AdGuard DNS is one of the fastest ways to get network-wide ad blocking and tracker suppression without running your own resolver. A single DNS change — on your router or via DoH/DoT on individual devices — drops the vast majority of ad requests, telemetry pings, and phishing domains before they ever touch a browser or app. This guide covers every setup path: router-level configuration by brand, per-OS setup, mobile devices, AdGuard Home self-hosted, and encrypted DNS, with CLI commands to confirm the configuration actually works.
AdGuard DNS Server Addresses for 2026
AdGuard offers three public tiers. Choose one and use it consistently across your entire network. Mixing tiers across devices defeats the purpose of a whole-network setup and makes troubleshooting harder.
- Default — blocks ads and trackers: 94.140.14.14 and 94.140.15.15
- Family Protection — adds adult content filtering on top: 94.140.14.15 and 94.140.15.16
- Non-Filtering — no blocking, just AdGuard's fast anycast resolver: 94.140.14.140 and 94.140.15.141
IPv6 addresses for the same three tiers:
- Default: 2a10:50c0::ad1:ff / 2a10:50c0::ad2:ff
- Family: 2a10:50c0::bad1:ff / 2a10:50c0::bad2:ff
- Non-Filtering: 2a10:50c0::1:ff / 2a10:50c0::2:ff
For encrypted DNS (DoH/DoT/DoQ), the default-tier endpoints are:
- DNS over HTTPS: https://dns.adguard-dns.com/dns-query
- DNS over TLS: dns.adguard-dns.com on port 853
- DNS over QUIC: quic://dns.adguard-dns.com on port 853
AdGuard also offers Private AdGuard DNS — a free-account tier that gives you a personalised DoH/DoT endpoint with your own query log, per-device rules, and custom blocklists. It's worth the two-minute signup if you want granular visibility without running AdGuard Home locally.
Router-Level Setup by Brand
Setting AdGuard DNS at the router covers every device on your network automatically — phones, smart TVs, IoT sensors — without touching each one individually. The tradeoff: per-device DoH/DoT configured at the OS level will bypass the router DNS on that device, so the two approaches are complementary rather than redundant.
TP-Link Archer and Deco
For Archer routers on current firmware:
- Browse to tplinkwifi.net or 192.168.0.1
- Go to Advanced > Network > Internet
- Scroll to DNS, uncheck Get DNS automatically
- Primary DNS: 94.140.14.14 — Secondary DNS: 94.140.15.15
- Save. The Archer DHCP server will advertise these to LAN clients immediately.
For Deco mesh systems, use the Deco mobile app: More > Advanced > DNS, toggle Custom DNS, enter the same IPs.
ASUS RT and ZenWiFi
- Browse to asusrouter.com or 192.168.1.1
- Go to WAN > Internet Connection and set DNS Server 1: 94.140.14.14, DNS Server 2: 94.140.15.15
- Also go to LAN > DHCP Server and repeat the same IPs in the DNS Server 1 and DNS Server 2 fields. This ensures LAN clients receive AdGuard's addresses directly rather than pointing at the router as a forwarder.
On ASUS Merlin firmware: the DHCP path is identical. For DoT, go to WAN > DNS Privacy Protocol, set mode to DNS-over-TLS, and enter dns.adguard-dns.com as the TLS hostname for port 853.
Netgear Nighthawk and Orbi
- Nighthawk: routerlogin.net > Advanced > Setup > Internet Setup > uncheck Use these DNS Servers, enter 94.140.14.14 / 94.140.15.15
- Orbi: orbilogin.com > Advanced > Setup > Internet Setup — same path
- Also check Advanced > Setup > LAN Setup. If the DHCP server is advertising a different DNS there, override it — otherwise local clients bypass your upstream setting entirely.
Linksys Velop and WRT
- Browse to linksyssmartwifi.com or 192.168.1.1
- Go to Connectivity > Internet Settings
- Under DNS Servers, select Manual and enter 94.140.14.14 / 94.140.15.15
Xiaomi Mi Router and AX Series
- Browse to miwifi.com or 192.168.31.1
- Go to Advanced Settings > DHCP
- Set DNS 1: 94.140.14.14, DNS 2: 94.140.15.15
OpenWrt and DD-WRT
On OpenWrt, configure dnsmasq to forward to AdGuard and disable automatic resolv.conf usage so it doesn't fall back to the ISP resolver:
On DD-WRT: Setup > Basic Setup > Network Address Server Settings (DHCP) — enter the IPs in Static DNS 1 and Static DNS 2. Ensure both Use DNSMasq for DHCP and Use DNSMasq for DNS are checked, otherwise the static entries are ignored.
Windows 11
Windows 11 supports DoH natively since 21H2. Plain DNS still works, but DoH gives you encryption even when the router doesn't support it and protects you on untrusted Wi-Fi.
- Settings > Network & Internet > Wi-Fi (or Ethernet) > click your active connection > DNS server assignment > Edit
- Switch to Manual. Under IPv4: Preferred DNS 94.140.14.14, Alternate DNS 94.140.15.15
- For each IP, expand the row and set DNS over HTTPS to On (automatic template)
If Windows doesn't auto-detect the DoH template, add it manually via PowerShell (run as Administrator):
macOS 13 and Later
The cleanest macOS method is a signed DNS configuration profile, which works at the OS level and survives Wi-Fi network changes. Download AdGuard's Default profile from their public DNS page, double-click to open it, then go to System Settings > Privacy & Security > Profiles to install it.
For a manual setup without a profile:
- System Settings > Network > Wi-Fi or Ethernet > Details > DNS
- Remove existing entries, add 94.140.14.14 and 94.140.15.15
- Click Apply
macOS does not support system-level DoH without a profile. For encrypted DNS on Mac, the profile method is the only reliable option.
