Mon 31 Aug 2026
daily since 25 Aug
CONFIRMEDFLODESK ▲ $19 appeared · 29 AugASANA ▼ €4.99 withdrawn · 29 AugASANA ▲ $5.99 appeared · 29 AugPROTON VPN ▲ €4.49 appeared · 28 Augall 13 →
Guide — Privacy

Your router tells your ISP every website you visit

US · UK · EU · DE · Deutsch · FR · Français · ES · Español

Every time you type a web address, your router asks your internet provider to translate it into a number. Nothing is hidden in that request, so your provider ends up holding a timestamped list of the sites you open. Pointing the router at a different resolver takes two minutes, costs nothing, and closes that particular gap. It does not make you private, and this page is careful about the difference.

Names like a bank's website mean nothing to the network. Before anything loads, your device has to turn that name into an address, and the service that performs the translation is called a resolver. Unless somebody has changed it, your router uses whichever resolver your internet provider handed it when the line was installed.

That is the whole leak. Classic DNS travels unencrypted, so the request carries the name you asked for in plain view, alongside the time and the household it came from. Nobody has to intercept anything: the provider is the one being asked. Over a week that record is a fair description of your reading habits, your health worries, the job sites you check at lunchtime and the shop you visit at two in the morning.

Be precise about what this record is and is not. It is not the contents of the pages. It is the list of doors you knocked on, which for most people is the more revealing document of the two. Retention rules differ by country and by provider, and this page does not pretend to know what yours keeps or for how long.

The fix is a setting, not a purchase. Your router has a field for upstream DNS servers, usually under WAN or Internet settings. Change it there rather than on each device and every phone, laptop and television on the network is covered at once, including the ones with no settings screen of their own.

The two-minute change

Open your router's admin page, find the upstream or forwarder DNS fields, and set them to 1.1.1.1 as primary and 1.0.0.1 as secondary. Those are Cloudflare's public resolvers. If your router offers DNS over TLS, switch it on and use tls://one.one.one.one, which encrypts the question itself so your provider can no longer read it in passing. Save, reboot the router, and you are finished. If Cloudflare is blocked or simply behaves oddly on your line, Quad9 at 9.9.9.9 is the sensible fallback and filters known malicious domains as it resolves.

If you want filtering as well

NextDNS sits in the same slot and adds blocklists, per-device profiles and a query log you control, with a free tier that covers 300,000 queries a month. A household of ordinary browsers rarely reaches that, and going past it breaks nothing: NextDNS keeps answering, it simply stops filtering until the month turns. Note what changes here: you have moved the record from a company you did not choose to one you did, and you can switch off logging entirely in its settings. That is a real improvement, but it is a change of custodian, not the abolition of the custodian.

We earn nothing from any of the three, and recommend them anyway

Cloudflare, Quad9 and NextDNS run no affiliate programme we could join. We checked on 31 August 2026 and there is no commission, no referral link and no arrangement of any kind behind those names. They are here because they are the right answer to the question. Elsewhere on this site you will find links that do pay us, always marked as such, and the reason you can trust those is that this paragraph exists.

The honest limit: this is not privacy

Changing your resolver stops your provider learning site names from your DNS queries. It does not hide where your traffic goes. Your provider still sees the address your connection opens, and the server name your browser announces at the start of a secure session, which usually names the site just as clearly. Encrypted DNS closes a window and leaves the door open. Anyone selling it as anonymity is selling you something.

The full fix, and what it costs

If the goal is that your provider sees a single encrypted connection rather than a browsing history, that is a VPN with its own private DNS, so name lookups happen inside the tunnel instead of leaking around it. Proton VPN's entry plan is $9.99 a month, with the ladder behind it on our Proton VPN price record. NordVPN's is $3.49, tracked on our NordVPN price record. Surfshark opens at $2.49 and puts no cap on the number of devices, kept on our Surfshark price record, and ExpressVPN's is $2.99, on our ExpressVPN price record. Which of the four is cheapest changes often enough that we will not fix an order in a sentence: those figures are read off the vendors' own pages rather than typed here, and our best VPN ranking sorts the field by the lowest published paid plan from the same reading. If you have narrowed it to two, ExpressVPN against NordVPN is the comparison people search for most.

Check the change actually took

Visit 1.1.1.1/help from a device on the network. It reports which resolver answered and whether the connection to it was encrypted. If it still names your provider, the router is ignoring the setting, which some provider-supplied boxes do deliberately. On those, set the resolver on each device instead, or replace the box.

Questions people actually search

Will changing my DNS make my internet faster?

Sometimes, and less often than the claim suggests. You are changing how long it takes to look up a name, not how fast the page downloads, so the gain shows up as a slightly quicker first response and nothing else. Whether there is a gain at all depends on where your provider's resolver sits and how well it caches. If yours is close and well run, a public resolver may be marginally slower. Measure it on your own line rather than taking anyone's chart on faith, ours included.

Why should I trust Cloudflare with my browsing?

Do not take it on faith; take it on the examination. Cloudflare has an independent Big Four accounting firm examine whether the public resolver does what it promises — among other commitments, that source addresses are anonymised and deleted within 25 hours — and publishes the accountants' report on its compliance page. The first examination covered 2019; a second, of the rebuilt platform, was published this year. Two things about that are worth saying plainly: Cloudflare does not name the firm in the posts announcing the reports, and it states an intention to repeat the examination rather than a fixed interval. It is still a stronger position than most resolvers occupy, because most publish nothing at all, and it is still a choice about whom to trust rather than a way of trusting nobody — which is why the VPN section above exists.

My iPhone says the Wi-Fi has Weak Security. Is that related?

That warning is about the network's encryption rather than DNS: iOS shows it when the router still uses WEP or plain WPA or TKIP instead of WPA2 or WPA3. It is worth fixing on the same visit to the admin page, since it sits a few fields away from the DNS settings you came for. Set the network to WPA2/WPA3 and the warning clears. A properly configured router, with modern Wi-Fi encryption and an upstream resolver you chose, removes both problems in one sitting.

VPN figures on this page are read from each vendor's own public pricing page on the dates shown in their price records, and re-checked daily. Cloudflare, Quad9 and NextDNS pay us nothing and were verified as having no affiliate programme on 31 August 2026. The method →

Found a price that no longer matches the vendor’s page? Tell us — corrections are dated and stay on the page.