At Geeks on Site, we help homeowners and small businesses secure and speed up their networks every day. One of the most effective changes you can make takes just a few minutes: adjusting your router’s dns settings to use a faster, more secure dns server.
When you change your dns on the router level, every connected device on your network, PCs, smartphones, smart TVs, security cameras, and IoT devices, automatically uses the new dns server addresses without any individual configuration.
We’ll cover why DNS matters for both speed and security, recommend reliable public dns providers like Cloudflare (1.1.1.1), Google Public DNS (8.8.8.8), and OpenDNS, and share essential security tips to prevent dns hijacking. If any step feels too technical, you can always schedule onsite or remote help with our team.
What Is DNS and How Does It Work on Your Router?
The Domain Name System (DNS) functions as the internet’s phone book. When you type a domain name like geeksonsite.com into your browser, your device sends dns queries to a dns server, which translates that human-readable name into a machine-readable ip address (like 104.21.12.123). Without this translation, your browser wouldn’t know where to find the website.
Here’s how the flow works on your home network:
Device (phone/laptop) → Router → DNS Server → Website IP returned
Most home routers receive their default dns server assignment from your internet service provider via DHCP when the modem connects. This means your ISP controls which dns service handles your queries by default. When you change dns servers on your router, every device that gets its IP from that router’s dhcp server will automatically use your preferred dns server instead.
Modern routers support both IPv4 and IPv6 dns addresses. For example, Cloudflare offers 1.1.1.1 (IPv4) and 2606:4700:4700::1111 (IPv6). For business networks, custom dns configuration often includes content filtering and uptime monitoring features that ISP defaults don’t provide.
DNS Hijacking and Why Router Settings Are a Target
DNS hijacking occurs when attackers gain access to your router, often through unchanged default passwords, and modify the dns server settings to point to malicious servers. According to a 2024 FBI report, over 1.2 million US households were affected by DNS-based malware campaigns that redirected traffic to phishing sites.
Key risks of DNS hijacking:
- Attackers can redirect you to fake banking or login pages even when your browser shows “https”
- Campaigns targeting consumer routers (like those affecting TP-Link users in 2023) silently reroute traffic without visible warnings
- All devices on the network become vulnerable simultaneously
The best defenses are using a secure dns server from a trusted dns provider and immediately changing your router’s default admin credentials. If you suspect infection across multiple devices, reset your router’s dns settings and consider professional malware cleanup.
Default Router DNS Settings and Their Impact on Speed
Most US ISPs automatically assign their own dns server addresses to your router:
| ISP | Primary DNS |
| Xfinity | 75.75.75.75 |
| AT&T | 68.94.156.1 |
| Spectrum | 71.10.216.1 |
| Verizon Fios | 71.252.0.12 |
| Cox | 68.105.28.11 |
Changing DNS doesn’t increase your raw bandwidth—your 300 Mbps connection stays 300 Mbps. However, it can significantly improve how quickly websites start to load. DNSPerf benchmarks from 2025 show ISP dns averages around 45ms latency compared to Google’s 14ms or Cloudflare’s 13ms. When loading a page with 20+ domains to resolve, this difference adds up fast.
In some all-in-one ISP gateways, dns fields are locked or hidden entirely. Users often need to add their own router behind the ISP box for full control over their dns configuration.
DNS and Network-Wide vs Device-Only Changes
Changing DNS on a single device (like adjusting settings in Windows via adapter options) only affects that one computer. Router-level changes apply to every device on your wi fi network, including smart TVs, game consoles, and IoT devices that don’t expose dns controls in their settings.
Router-level DNS is ideal when:
- You want consistent settings across all the devices on your network
- You have IoT devices without user interfaces
- You want to apply family filters network-wide
Device-level DNS makes sense when:
- You’re traveling and using public wi fi
- You need a different dns server for work vs personal use
- You use a VPN that handles its own dns queries
Preparation: What to Do Before Changing DNS on Your Router
Before making changes, complete this quick checklist:
- Document your current settings Screenshot your router’s current WAN/Internet page showing the existing dns server addresses. This makes reverting easy if something goes wrong.
- Find your router’s IP address On most home networks, this is 192.168.0.1 or 192.168.1.1. To confirm:
- Windows: Open Command Prompt, type ipconfig, find “Default Gateway”
- macOS: System Preferences → Network → Advanced → TCP/IP
- Smartphones: Check your wi fi connection details for “Gateway” or “Router”
- Connect via Ethernet if possible A wired connection prevents disconnection during configuration changes.
