Website Review
What is DNS.SB?
DNS.SB is a free public DNS resolver focused on privacy and speed. It translates domain names into IP addresses like any DNS service, but it encrypts those queries and states that it keeps no logs. If you want to stop your internet provider or a network operator from seeing every site you look up, this is the kind of service you would point your device or router at.
What it offers
- No logging: The service says it is designed so it cannot know what you browse, and that it keeps no logs permanently.
- Encrypted DNS: It supports DNS over HTTPS (DoH) and DNS over TLS (DoT), which prevent eavesdropping and tampering with DNS traffic.
- Easy-to-remember addresses: It advertises short IPv4 and IPv6 resolver addresses, including what it calls the world's shortest IPv6 addresses.
- Global network: It runs on xTom's anycast network across 30 locations on 6 continents, which is meant to keep resolution fast wherever you are.
Who it suits
- People who want encrypted DNS without paying or running their own resolver.
- Users who find their ISP's DNS slow or want to avoid ISP-level DNS logging.
- Router owners who want one resolver address to cover every device on the network.
Trade-offs to weigh
Encryption hides DNS queries from your local network, but the resolver itself still sees them—DNS.SB's promise is that it does not store them. Anycast can improve speed, though real-world latency varies by location. Also, DoH and DoT need client support; older devices or some routers may only handle plain DNS.
A practical next step
Check whether your router or operating system supports DoH or DoT. If it does, enter a DNS.SB resolver address there so all your devices benefit at once; if not, set it per device. For a second opinion on encrypted DNS in general, see Cloudflare or Google Developers.
How do I set up DNS.SB on my device or router?
DNS.SB is configured by pointing your device or router at its resolver addresses, then enabling encrypted DNS (DoH or DoT) where your software supports it. The service publishes these addresses on its site: IPv4 185.222.222.222 and 45.11.45.11, and IPv6 2a09:: and 2a11::. DoH and DoT endpoint details are also listed there, so copy the exact values from DNS.SB rather than retyping from memory.
Choose your setup path
| Situation | What to configure | Trade-off |
|---|---|---|
| Single laptop or phone | Set the resolver in network settings, or add a DoH/DoT profile in the OS or browser | Quick and reversible, but only covers that device |
| Whole home or office | Set the addresses in the router's DNS fields | Covers every device automatically; older routers may not support DoH/DoT, so queries stay unencrypted |
| Router with encrypted DNS support | Enter the DoH or DoT server address in the router's encrypted-DNS section | Best coverage plus encryption; requires firmware that exposes the option |
| Devices that ignore router DNS | Configure each device individually | More work, but avoids leaks from apps with hardcoded resolvers |
Router steps
- Sign in to your router's admin page.
- Find the WAN, Internet, or DHCP settings, then the DNS server fields.
- Replace any existing entries with the two IPv4 addresses, or the IPv6 pair if your ISP provides IPv6.
- If the router offers DNS over HTTPS or DNS over TLS, enable it and paste the matching server address.
- Save and reboot the router.
- Confirm the change by visiting DNS.SB's own site or a DNS leak test page; the resolver shown should be DNS.SB, not your ISP.
Device steps
- Windows: Network adapter properties → IPv4/IPv6 → use the manual DNS fields. For encryption, use the OS encrypted-DNS setting if your version has it.
- macOS and iOS: Network settings → DNS → add the servers, or install a DoH/DoT profile.
- Android: Private DNS accepts a DoT hostname; older versions need a third-party client.
- Linux: Edit the resolver configuration or your network manager, and run a local DoH proxy such as dnscrypt-proxy if you want encryption.
Practical notes
Encrypted DNS hides queries from your network operator and local eavesdroppers, but it does not hide them from the resolver itself. DNS.SB states it keeps no logs, which is the relevant claim to weigh here. If you want an independent check on that kind of promise, compare policies at Quad9 and Cloudflare before committing. If you run your own filtering, pair DNS.SB with a local blocklist instead of switching resolvers.
