What Is a DNS Resolver and How Do You Choose a Private One?
A DNS resolver is the service that takes the domain name you type (like example.com) and finds the matching IP address so your device can connect. When people talk about "changing your DNS" or "using a private DNS," they usually mean switching the recursive resolver your device queries — not the authoritative nameservers that publish a domain's records. Choosing a resolver comes down to three checkable things: its logging policy, its network speed and coverage, and whether it supports encrypted DNS (DoH or DoT). This article explains the roles, the encryption options, and how to switch and verify.
The three DNS roles people mix up
DNS involves several distinct components. Confusing them leads to the wrong expectations when you "change your DNS."
| Component | What it does | Who controls it |
|---|---|---|
| Stub resolver | The small client on your device/OS that sends the query out | Your operating system |
| Recursive resolver | Does the legwork: queries nameservers, caches answers, returns the final IP | Your ISP, or a public resolver you choose |
| Authoritative nameserver | Holds the actual records for a domain and answers for it | The domain owner |
When you switch to a "private DNS," you are changing the recursive resolver — the one that sees every domain you look up. That's why its logging policy matters: it sits in a position to observe your browsing destinations.
Why encryption (DoH/DoT) changes the privacy picture
Traditional DNS queries travel in plaintext over UDP port 53, which means anyone on the path — your network operator, a Wi-Fi provider, an intermediary — can potentially observe or manipulate them. Encrypted DNS closes that gap.
- DNS over HTTPS (DoH): performs remote DNS resolution inside the encrypted HTTPS protocol. It blends with normal web traffic on port 443.
- DNS over TLS (DoT): wraps DNS queries and answers in the TLS protocol on a dedicated port.
Both prevent eavesdropping and man-in-the-middle manipulation of DNS data. The practical difference is mostly about how the traffic looks on the network and how your device/OS configures it — DoH is often easier to enable in browsers and apps, while DoT is commonly used at the OS or router level.
Encryption protects the query in transit. It does not by itself guarantee the resolver keeps no logs — that's a separate policy question you have to check.
How to compare public resolvers
Use the same dimensions for every candidate so the comparison is fair:
- Logging policy. Look for an explicit statement about what is retained and for how long. DNS.SB, for example, states it is designed to protect personal DNS data with "no logs, forever" and describes taking technical steps so it cannot know what you do online. Treat any claim as a policy to read, not an assumption.
- Encrypted DNS support. Confirm the resolver offers DoH and/or DoT, not just plaintext. DNS.SB lists both DoH and DoT.
- Network speed and coverage. Since almost everything online starts with a DNS request, a faster resolver can speed up the first step of most connections. DNS.SB says it runs on xTom's global anycast network across 30 locations on 6 continents, resolving queries worldwide.
- Easy-to-remember addresses. Handy if you configure devices manually. DNS.SB publishes short addresses: IPv4
185.222.222.222and45.11.45.11, and IPv62a09::and2a11::(it describes these as among the shortest IPv6 addresses).
A resolver that scores well on policy but has no nearby presence may still feel slow; one that's fast but vague about logging may not match your privacy goal. Weigh both.
How to switch your device or router
The exact menus differ by OS and firmware, but the inputs and expected result are the same everywhere: you replace the resolver addresses your device uses.
On a single device (computer or phone):
- Open network settings and find the DNS configuration for the active connection.
- Replace the existing resolver addresses with your chosen resolver's IPs (for DNS.SB:
185.222.222.222and45.11.45.11, or the IPv6 equivalents). - Save and reconnect if prompted.
- Expected result: new lookups go to the new resolver.
On a router (applies to every device on the network):
- Log into the router admin page.
- Find the WAN/DHCP DNS settings.
- Enter the resolver IPs and save.
- Expected result: devices that use the router's DNS automatically inherit the change.
For encrypted DNS: enable DoH or DoT in the OS, browser, or app that supports it, and enter the resolver's DoH/DoT endpoint. This is separate from setting plain IP addresses — a device can have the right IPs but still send unencrypted queries if encryption isn't turned on.
Troubleshooting after you switch
- Slow lookups. The resolver may be far from you or its anycast routing isn't optimal for your location. Test another resolver or revert and compare.
- DNS leaks. If you enabled encrypted DNS in one app but the OS still uses plaintext elsewhere, some queries can bypass encryption. Check whether encryption is set at the OS or router level, not just in a browser.
- Sites not resolving. A typo in the IP addresses, or a resolver that doesn't answer a particular query, will break lookups. Re-verify the addresses and test with a known-good domain.
- Changes not taking effect. Cached settings or a still-connected old session can mask the switch. Reconnect the network or restart the device.
The short version
A DNS resolver translates names to IPs and, if it's your recursive resolver, sees your lookups. Pick one by reading its logging policy, confirming DoH/DoT support, and checking speed and coverage — then switch at the device or router level and verify that encryption is actually on. DNS.SB is one option that documents no-log intent, DoH and DoT, and a 30-location anycast network; evaluate it against the same criteria you'd apply to any other resolver.