- Update router firmware Visit your manufacturer’s support site (Netgear, TP-Link, ASUS) and install the latest stable firmware to patch known security issues.
- Choose your DNS provider Have your preferred dns server addresses ready before starting. We recommend having both primary and secondary dns IPs prepared.

Choosing Safe and Reliable DNS Servers
Here are the most reliable public dns providers as of 2025-2026:
Cloudflare DNS
- IPv4: 1.1.1.1 and 1.0.0.1
- IPv6: 2606:4700:4700::1111 and 2606:4700:4700::1001
- Features: Fastest average latency (13.4ms), strict no-logs policy verified by independent audit, malware blocking via 1.1.1.2
Google Public DNS
- IPv4: 8.8.8.8 and 8.8.4.4
- IPv6: 2001:4860:4860::8888 and 2001:4860:4860::8844
- Features: 99.99% uptime, handles 300 trillion daily queries, anonymized logging for 24-48 hours
OpenDNS (Cisco)
- IPv4: 208.67.222.222 and 208.67.220.220
- Features: Content filtering via Cisco Umbrella, blocks 1.4 million malware domains daily
Family-Safe Options:
- OpenDNS FamilyShield: Blocks age inappropriate content and adult content automatically
- CleanBrowsing: 185.228.168.168 / 185.228.169.168 with specialized family filters
For most home users, we recommend Cloudflare or Google for optimal performance and reliability. If choosing feels overwhelming, we can recommend and configure the right setup during a remote support session.
How to Change DNS on Your Router: Generic Step-by-Step
These steps work for most wireless routers produced between 2018 and 2026. Exact menu labels vary, but the flow remains similar.
- Connect to your router via wi fi connection or Ethernet cable
- Open a browser and enter your router’s IP address (typically 192.168.0.1 or 192.168.1.1)
- Log in with your router username and password
- Default credentials like admin/admin should be changed immediately
- Check the router’s label if you haven’t modified them
- Navigate to Internet, WAN, or DHCP settings
- Often under “Advanced” or “Network” menus
- Look for a dns tab or dns section
- Locate DNS Server fields
- Find Primary DNS and Secondary DNS fields
- Some interfaces show DNS Server 1 and DNS Server 2
- Change from automatic to manual
- Select “Use the following dns server addresses” instead of “Obtain dns server automatically”
- Enter your chosen DNS addresses
- Input preferred dns server (e.g., 1.1.1.1)
- Input secondary dns servers (e.g., 1.0.0.1)
- Click save or Apply, then restart if prompted
After your router reboots, devices may take 1-5 minutes to pick up the new settings via DHCP renewal. Power cycling one device helps confirm the new settings are working.
Keep your backup of old settings handy for reverting if needed. Note that smart home devices depend on stable DNS.
Example: Changing DNS on a Typical Netgear Router
For Netgear Nighthawk models (2020-2025 firmware):
- Open your browser and navigate to 192.168.1.1 or routerlogin.net
- Log in with your admin credentials
- Click Advanced tab at the top
- Select Setup → Internet Setup
- Find “Domain Name Server (DNS) Address”
- Change from “Get Automatically from ISP” to “Use These DNS Servers”
- Enter your primary dns: 1.1.1.1
- Enter secondary dns: 1.0.0.1
- Click Apply
The router will reconnect to your ISP, which takes 30-60 seconds. Streaming or gaming sessions may briefly disconnect. Document your exact navigation path in case you need to repeat after a factory reset.
Example: Changing DNS on a TP-Link or ASUS Router
TP-Link Archer Series (2022-2025):
- Navigate to 192.168.0.1 in your browser
- Log in and go to Advanced → Network → Internet
- Find “Use the Following DNS Addresses”
- Enter DNS 1: 8.8.8.8 and DNS 2: 8.8.4.4
- Tap save, then go to System Tools → Reboot
ASUS RT Series:
- Navigate to router.asus.com or 192.168.1.1
- Go to WAN tab → Internet Connection
- Set “DNS Server 1” and “DNS Server 2” to manual
- Enter your following dns addresses
- Click Apply
Although menu names differ across asus routers and TP-Link models, the concept remains identical: switch DNS from automatic to manual and enter your chosen IPs. Screenshots taken now will save troubleshooting time later.
Special Case: ISP Gateways (Xfinity, AT&T, Spectrum, Verizon, etc.)
