Guide
What is a DNS server?
DNS servers turn domain names into IP addresses. Learn how resolution works, how encrypted DNS changes privacy, and what a DNS leak really is.
On this page
The internet routes packets by IP address, but people remember names. The Domain Name System is the directory that bridges the two — and your DNS resolver is the service that looks names up on your behalf. It is also one of the most revealing logs on any network, which is why it appears in every privacy discussion.
DNS in one sentence
DNS is a distributed, hierarchical database that maps names such as publicipchecker.com to IP addresses such as 203.0.113.10. When you type a domain, your device asks a resolver, the resolver asks the wider DNS system, and the answer comes back in milliseconds — usually from a cache.
The resolution walk-through
- Your device checks locally. The OS cache, then the hosts file, may already hold the answer. Loopback entries such as
127.0.0.1matter here — see what 127.0.0.1 is. - It asks a recursive resolver — your ISP's by default, or one you chose: Cloudflare's
1.1.1.1, Google's8.8.8.8, Quad9, or your VPN's. - The resolver walks the hierarchy: a root server points to the
.comnameservers, those point to the domain's authoritative nameservers, and those return the record. - The record type decides the answer.
Afor IPv4,AAAAfor IPv6,CNAMEfor an alias,MXfor mail,TXTfor verification and policy records such as SPF and DMARC. - The answer is cached for the record's TTL (time to live), typically minutes to hours, which is why DNS changes are not instant everywhere.
Which resolver are you using?
| Resolver | Operator | Notes |
|---|---|---|
| Your ISP's | The ISP | Default, usually fastest, and visible to the ISP |
| 1.1.1.1 | Cloudflare | Fast, privacy-forward policy, supports DoH/DoT |
| 8.8.8.8 / 8.8.4.4 | Reliable, globally anycast | |
| 9.9.9.9 | Quad9 | Blocks known malicious domains by default |
| dns.adguard-dns.com | AdGuard | Blocks ads and trackers at the resolver level |
On Windows, ipconfig /all lists your DNS servers; on macOS and Linux, scutil --dns and resolvectl status (or cat /etc/resolv.conf) show them. If you are on a VPN, the resolver should belong to the tunnel.
DNS and your privacy
Because every lookup carries the domain you are about to visit, a resolver sees a near-complete map of your browsing — even though the page contents are encrypted by HTTPS. Plain DNS (port 53) is unencrypted, so anyone on the path, from a café network to a national gateway, can read it.
Three things changed that landscape:
- Encrypted transports — DNS over HTTPS (DoH), DNS over TLS (DoT) and DNS over QUIC (DoQ) hide queries from the local network. Modern browsers enable DoH by default for many users, often using their own resolver.
- Anycast and centralisation — a handful of large public resolvers now handle much of the world's DNS, which improves speed and moves trust from your ISP to a resolver operator.
- Awareness of leaks — a VPN that tunnels your web traffic but lets DNS queries go to your ISP's resolver is leaking your browsing. That is what a DNS leak is, and it is easy to test.
Changing DNS and fixing leaks
- Pick a resolver with a policy you accept, and enable encrypted DNS where the platform supports it — Windows 11, macOS, iOS, Android and modern browsers all have a switch.
- Set it in one place. Changing DNS inside a VPN app while the OS uses its own resolver causes exactly the split that leaks.
- Test. A leak test shows which resolver answered your queries — see the five-point VPN check.
- Flush caches after a change:
ipconfig /flushdnson Windows,sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponderon macOS,sudo resolvectl flush-cacheson Linux.
Bottom line: DNS tells the internet where to send your request and tells your resolver what you asked for. Changing the resolver does not hide your IP — the destination still sees it; our IP checker shows what that destination sees. Encrypting DNS hides the query from the path, not the visit from the site.
Frequently asked questions
Does changing my DNS server hide my IP address?
No. The site you visit still sees your public IP. Encrypted DNS hides the name you looked up from the local network, which is a different privacy property — see how to hide your IP for that.
What is a DNS leak?
It is a query that escapes the encrypted tunnel — usually because DNS is configured outside the VPN — so your ISP or the local network can still see which domains you resolve. Leak tests look for resolver mismatches.
Is 1.1.1.1 safe to use?
It is a well-run public resolver with published policies and strong performance, and it supports encrypted DNS. Every resolver sees your queries, so pick one whose policy you accept — that is the real trade-off.
Keep reading
- What is a proxy server?
- What is a DNS leak?
- Tor vs VPN
- What is port forwarding?
- Does a VPN slow down your internet?
- MAC address vs IP address
- Are free VPNs safe?
- What is 127.0.0.1?
- How does a VPN work?
- Subnet masks and CIDR explained
- How to fix an IP address conflict
- How to find your IP address on a computer
- Browse all IP guides
- Check my public IP address
Check any other IP address
Investigating a suspicious login, a spam email header or a server log entry? Run any IPv4 or IPv6 address through the same geolocation and proxy checks.