Home/ Blog/ Explainers/ Article
Blog · Explainers

Public DNS servers with filtering: a verified list of what each IP really blocks

Public DNS servers with filtering, verified against official docs: what the Cloudflare, Quad9, AdGuard, CleanBrowsing, ControlD, Mullvad and OpenDNS IPs block.

Diagram of DNS routes with filtered branches cut before resolving

Public DNS servers with filtering are free resolvers that refuse to answer lookups for known malware, phishing, or adult-content domains. The dependable options are Cloudflare (1.1.1.2 and 1.1.1.3), Quad9 (9.9.9.9), AdGuard DNS, CleanBrowsing, ControlD, OpenDNS FamilyShield, and Mullvad. The exact IP you pick matters more than the provider, because the lists people copy from forums often mislabel them.

A resolver is the service that turns a name like example.com into an address your machine can connect to. A filtered resolver is a phone book with the con artists' numbers torn out: ask for a known-bad name and it simply refuses to answer. Nothing to install, nothing to pay. You change one setting and every lookup on that device passes through the filter.

We verified every address on this page against the providers' own documentation on 28 July 2026. That check exists because the versions of this list circulating on social media and forums get roughly a third of the labels wrong. Some of those errors are harmless. A few point a "family filter" at an address that does no family filtering at all.

Why servers should care, not just parents

Filtered DNS is usually pitched at home routers. It earns a place on servers too. Almost every piece of malware that lands on a host eventually asks DNS for the name of its command and control point, the server it reports back to. Point your fleet's outbound resolution at a malware-blocking resolver and some of those callbacks fail on their own. Security agencies call this practice protective DNS (PDNS), and the free resolvers below are the zero-budget version of it: one cheap layer in a broader server hardening stack, not a substitute for detection, but a tripwire that costs one line of configuration.

The verified list: pick your goal, take the pair

Start from what you want blocked, not from the provider. Each short table below covers one goal. Addresses come in pairs; use both, and keep both in the same tier.

One more thing before the addresses. Providers add and change tiers, so every provider name below links straight to its official tier documentation: any row can be re-checked in seconds. Every address was last verified against those pages on 28 July 2026. If a provider's page and this table ever disagree, trust the provider's page, and tell us so we can fix the row.

Block malware and phishing

ResolverIPv4 addressesWorth knowing
Quad9 Recommended9.9.9.9, 149.112.112.112Malware plus phishing; DNSSEC validation on
Cloudflare Malware Blocking Only1.1.1.2, 1.0.0.2Blocked names answer 0.0.0.0
ControlD Malware (p1)76.76.2.1, 76.76.10.1Blocklists refresh every 30 minutes
CleanBrowsing Security Filter185.228.168.9, 185.228.169.9Malware, phishing, spam; no adult filtering
OpenDNS Home208.67.222.222, 208.67.220.220Phishing by default; more categories with a free account
Mullvad base194.242.2.4Encrypted DNS only; also blocks ads and trackers
Malware-blocking public resolvers. Last verified against the linked official docs: 28 July 2026.

Family and adult-content filtering

ResolverIPv4 addressesWorth knowing
Cloudflare Malware and Adult Content1.1.1.3, 1.0.0.3Adult content plus the malware list
AdGuard DNS Family protection94.140.14.15, 94.140.15.16Also ads and trackers; forces Safe Search
CleanBrowsing Adult Filter185.228.168.10, 185.228.169.11Adult sites plus malware; allows mixed-content sites
CleanBrowsing Family Filter185.228.168.168, 185.228.169.168Strictest: adds VPN, proxy, and mixed-content domains
ControlD Family Friendly76.76.2.4, 76.76.10.4Adult and inappropriate content
OpenDNS FamilyShield208.67.222.123, 208.67.220.123Adult content plus proxies and anonymizers
Mullvad family194.242.2.6Encrypted DNS only; adds gambling
Quad9noneNo family tier exists; 9.9.9.11 is not one
Family-filtering public resolvers. Last verified against the linked official docs: 28 July 2026.

Block ads and trackers

ResolverIPv4 addressesWorth knowing
AdGuard DNS Default94.140.14.14, 94.140.15.15Ads and trackers; no adult filtering on this pair
ControlD Ads and Tracking (p2)76.76.2.2, 76.76.10.2Ads and trackers
Mullvad adblock194.242.2.3Encrypted DNS only
Ad-blocking public resolvers. Last verified against the linked official docs: 28 July 2026.

