DEV Community

Cover image for How to Change DNS Servers on Windows 11 (Cloudflare vs Google vs Quad9)
Tzukizy
Tzukizy

Posted on Originally published at kocakz.me on

How to Change DNS Servers on Windows 11 (Cloudflare vs Google vs Quad9)

Your ISP's DNS servers work fine for most people. They also tend to be slower than the big public ones, sometimes log more than you'd like, and rarely offer malware blocking. Switching to Cloudflare, Google, or Quad9 takes a couple of minutes and can cut lookup times while giving you clearer privacy or security options.

DNS only handles the name-to-IP step. Once a game or website has the address, the rest of the traffic goes straight to that server. A faster resolver can make pages and matchmaking start a little quicker. It won't lower your in-game ping by some magic amount.

What You're Actually Changing

When you type a domain or a game tries to reach its servers, Windows asks a DNS server for the matching IP address. By default that request goes to whatever your router or ISP hands out. Changing the setting on the adapter overrides that for the connection you're using.

Windows 11 also supports DNS over HTTPS (DoH). That wraps the lookup in the same kind of encryption browsers use for normal HTTPS sites, so the request itself isn't sitting in clear text on the network.

Change DNS in Windows 11 Settings

This is the cleanest method and the one that also lets you turn on DoH.

  1. Press Win + I to open Settings.
  2. Go to Network & internet.
  3. Click Wi-Fi or Ethernet, depending on what you're using.
  4. Open the properties for the active connection (on Wi-Fi this is usually under Hardware properties or the network name).
  5. Find DNS server assignment and click Edit.
  6. Change the drop-down from Automatic (DHCP) to Manual.
  7. Turn on the IPv4 switch.
  8. Enter the preferred and alternate addresses for the service you want.
  9. Under DNS over HTTPS, pick On (automatic template) if you want encryption. Windows already knows the templates for Cloudflare, Google, and Quad9.
  10. Click Save.

You can do the same for IPv6 if your network uses it. The addresses are listed later in the comparison section.

After saving, open a Command Prompt or PowerShell and run:

ipconfig /flushdns
Enter fullscreen mode Exit fullscreen mode

That clears the old cache so new lookups use the servers you just set. Check the result with:

ipconfig /all
Enter fullscreen mode Exit fullscreen mode

Look under the active adapter for the DNS Servers line. It should show the addresses you entered.

The Three Public Options Side by Side

Provider Preferred Alternate IPv6 Preferred IPv6 Alternate Default Filtering Privacy Stance
Cloudflare 1.1.1.1 1.0.0.1 2606:4700:4700::1111 2606:4700:4700::1001 None (use 1.1.1.2 or 1.1.1.3 for blocking) Logs deleted within ~24 hours, audited
Google 8.8.8.8 8.8.4.4 2001:4860:4860::8888 2001:4860:4860::8844 None Temporary logs 24–48 hours, then anonymized
Quad9 9.9.9.9 149.112.112.112 2620:fe::fe 2620:fe::fe:9 Blocks known malware and phishing domains Swiss non-profit, no IP logging by default

Cloudflare (1.1.1.1)

Usually the fastest of the three in global tests. Strong privacy policy and independent audits. The plain 1.1.1.1 service does zero filtering. If you want malware blocking, use 1.1.1.2 / 1.0.0.2. For malware plus adult-content filtering, use 1.1.1.3 / 1.0.0.3.

Good default when you care about lookup speed and keeping the data trail short.

Google Public DNS (8.8.8.8)

Extremely reliable and widely cached. Slightly higher average latency than Cloudflare in most regions, but still much faster than a typical ISP resolver. No content filtering. Google keeps temporary logs longer than Cloudflare before anonymizing them.

Solid choice if you just want something that works everywhere without surprises.

Quad9 (9.9.9.9)

The one that blocks threats by default. It pulls from threat-intelligence lists and refuses to resolve known bad domains. Latency is competitive, sometimes even better than the others depending on your location and routing. Operated by a Swiss non-profit with a no-IP-logging policy.

Useful if you download a lot of random tools, mods, or visit unfamiliar sites and want an extra layer that doesn't require extra software.

Which One for Gaming?

DNS speed only affects the initial connection and any later name lookups. Once the game has the IP, the resolver is out of the path. The difference you feel is usually a few milliseconds on matchmaking or loading screens, not a big drop in in-match ping.

Still, lower and more consistent lookup times help. Cloudflare tends to win pure speed benchmarks. Quad9 can win on specific networks and gives you the malware block. Google sits in the middle as the reliable all-rounder.

The only real way to know is to test from your own connection. Tools like namebench, DNS Benchmark, or even a quick PowerShell loop against a few domains will show which one answers fastest for you. Run the test, switch, flush the cache, and re-test.

Other Ways to Set DNS

Control Panel (older method)

  1. Press Win + R, type ncpa.cpl, and press Enter.
  2. Right-click the active adapter → Properties.
  3. Select Internet Protocol Version 4 (TCP/IPv4) → Properties.
  4. Choose Use the following DNS server addresses and enter the numbers.
  5. Confirm and close.

This method doesn't give you the DoH options that live in the modern Settings app.

PowerShell

Open PowerShell as administrator and find your interface:

Get-NetIPConfiguration
Enter fullscreen mode Exit fullscreen mode

Note the InterfaceIndex or InterfaceAlias, then:

Set-DnsClientServerAddress -InterfaceAlias "Ethernet" -ServerAddresses ("1.1.1.1","1.0.0.1")
Enter fullscreen mode Exit fullscreen mode

Replace the alias and addresses as needed. Flush the cache afterward the same way.

A Few Practical Notes

Changing DNS only affects the device you configure. Your phone, other PCs, and consoles still use whatever they were set to unless you also change them or push the setting from the router.

If something stops resolving after the switch, go back to Automatic (DHCP) or try a different pair. Typos in the address fields are the most common reason things break.

DoH encrypts the lookup between your PC and the resolver. It does not encrypt the rest of your traffic. If you need that, you still need a VPN or similar.

Router-level DNS changes apply to every device on the network at once. That's often cleaner for a household, but the exact steps depend on the router brand and whether it supports DoH itself.

Quick Checklist

  • Pick the provider that matches what you care about most (speed, privacy, or blocking).
  • Set both preferred and alternate addresses.
  • Turn on DoH if the option is available.
  • Flush the DNS cache.
  • Confirm with ipconfig /all.
  • Test a few sites and, if you care about gaming, run a local benchmark.

That's it. The change is reversible in the same place you made it, so there's little downside to trying a different resolver for a day or two and seeing how it feels.

Top comments (0)

Some comments may only be visible to logged-in visitors. Sign in to view all comments.