How does DNS.SB prevent logging of my DNS queries?
DNS.SB states that it is designed with a single goal: protecting your personal DNS data with “no logs, forever.” Its page claims it does not want to know what you do online and has “taken the technical steps to ensure we can’t.” In other words, the privacy promise is architectural and policy-based rather than something you configure yourself: you point your device or router at DNS.SB’s resolver, and the service says queries are not recorded.
That matters most when DNS is the last unencrypted step in your browsing. Even with HTTPS websites, plain DNS can reveal the domains you visit to your network operator. DNS.SB addresses this by offering DNS over HTTPS (DoH) and DNS over TLS (DoT), which encrypt DNS queries and answers so they cannot be easily read or altered in transit.
What to check before trusting any no-log claim
- Scope: Does “no logs” cover query contents, client IP addresses, timestamps and retention periods? DNS.SB’s page states no logs, but the practical value depends on those details.
- Encryption: Use DoH or DoT rather than plain DNS if you want the transport itself protected.
- Who else sees data: Your DNS resolver is only one party; your browser, VPN, or ISP may still observe activity.
- Verification: Independent audits or transparency reports are stronger than marketing language alone.
A concrete way to use this: if you are on a public Wi-Fi network and want to reduce the chance that the network operator can see which domains you resolve, configure your phone or laptop to use DNS.SB over DoH or DoT. Your web traffic remains encrypted by HTTPS, and DNS lookups are encrypted as well.
If you want to compare the trade-off, DNS.SB emphasizes speed through a global anycast network across 30 locations and easy-to-remember addresses, while privacy-focused alternatives such as Quad9 emphasize threat blocking and Cloudflare offers a widely used public resolver. The right choice depends on whether you prioritize no-log privacy, malware filtering, or latency in your region.
What is the difference between DNS over HTTPS and DNS over TLS, and which should I use?
Both encrypt DNS traffic so your ISP or a network snoop can't read or tamper with the names you look up. The difference is mostly about the transport they ride on, and that shapes where they work best.
- DNS over HTTPS (DoH) sends DNS queries inside ordinary HTTPS requests over port 443. To the network, it looks like regular web browsing.
- DNS over TLS (DoT) wraps DNS in a dedicated TLS connection over port 853. It's encrypted, but it announces itself as DNS traffic on a distinct port.
H3: Practical differences
| DoH | DoT | |
|---|---|---|
| Port | 443 (shared with HTTPS) | 853 (dedicated) |
| Blends with normal traffic | Yes | No |
| Blocking on restrictive networks | Harder to block | Easier to block |
| OS-level support | Common on modern phones and browsers | Common on Android's Private DNS and many routers |
| Best fit | Browser/app-level privacy, hostile networks | System-wide resolver, home router, servers |
DNS.SB supports both, so the choice is about your setup rather than the provider. If you're configuring a browser or an app, DoH is usually the smoother path and survives networks that block unusual ports. If you want every app on a device or an entire home network covered, DoT through the operating system or router is often simpler to manage in one place.
H3: How to decide
- Setting it up on a single phone or laptop: use the OS private-DNS or encrypted-DNS setting, which typically expects DoT.
- Configuring a browser only: use DoH.
- Running a router or a small server: DoT is easier to point at a fixed resolver and monitor.
- On a network that blocks non-standard ports or inspects traffic: DoH is more likely to keep working.
A concrete example: a remote worker on hotel Wi-Fi who wants encrypted lookups for everything on a laptop can set the OS to DoT, but if that network blocks port 853, switching the browser to DoH restores protection at least for browsing.
One trade-off to keep in mind: encryption hides queries from the local network, but it moves trust to the resolver. DNS.SB states it keeps no logs and operates a global anycast network, which addresses both the trust and latency sides. If your priority is being able to audit or self-host, compare with a resolver you run yourself, such as Pi-hole or Unbound—note these are self-hosted options, not hosted resolvers.