No filtering at all

ResolverIPv4 addressesWorth knowing
Google Public DNS8.8.8.8, 8.8.4.4No filtered variant exists at all
Cloudflare Standard1.1.1.1, 1.0.0.1The filtered tiers are separate addresses
Quad9 Unsecured9.9.9.10, 149.112.112.10Drops even the malware list; Quad9 says experts only
AdGuard DNS Non-filtering94.140.14.140, 94.140.14.141Unfiltered pair, distinct from the Default pair
ControlD Unfiltered (p0)76.76.2.0, 76.76.10.0An Uncensored tier also exists at 76.76.2.5
Unfiltered public resolvers. Last verified against the linked official docs: 28 July 2026.

Two niche tiers do not fit the tables above: ControlD Social (76.76.2.3, 76.76.10.3) blocks social media platforms, and Mullvad's extended (194.242.2.5) and all (194.242.2.9) tiers stack social media, and in the case of all, every category the provider filters, onto the base list.

In prose, the short version: Google filters nothing. The difference between Cloudflare's 1.1.1.1, 1.1.1.2, and 1.1.1.3 is only the filter: the first resolves everything, the second adds malware blocking, the third blocks malware plus adult content, and blocked names answer 0.0.0.0. Quad9 blocks malware and phishing on 9.9.9.9 and offers no content filtering of any kind. AdGuard's default tier is about ads and trackers, with a separate family pair. CleanBrowsing splits security, adult, and family into three tiers of rising strictness. ControlD ships six free tiers from unfiltered to family. Mullvad filters up to six categories but only over encrypted DNS. OpenDNS does phishing by default and family filtering on its FamilyShield pair.

Five mislabels that keep circulating

These are the errors we found in the widely shared version of this list. Each one is the kind that fails silently: the resolver answers fine, so nothing looks broken, and the filter you think you have is not there.

  1. CleanBrowsing 185.228.168.9 is not a family filter. It is the Security Filter: malware, phishing, and spam only. CleanBrowsing's own documentation states it does not block adult content. The real Family Filter pair is 185.228.168.168 and 185.228.169.168.

  2. Quad9 has no family tier at all. 9.9.9.11 is the same malware blocklist as 9.9.9.9 with EDNS Client Subnet (ECS) enabled, a mechanism that shares part of your network address with content delivery networks for better geographic routing. Quad9 states plainly that it does no content filtering.

  3. ControlD's 76.76.2.1 is the malware tier, not family. The Family Friendly resolver is 76.76.2.4. Point a child's device at .1 and adult content resolves normally.

  4. Mullvad's 194.242.2.4 and .5 do no adult filtering, and none of Mullvad's IPs answer plain DNS. Those two are the base and extended tiers (malware and social media, no adult category). The family tier, 194.242.2.6, is missing from most reposts entirely. And Mullvad serves DNS over HTTPS (DoH) and DNS over TLS (DoT) only, so typing these IPs into a router's ordinary DNS fields does nothing.

  5. OpenDNS 208.67.220.220 is the standard secondary, not a family filter. The family product is FamilyShield, on 208.67.222.123 and 208.67.220.123, which also blocks proxy and anonymizer sites.

Set it up without surprises

Pick the tier for the job. On servers, use a malware tier such as Quad9's 9.9.9.9 or Cloudflare's 1.1.1.2; family tiers block categories a server never needs and can break legitimate lookups. On a family network, take the family pair from one provider and use both of its addresses.

The classic mistake is mixing tiers. Most systems treat primary and secondary DNS as a pool, not a strict failover order, so a lookup can go to either address at any moment. Set a family filter as primary and an unfiltered 8.8.8.8 as secondary and the filter is off for a share of your traffic from day one. Both entries must come from the same tier. And for a whole household, set the pair once in the router's DNS settings instead of per device: everything on the network inherits it.

Pick your platform:

On a modern Linux server, the setting lives in systemd-resolved:

/etc/systemd/resolved.conf · then: systemctl restart systemd-resolved
[Resolve]
DNS=9.9.9.9 149.112.112.112
FallbackDNS=1.1.1.2 1.0.0.2

Note the fallback pair is also a filtering tier. Leave the default fallbacks in place and the machine quietly resolves unfiltered whenever the primaries are slow or unreachable.

