Safari's DNS queries through its own encrypted path. If you're testing a resolver from Safari with Private Relay on, results may not reflect your custom setting.
- Limit IP Address Tracking and some network-specific features can interact with filtering resolvers. If a filtering DNS seems to be bypassed, check these first.
How to Change DNS Settings on Android
Private DNS (Android 9 and later)
Android's built-in Private DNS feature is the best option on most phones. It uses DNS over TLS and applies to every connection — Wi-Fi and mobile data — so you set it once.
- Open Settings and go to Network & internet (on Samsung devices, Connections, then More connection settings).
- Tap Private DNS.
- Select Private DNS provider hostname.
- Enter the provider's hostname, for example
one.one.one.one,dns.google, ordns.quad9.net. - Tap Save.
Note that Private DNS takes a hostname, not an IP address. Entering 1.1.1.1 here won't work. If the hostname is wrong or the network blocks port 853, you'll lose name resolution entirely in strict mode, which is a quick way to notice a typo. The Automatic option tries DNS over TLS with your network's resolver and falls back to plain DNS when it isn't supported. For background on how DoT compares to DoH, see what DNS over TLS is and how it differs from DoH.
Per Wi-Fi network (static IP settings)
If you want a plain DNS server on one specific Wi-Fi network instead:
- Go to Settings, then Network & internet, then Internet (or Wi-Fi).
- Tap the gear or arrow icon next to the connected network, then the edit (pencil) icon or Advanced options.
- Change IP settings from DHCP to Static.
- Fill in the IP address, gateway, and prefix length for your network, then enter DNS 1 and DNS 2.
- Save.
This is clumsy because Android ties DNS to static IP configuration on that network, so you must enter a valid unused IP address yourself. On Android 9 and later, Private DNS is almost always the better choice. Menu names vary by manufacturer, so if you don't see these exact labels, search Settings for "Private DNS" or "DNS".
How to Confirm Your New DNS Settings Are Working
Changing the setting is only half the job. Check which resolver actually answers your queries.
From any desktop terminal, nslookup prints the server it used before the answer:
nslookup example.com
The Server: line should show your new resolver's address (or a hostname belonging to it). If it still shows your router's IP, the router may be forwarding to your ISP, or the setting didn't apply to the active interface.
With dig on macOS or Linux, the SERVER line at the bottom of the output shows the same thing:
dig example.com | grep SERVER
On Windows, Resolve-DnsName combined with the interface check gives a clear picture:
Get-DnsClientServerAddress -AddressFamily IPv4 | Where-Object ServerAddresses
Resolve-DnsName example.com -Type A
On phones, use a provider's own check page. Cloudflare publishes one at https://one.one.one.one/help that reports whether you're connected to its resolver and whether DoH or DoT is in use. Other providers offer similar test pages.
If you want a quick reference for nslookup's options, see how to use nslookup to check DNS records.
Why Your DNS Change Might Not Take Effect
- Your browser uses its own DNS. Chrome, Edge, and Firefox can use secure DNS with a provider of their own choosing, bypassing your operating system's setting. Check the browser's privacy or security settings for a "Use secure DNS" or "DNS over HTTPS" option and set it to use your current provider or turn it off.
- A VPN overrides DNS. Most VPN clients push their own resolvers while connected. Disconnect the VPN to test, or configure DNS within the VPN app.
- You changed the wrong interface. Laptops often have Wi-Fi, Ethernet, and virtual adapters. Make sure you edited the one carrying traffic.
- IPv6 DNS is still automatic. If you set only IPv4 servers, your device may still use IPv6 resolvers advertised by the router. Set both families or confirm with
scutil --dnsorGet-DnsClientServerAddress. - Cached answers. Old responses stay in the OS and browser caches until their TTL expires. Flush them after changing servers.
- The network intercepts port 53. Some public and corporate networks redirect all plain DNS traffic to their own resolver regardless of what you configure. Encrypted DNS (DoH or DoT) is the usual way around this, where policy allows it.
Best Practices
- Always configure two servers, ideally from the same provider, so a single outage doesn't take down name resolution.
- Don't mix filtering and non-filtering providers as primary and secondary. Operating systems don't strictly prefer the primary, so you'll get inconsistent blocking.
- Keep work devices on managed DNS. Corporate laptops often need internal resolvers to reach intranet sites; changing them can break access and may violate policy.
- Prefer encrypted DNS on mobile devices, since they spend the most time on untrusted networks.
- Document what you changed, especially on family devices, so troubleshooting later doesn't start from scratch.
Changing DNS Settings FAQ
Yes. Changing your DNS server only changes who resolves domain names for you. Choosing a reputable public resolver is safe and often improves privacy. The main risk is a typo that stops name resolution, which you can undo by switching back to automatic.
It can make page loads feel snappier if your current resolver is slow or overloaded, because each new domain lookup completes sooner. It won't increase your download bandwidth. Test a few resolvers from your location before deciding.
iOS doesn't expose a DNS setting for mobile data. To use a custom resolver on cellular, install an encrypted DNS configuration profile or an app from your DNS provider, which applies system-wide.
Private DNS uses DNS over TLS, and the device verifies the resolver's TLS certificate against the hostname you enter. An IP address alone can't be validated that way, so Android requires a hostname such as dns.google.
Usually not. The new servers are used for new lookups immediately. Flushing the DNS cache and restarting the browser is enough to clear old answers in most cases.
Change it on the router if you want every device on your home network to use the same resolver. Change it per device if you only want it on one machine, or if the device moves between networks and you want consistent behaviour.
Set the DNS option back to Automatic or DHCP on Windows and iOS, remove the manual entries on macOS, or switch Android Private DNS back to Automatic. From the command line, use Set-DnsClientServerAddress with -ResetServerAddresses on Windows or networksetup -setdnsservers with the value empty on macOS.
Browsers with secure DNS enabled can send queries directly to their own chosen DoH provider. Check the browser's security settings and either point it at the same provider or disable the browser-level option.
Conclusion
Changing DNS on an individual device takes a couple of minutes on any modern platform: the network settings screen on Windows and macOS, the per-network Configure DNS option on iPhone, and Private DNS on Android. The command-line tools — Set-DnsClientServerAddress on Windows and networksetup on macOS — make the same change scriptable and easy to reverse.
The step people skip is verification. Confirm with nslookup, dig, or a provider's test page that queries really go to the new resolver, and remember that browsers, VPNs, and IPv6 settings can quietly override what you configured. Once it's confirmed, you get the speed, privacy, or filtering benefits you switched for.
Here are some useful references for configuring DNS on your devices:
- Cloudflare 1.1.1.1 Docs: Set up 1.1.1.1 — official per-platform setup instructions for Cloudflare's public resolver.
- Google Public DNS: Get started with Google Public DNS — Google's configuration guide with addresses for IPv4 and IPv6.
- Quad9: Quad9 public DNS — service details and setup guides for Quad9's filtering resolver.
- Microsoft Learn: Set-DnsClientServerAddress — reference for the PowerShell cmdlet used to change DNS servers on Windows.
- RFC 7858: Specification for DNS over Transport Layer Security (TLS) — the standard behind Android's Private DNS feature.