Many ISP-supplied gateways (modem/router combos) present unique challenges:
Common limitations:
- Xfinity xFi gateways often hide DNS options entirely
- AT&T BGW320 units may lock DNS to AT&T servers
- Spectrum RAC2V1K rarely exposes manual DNS fields
Solutions:
- Log into your ISP gateway’s web UI or mobile app
- Look under Advanced, LAN, or WAN sections for DNS settings
- If no editable DNS field exists, you may need to enable bridge mode or passthrough mode
- Connect your own router to the ISP gateway operating in bridge mode
Switching to bridge mode incorrectly can drop your internet connection until properly reconfigured. If you’re unsure, contact your ISP or work with a professional. Our technicians frequently configure bridging and DNS on these exact models for both home and small business customers.
Testing Your New Router DNS Settings
After applying new settings, verify they’re working correctly.
Using Command Line:
On Windows, open Command Prompt and run:
nslookup geeksonsite.com
The “Server” field should display your new DNS provider (e.g., 1.1.1.1 for Cloudflare). Before testing, clear your local cache:
ipconfig /flushdns
On macOS/Linux, use:
dig geeksonsite.com
Using Online Tools:
DNS leak test websites confirm that your dns queries no longer route through your ISP’s servers.
Troubleshooting failures:
- Double-check IP addresses for typos (e.g., 1.1.1.1 vs 11.1.1.1)
- Verify IPv6 dns addresses if your network uses dual-stack
- Check that your browser cache is cleared
If websites fail to load or streaming apps break, revert to your saved settings and verify your internet connection is stable. If YouTube TV is still having trouble, follow our guide to fix YouTube TV buffering issues and rule out other possible causes.
How to Revert to Your Old DNS Settings If Something Breaks
Reverting is straightforward:
- Log back into your router admin page
- Navigate to the DNS settings section
- Change back to “Obtain DNS automatically from ISP” or re-enter your original ISP dns server addresses
- Click save and apply changes
- Power cycle one or two devices to confirm connectivity
Test browsing, video streaming, and email after reverting. Only perform a factory reset as a last resort—it wipes wi fi names, passwords, and all custom settings.
If your internet connection doesn’t return after reverting, contact professional support. We can diagnose whether the issue is DNS-related, an ISP outage, or router failure.
Security Best Practices After Changing DNS on Your Router
Changing DNS is one piece of network hardening. Complete these additional steps for optimal performance and security:
Immediate actions:
- Change your router’s default admin password to a strong, unique passphrase
- Store credentials in a password manager
- Disable remote web administration from the internet
Ongoing maintenance:
- Enable automatic firmware updates (most routers from 2020+ support this)
- Disable WPS (Wi-Fi Protected Setup) pins—they’re vulnerable to brute-force attacks
- Use WPA3-Personal or WPA2-AES with a strong wi fi password
IoT considerations:
- Security cameras and smart doorbells are frequent targets for attackers
- Consider network segmentation for IoT devices
- Our security camera installation services include proper network configuration
Private dns and dns over tls provide additional encryption for dns queries, though not all routers support these features yet.
When to Get Professional Help With Router DNS and Network Setup
Consider professional assistance when you encounter:
- Persistent DNS errors or intermittent connection drops network-wide
- Smart TVs, printers, or IoT devices losing connectivity after DNS changes
- Complex setups with multiple routers, mesh systems, or VLANs
- Small business requirements for content filtering, logging, or compliance
At Geeks on Site, we routinely:
- Audit router and dns configuration settings
- Clean malware that may have altered DNS
- Design secure, high-performance networks for home offices and businesses
Network and DNS problems often manifest as printer “offline” errors or scanning issues. We can resolve the root cause rather than just treating symptoms. Balance your time spent troubleshooting against the value of expert configuration that’s secure, backed up, and documented.
Take Control of Your Network With Better DNS
DNS is a foundational part of how every device on your network reaches the internet. By changing your router’s dns server to a trusted public dns provider, you gain network-wide improvements in speed, reliability, and security—often reducing page load times by 20-30% compared to ISP defaults.
Combining a reputable dns service like Cloudflare or Google Public DNS with strong router security practices significantly reduces your risk of DNS hijacking and other attacks. Choose your dns provider based on your priorities (speed, privacy, or family filtering), carefully follow the router-specific steps for your setup, and document your configuration for future reference.
Ready for help with your router setup, wi fi optimization, smart home integration, or complete business network design? Get in touch with Geeks on Site to schedule onsite or remote support from our experienced technicians.
Last Updated on September 8, 2026