Either click through System Settings, then Network, then your connection's Details button, then DNS, or do it in one command. List your network service names first, then set the pair on the one you use:

terminal · set both addresses on the active service
networksetup -listallnetworkservices
networksetup -setdnsservers Wi-Fi 9.9.9.9 149.112.112.112
networksetup -getdnsservers Wi-Fi

Swap Wi-Fi for Ethernet if that is the service in use. The third command reads the setting back so you can confirm it took.

The clicking route is Settings, then Network and internet, then your adapter, then Edit next to DNS server assignment, then Manual with IPv4 on. In PowerShell (run as administrator) it is two commands: find the interface name, then set the pair.

PowerShell (administrator) · set both addresses on the active interface
Get-DnsClientServerAddress
Set-DnsClientServerAddress -InterfaceAlias "Ethernet" -ServerAddresses ("9.9.9.9","149.112.112.112")
ipconfig /flushdns

Swap Ethernet for your interface's name from the first command, commonly Wi-Fi on laptops. The flush clears answers cached before the change.

Verify it, whatever the platform

To confirm which resolver a host is actually using, and that the filter answers:

terminal · verify the active resolver and test a name
resolvectl status | grep 'DNS Servers'
dig +short example.com @1.1.1.2

A normal domain returns its real addresses. For a domain on Cloudflare's malware list, the documented behavior is an answer of 0.0.0.0: run the same lookup against 1.1.1.1 and 1.1.1.2, and a filtered name resolves normally on the first while the second returns 0.0.0.0. On Windows, where dig is not installed, nslookup example.com 1.1.1.2 plays the same role; on macOS, dig ships with the system. That pair of lookups is the whole verification, and it is worth running once after setup rather than trusting the label on a list.

Where DNS filtering stops helping

A filtered resolver only blocks what asks DNS for a known-bad name. Three things walk straight past it.

First, attacks that live on legitimate domains. Malware that runs its command channel through Microsoft 365 calendar entries or Microsoft Teams relay servers makes lookups any filter must allow, because blocking them would break the product for everyone. Second, malware that skips your resolver: a hardcoded IP address or a built-in DoH client never touches the DNS you configured. Third, freshness. Blocklists are curated and updated on the providers' schedules, and shared attack infrastructure rotates domains faster than any list tracks them.

So treat filtered DNS as what it is: a free layer that removes the lazy end of the threat, silently. It blocks, but it does not tell you what tried. The lookup that got refused on a server that should never browse the web is a signal worth investigating, and that visibility comes from your logs and your detection stack, not from the resolver.

Topics

Frequently asked questions

Which public DNS server blocks malware for free?

Quad9 (9.9.9.9 and 149.112.112.112) and Cloudflare (1.1.1.2 and 1.0.0.2) both block known malware domains at no cost.

ControlD offers a free malware tier at 76.76.2.1, and CleanBrowsing at 185.228.168.9. All are set by changing the DNS servers on your device or router.

Does Quad9 have a family or adult-content filter?

No. Quad9 blocks malware and phishing domains only and states it will not do content filtering.

The 9.9.9.11 address sometimes labeled "family" online is the same security blocklist as 9.9.9.9 with EDNS Client Subnet enabled for better content-delivery routing.

Why is my family-filter DNS not blocking adult content?

Most often the address is mislabeled: several widely shared lists point "family" at security-only resolvers.

The verified family pairs are AdGuard 94.140.14.15/94.140.15.16, CleanBrowsing 185.228.168.168/185.228.169.168, ControlD 76.76.2.4, and OpenDNS FamilyShield 208.67.222.123/208.67.220.123. Also confirm the secondary DNS is from the same tier.

Can I use Mullvad DNS in my router settings?

Only if the router supports encrypted DNS (DNS over HTTPS or DNS over TLS).

Mullvad serves filtered DNS exclusively over those encrypted protocols, so entering addresses like 194.242.2.4 in ordinary plain-DNS fields does nothing.

Do Google 8.8.8.8 and 8.8.4.4 filter anything?

No. Google Public DNS states it performs no blocking or filtering, apart from rare security or legal exceptions.

If you want malware or content blocking with similar performance, use a filtered resolver such as Quad9 9.9.9.9 or Cloudflare 1.1.1.2 and 1.1.1.3 instead.

How current is this verified DNS list?

Every address was last verified against the providers' official documentation on 28 July 2026.

Each provider name in the tables links to that documentation, so any row can be re-checked in seconds. If a provider's page and this table ever disagree, trust the provider's page: tiers do change.

Ready to meet the Guardians?

Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.