Welcome to the IPFire Wiki

This wiki is a community-maintained resource about everything there is to know about IPFire. Join us and help us improving it!

Looking for something?

Use the search and find answers to everything about IPFire. If you cannot find what you are looking for, join our community and talk to fellow IPFire users, developers and everybody else involved in the project.

IPFire Community

Differences in Revisions: List of Public DNS Servers

Older Revision
March 22 at 8:13 pm
»
Newer Revision
March 22 at 8:30 pm
updated sprint
# Playground - List of Public DNS Servers
 
## this is a test page
 
This is a list of publicly available DNS servers suitable for use with IPFire. They are operated by many different organisations in many different countries. [Please consider carefully](https://blog.ipfire.org/post/what-you-can-do-with-the-new-dns-features-in-ipfire) which ones you would like to use.
 
**DoT** = DNS-over-TLS service only
**DS** = DNSSEC service only
 
| Operator | Address(es) | DNS over TLS Hostname | Srvc |
| -------- | ----------- | --------------------- | :--: |
| **Anycast** | | | |
| [censurfridns.dk](http://censurfridns.dk/) | 91.239.100.100 | `anycast.uncensoreddns.org` | |
| | 2002:d596:2a92:1:71:53:: | | |
| [Cloudflare](https://1.1.1.1/) | 1.1.1.1 | `cloudflare-dns.com` | Both |
| | 1.0.0.1 | | Both |
| | 2606:4700:4700::1111 | | |
| | 2606:4700:4700::1001 | | |
| [dns.sb](https://dns.sb) | 185.222.222.222 | `dns.sb` | |
| | 185.184.222.222 | | |
| | 2a09:: | | |
| | 2a09::1 | | |
| Hurricane Electric | 74.82.42.42 | | |
| | 2001:470:20::2 | | |
| [Google Public Free DNS](https://developers.google.com/speed/public-dns/) | 8.8.8.8 | `dns.google` | |
| | 8.8.4.4 | | |
| [Quad9](https://www.quad9.net/) | 9.9.9.9 | `dns.quad9.net` | Both |
| | 149.112.112.112 | | |
| | 2620:fe::9 | | |
| | 2620:fe::fe | | |
| [SafeDNS](https://www.safedns.com/) | 195.46.39.39 | | |
| | 195.46.39.40 | | |
| Level 3 / CentryLink / Verizon | 4.2.2.1 | | |
| | 4.2.2.2 | | |
| | 4.2.2.3 | | |
| | 4.2.2.4 | | |
| | 4.2.2.5 | | |
| | 4.2.2.6 | | |
| **Austria (AT)** | | | |
| [Foundation for Applied Privacy](https://applied-privacy.net/services/dns/) | 93.177.65.183 | `dot1.applied-privacy.net` | DoT |
| | 2a03:4000:38:53c::2 | | |
| ** Canada (CA)** | | | |
| [CMRG DNS](https://dns.cmrg.net/) | 199.58.81.218 | `dns.cmrg.net` | |
| **Switzerland (CH)** | | | |
| [Digitale Gesellschaft Schweiz](https://www.digitale-gesellschaft.ch/2019/04/11/oeffentliche-dns-over-tls-und-https-dns-resolver-neuer-service-der-digitalen-gesellschaft/) | 185.95.218.42 | `dns.digitale-gesellschaft.ch` | DoT |
| | 185.95.218.43 | | |
| | 2a05:fc84::42 | | |
| | 2a05:fc84::43 | | |
| ** Germany (DE)** | | | |
| [Digitalcourage e.V.](https://digitalcourage.de/support/zensurfreier-dns-server) | 46.182.19.48 | `dns2.digitalcourage.de` | |
| | 2a02:2970:1002::18 | | |
| [Lightning Wire Labs](https://dns.lightningwirelabs.com/knowledge-base/specs/name-servers) | 81.3.27.54 | `recursor01.dns.ipfire.org` | Both |
| | 2001:678:b28::54 | | |
| | 81.3.27.54 | `recursor01.dns.lightningwirelabs.com` | |
| | 2001:678:b28::54 | | |
| New Nations | 185.82.22.133 | | |
| | 5.45.96.220 | | |
| ** Denmark (DK)** | | | |
| [censurfridns.dk](http://censurfridns.dk/) | 89.233.43.71 | `unicast.uncensoreddns.org` | |
| | 2001:67c:28a4:: | | |
| ** Spain (ES)** | | | |
| [puntCAT](http://servidordenoms.cat/vull-aquest-dns/configuracio-a-windows/windows-7/) | 109.69.8.51 | | |
| ** France (FR)** | | | |
| [French Data Network (FDN)](https://www.fdn.fr/actions/dns/) | 80.67.169.12 | | |
| | 80.67.169.40 | | |
| | 2001:910:800::12 | | |
| | 2001:910:800::40 | | |
| [GetDNS](https://getdnsapi.net/) | 185.49.141.37 | `getdnsapi.net` | |
| Neutopia | 89.234.186.112 | `dns.neutopia.org` | |
| [SafeDNS](https://www.safedns.com/) | 146.185.167.43 | `dot.securedns.eu` | |
| ** Luxembourg (LU)** | | | |
| [Restena Foundation](https://www.restena.lu/en) | 158.64.1.29 | `kaitain.restena.lu` | |
| ** Netherlands (NL)** | | | |
| [Freenom World](https://www.freenom.world/en/index.html) | 80.80.80.80 | | |
| | 80.80.81.81 | | |
| Surfnet | 145.100.185.17 | `dnsovertls2.sinodun.com` | |
| | 145.100.185.18 | `dnsovertls3.sinodun.com` | |
| | 2001:610:1:40ba:145:100:185:17 | | |
| | 2001:610:1:40ba:145:100:185:18 | | |
| **Russian Federation (RU)** | | | |
| SkyDNS | 193.58.251.251 | | |
| **United Kingdom (UK)** | | | |
| [CyberGhost](https://support.cyberghostvpn.com/hc/en-us/articles/214480265-CyberGhost-name-server-addresses-DNS-) | 194.187.251.67 | | |
| **United States (US)** | | | |
| Comcast / Xfinity | 75.75.75.75 | cdns01.comcast.net | DS |
| | 75.75.76.76 | cdns02.comcast.net | DS |
| | 96.113.151.145 | `dot.xfinity.com` (beta) | DoT |
| [Neustar DNS Advantage](https://www.home.neustar/dns-services/ultra-recursive-dns) | 156.154.70.1 | rdns1.ultradns.net | DS |
| | 156.154.71.1 | rdns2.ultradns.net | DS |
| [Sprintlink General DNS](https://sprint.net/index.php?p=faq_dns) | 204.117.214.10 | (sprint customers only) | DS |
| [Sprintlink General DNS](https://sprint.net/index.php?p=faq_dns) | 204.117.214.10 | | DS |
| | 199.2.252.10 | | |
| | 204.97.212.10 | | |
| | 199.2.252.10 | (sprint customers only) | |
| | 204.97.212.10 | (sprint customers only) | |
| [Verisign](https://www.verisign.com/en_US/security-services/public-dns/index.xhtml) | 64.6.64.6 | recpubns1.nstld.net | DS |
| | 64.6.65.6 | recpubns2.nstld.net | DS |
 