Next step: check whether your device, browser or router exposes an encrypted-DNS setting, then pick DoT for whole-device coverage and DoH for browser-only use.
How does DNS.SB improve my internet speed compared to my current DNS provider?
DNS.SB can improve speed mainly by answering your DNS lookups from a nearby point on a global anycast network rather than from a single distant server. Because almost every web request begins with a DNS lookup, shaving milliseconds off each lookup can make browsing feel snappier, especially on sites that load resources from many different domains.
The page states that DNS.SB runs on xTom's anycast network across 30 locations on 6 continents, and that it offers short, easy-to-remember resolver addresses, including IPv4 addresses like 185.222.222.222 and 45.11.45.11, plus very short IPv6 addresses. It also supports encrypted DNS over HTTPS (DoH) and DNS over TLS (DoT), with a stated no-logging policy.
What actually changes your speed
- Anycast proximity: Your query is routed to a topologically near resolver location, which usually reduces round-trip time compared with a single-region provider.
- Cache warmth: A resolver that many users query can hold popular answers in cache, so you skip a full recursive lookup.
- Encrypted transport trade-off: DoH and DoT add a small handshake and encryption overhead. On a fast, nearby server this is negligible, but on a slow or distant one it can feel slower than plain DNS.
- Your ISP's resolver: Your current provider may already be very close and fast. The gain from switching is often small unless your ISP's resolver is overloaded, poorly peered, or far away.
A practical test
Run a DNS benchmarking tool such as dnsperf or a resolver-comparison script against your current resolver and DNS.SB's addresses, from your actual network, at different times of day. Compare median and 95th-percentile lookup times, not just the average. Then switch your router or device to DNS.SB's DoH or DoT endpoint and repeat the test. If the numbers are close, choose based on privacy and reliability rather than raw speed.
For a concrete scenario: if you are on a fiber connection and your ISP resolver is one hop away, you may see little change. If you are on a mobile or satellite link where your ISP resolver is distant or congested, an anycast resolver with 30 locations is more likely to help.
For setup details and current addresses, use the official site: DNS.SB.
Can I use DNS.SB for free, and are there any usage limits?
Yes. DNS.SB is a free public DNS resolver, and its page presents it as a no-cost service rather than a paid tier. The page does not state any usage quotas, query caps, or account requirements, so there is no published limit to plan around.
What "free" means here in practice
- No signup is described for normal resolver use; you point your device or router at DNS.SB's addresses or encrypted endpoints.
- Privacy is the core promise: the page says DNS data is not logged, "no logs, forever," and that technical steps were taken so the operator cannot see your activity. Treat that as the service's stated design goal.
- The resolver supports encrypted DNS: DNS over HTTPS (DoH) and DNS over TLS (DoT), which prevent eavesdropping or tampering with DNS queries in transit.
- Performance is positioned around a global anycast network spanning 30 locations across 6 continents, so queries are answered from a nearby point.
Practical trade-offs to weigh
A free, no-log resolver is a good fit if you want encrypted DNS without an account, especially on a home router or a laptop where you control network settings. The main trade-off is that "no usage limits" is not the same as "no fair-use expectations": a public resolver can still rate-limit abusive traffic, and the page does not document a service-level agreement. If you run a large network with strict uptime requirements, a resolver with a formal SLA may suit you better.
A concrete scenario
Say you want to stop your ISP from seeing every domain your household visits. You set your router's DNS to DNS.SB, enable DoT or DoH where supported, and leave it running. Browsing feels the same, but lookups are encrypted and, per the site, unlogged.
Next step
Check whether your device or router supports DoH or DoT, then configure DNS.SB as the resolver. If you want a second opinion on encrypted DNS setup, Cloudflare Developers documents DoH/DoT configuration, and Quad9 is another privacy-oriented public resolver worth comparing on logging policy and features.
User reviews (0)