What a resolver actually does
Type a domain, and before your browser can request anything it has to turn that name into an IP address. That lookup goes to a resolver — by default, one your ISP runs.
ISP resolvers are frequently slow, occasionally misconfigured, and sometimes return an advertising page instead of an honest NXDOMAIN for a name that does not exist. Public resolvers are usually faster and better behaved.
The candidates
| Resolver | Primary | Secondary | Notes |
|---|---|---|---|
| Cloudflare | 1.1.1.1 | 1.0.0.1 | Nodes in Mumbai, Delhi, Chennai, Bengaluru, Hyderabad. Strong privacy stance. |
| 8.8.8.8 | 8.8.4.4 | Nodes in India. Very reliable, logs more than Cloudflare. | |
| Quad9 | 9.9.9.9 | 149.112.112.112 | Blocks known malicious domains. Slightly slower from India. |
| Cloudflare Family | 1.1.1.3 | 1.0.0.3 | Same speed, filters malware and adult content. |
| Your ISP | — | — | Sometimes fastest, being closest. Often not. Measure it. |
Measure it yourself — this is the whole point
Published rankings are averages across the world, and they tell you nothing about your line in your city. Two minutes of measurement beats any list:
# Linux or macOS — compare three resolvers
for dns in 1.1.1.1 8.8.8.8 9.9.9.9; do
echo -n "$dns "
dig @$dns google.com +noall +stats | grep "Query time"
done
# Windows
nslookup google.com 1.1.1.1
nslookup google.com 8.8.8.8
Run each several times against a few different domains. First lookups are slower than cached ones, so a single measurement tells you very little. What you want is the consistent winner over a dozen queries.
Typical query times from an Indian broadband connection to a resolver with local nodes are 5–25 ms. If yours is over 60 ms, changing resolver is worth doing.
How much does it actually matter?
Honestly: less than the people recommending it suggest. A DNS lookup happens once per domain, then it is cached for the duration of the TTL. Saving 40 ms on the first request to each new domain is real but modest, and it does nothing at all for bandwidth.
Where it is genuinely noticeable: browsing lots of new sites, pages that pull resources from many different domains, and connections whose ISP resolver is badly overloaded at peak hours — which in India is a real phenomenon on some networks between 8pm and 11pm.
Changing it
On the router is best — every device on the network benefits and you do it once. Look under WAN or Internet settings for primary and secondary DNS.
Windows: Settings → Network → Change adapter options → right-click your adapter → Properties → IPv4 → Use the following DNS server addresses.
macOS: System Settings → Network → your connection → Details → DNS.
Android and iOS: both support private DNS over TLS — enter one.one.one.one or dns.google and it applies on mobile data as well as Wi-Fi.
Always set a secondary. If your only resolver goes down, nothing resolves and the internet appears to be broken.
A different question: DNS for your domain
Everything above is about the resolver you query. Your website has the opposite problem — the authoritative nameservers that answer when someone else looks your domain up.
There, what matters is that the nameservers are anycast, have presence in India, and answer quickly for visitors. Our domain registration includes free DNS management on nameservers with Indian presence, so a lookup for your domain from Mumbai is answered from Mumbai.
If your site feels slow to start loading and you have already dealt with hosting location and caching, authoritative DNS is a reasonable next place to look. It is rarely the biggest problem, and it is worth ruling out.