 
## Unusable DNS Providers
These providers are not suitable for use with IPFire because they do not support DNSSEC or tamper with DNS traffic in another way.
 
| Operator | IP Addresses |
| --- | --- |
| [Cleanbrowsing](https://cleanbrowsing.org/guides/dnsovertls) | 2a0d:2a00:1::2 / 185.228.168.9, 2a0d:2a00:2::2 / 185.228.169.9 |
| [Comodo Secure DNS](https://securedns.dnsbycomodo.com/) | 8.26.56.26, 8.20.247.20 |
| [DNSReactor](http://dnsreactor.net/) | 45.55.155.25, 104.236.210.29 |
| [FreeDNS](https://freedns.zone/en/) | 37.235.1.174, 37.235.1.177 |
| [GreenTeamDNS](http://www.greenteamdns.com/) | 81.218.119.1, 09.88.198.133 |
| [Nuernberg Internet Exchange (N-IX)](http://www.n-ix.net/mehrwertdienste/dns-server/) | 194.8.57.12 |
| [OpenDNS](https://www.opendns.com/setupguide/) ([](/dns/dnssec/hosted-blacklists)) | 208.67.222.222, 208.67.220.220, 208.67.220.222, 208.67.222.220 |
| [Quad 9](https://quad9.net/) | 9.9.9.10, 149.112.112.10 |
| [SWITCH](https://www.switch.ch/security/info/public-dns/) ([](/dns/dnssec/hosted-blacklists)) | 130.59.31.248 / 2001:620:0:ff::2, 130.59.31.251 / 2001:620:0:ff::3 |
| [Yandex.DNS](https://dns.yandex.com/) | 77.88.8.88, 77.88.8.2 |
 
---
 
These are items just moved from above. They need to be formatted for the **Unusable DNS Providers** table.
 
| Operator | Src | Address(es) | DNS over TLS Hostname |
| -------- | --- | ----------- | --------------------- |
| [Alternate DNS](https://alternate-dns.com/index.php) | DNS o | 198.101.242.72 | dns1.alternate-dns.com |
| | DNSo | 23.253.163.53 | ad-blocking-dns2.alternate-dns.com |
| [CyberGhost](https://support.cyberghostvpn.com/hc/en-us/articles/214480265-CyberGhost-name-server-addresses-DNS-) | DNSo | 38.132.106.139 | newyork-ns01.cyberghostvpn.com |
 
 
## About location and DNSSEC status
The location of the servers has been stated by using [GeoIP Tool](https://geoiptool.com/) and the IPFire GeoIP server. [However, it might be possible that the location is wrong (or has been changed meanwhile).](/configuration/firewall/geoip-block)
 
The servers that are marked with "Anycast" are using anycasts so that traffic will be routed to the nearest of the many instances that are there on the network. Thereof the exact location of the server(s) cannot be determined. Worse, different configurations of Anycast instances cannot be determined reliable.
 
## Security Considerations
A DNS server has a very powerful function in network topology. Please keep in mind that it might log your queries (which is a huge information leak).
 
Further, not all of the DNS servers listed above return correct answers in any case. Some of them return failures for harmful or malicious sites. Check the operators website for more information on this topic.
 
For security reasons, it is required to use DNS servers which support DNSSEC. For privacy and availability reasons, avoid using just one providers' DNS servers.