Linux with systemd-resolved
Most current distros (Ubuntu 22.04+, Debian 12, Fedora 38+) use systemd-resolved. You can enable DoT and DNSSEC validation at the same time as switching resolvers:
Verify it took:
iOS 17 and 18
iOS supports DoH and DoT only via configuration profiles — there is no GUI option for encrypted DNS. For plain DNS, set it per-Wi-Fi network:
- Settings > Wi-Fi > tap the (i) next to your network > Configure DNS > Manual
- Delete existing servers, add 94.140.14.14 and 94.140.15.15
For DoH on iOS (recommended): install AdGuard's DNS profile. In Safari, navigate to AdGuard's DNS page and download the Default profile. Then go to Settings > General > VPN & Device Management and install it. The profile configures DoH at the system level and affects all apps, including those that ignore the per-network DNS setting.
Android 9 and Later
Android's Private DNS feature (Android 9+) gives you system-wide DoT without a VPN or profile. It applies across all networks — Wi-Fi, mobile data, and hotspots — and survives switching between them.
- Settings > Network & Internet > Private DNS
- Select Private DNS provider hostname
- Enter: dns.adguard-dns.com
- Save
Android connects to AdGuard on port 853 automatically. On Samsung One UI, the path is Settings > Connections > More connection settings > Private DNS. A lock icon in the status bar on some devices confirms DoT is active.
AdGuard Home — Self-Hosted Option
AdGuard Home is an open-source DNS server you run on your own hardware — Raspberry Pi, VPS, or NAS. It gives you full control: custom blocklists, per-client rules, query logs, and DNSSEC validation. It's the right choice when you need visibility into exactly what's being blocked and customisation the public AdGuard DNS tiers can't offer.
Quick install on a Raspberry Pi or Debian/Ubuntu server:
The wizard walks you through choosing the listening interface and setting an admin password. After setup, point your router's DHCP DNS to the Pi's IP. AdGuard Home then forwards clean queries to its configured upstream — set that upstream to AdGuard's public DNS IPs, Cloudflare, or any DoH/DoT endpoint. New blocklist entries drop regularly, so keep it updated:
Verifying the Setup Works
After any DNS change, confirm you're actually hitting AdGuard's resolvers before trusting the protection is active. A misconfigured DNS that silently falls back to the ISP resolver looks fine until someone checks.
With dig (Linux/macOS, or install BIND tools on Windows):
With nslookup on any platform:
Use the DNS Lookup tool to check any domain's resolution from multiple global vantage points and see the exact record AdGuard is returning — useful for diagnosing whether a domain is being blocked or misresolved.
On Linux with systemd-resolved:
Common Misdiagnoses
DNS set on router but devices still see ads. Most likely the device has its own hardcoded DNS or has DoH enabled at the browser level. Chrome and Firefox both ship with DoH active and bypass the router's DNS entirely. In Firefox: Settings > Privacy & Security > DNS over HTTPS — set to Off if you want router-level blocking to work. In Chrome: Settings > Privacy and security > Security > Use secure DNS — disable it, or keep it enabled and switch the provider to AdGuard DNS so Chrome's encrypted queries also reach AdGuard.
AdGuard DNS set but some legitimate sites are broken. Occasionally a legitimate domain lands on a community blocklist. Test it directly: dig domain.com @94.140.14.14 — if it returns 0.0.0.0, AdGuard is blocking it. Whitelist specific domains via the AdGuard DNS dashboard at adguard-dns.io after logging into a linked account. With AdGuard Home, use the Filters > Custom filtering rules page and add @@||domain.com^ to whitelist.
Router DNS changed but devices still resolve via old DNS. DHCP leases cache the previous DNS for their lease duration (often 24 hours). Force-renew: Windows — ipconfig /release && ipconfig /renew; macOS — disconnect and reconnect Wi-Fi; Linux — sudo dhclient -r && sudo dhclient. Shortening the DHCP lease time to one hour before making a DNS change pushes updates out faster.
IPv6 queries leaking around AdGuard. If your ISP assigns IPv6 and the router's DHCPv6 configuration doesn't also advertise AdGuard's IPv6 resolver addresses, devices will use ISP-provided DNS for all IPv6 queries and bypass your blocking entirely. Add 2a10:50c0::ad1:ff and 2a10:50c0::ad2:ff to your router's DHCPv6 or RDNSS configuration alongside the IPv4 entries.
2026 Notes: DNSSEC, DoQ, and ECH
AdGuard's public resolvers validate DNSSEC by default. If a domain has a broken DNSSEC chain, AdGuard returns SERVFAIL rather than silently serving potentially poisoned records — this is correct behaviour, not a misconfiguration on AdGuard's side. If you're seeing unexpected SERVFAIL responses for a specific domain, check its DNSSEC chain with a dedicated DNSSEC debugger before adjusting your DNS settings.
DNS over QUIC (DoQ) is production-stable on AdGuard DNS and supported in AdGuard Home 0.107 and later. It offers lower latency than DoT by eliminating TCP handshake overhead and handles lossy connections better. Android doesn't support DoQ natively yet, but AdGuard's own Android app does. If you're running AdGuard Home as a local resolver, enabling DoQ as the upstream transport to AdGuard's public servers is a meaningful latency improvement in 2026.
Encrypted Client Hello (ECH) is increasingly deployed alongside DoH. When a browser uses DoH and ECH together, the TLS SNI in handshakes is also encrypted, closing a significant privacy gap that plain DoH leaves open. AdGuard's resolvers support ECH. For maximum privacy on desktop: use the DoH profile on macOS or the Windows DoH client, and keep Chrome and Firefox updated — both now negotiate ECH when the upstream server advertises it.
For a thorough explanation of how DNS resolution works and why encrypted transports matter for security, the Cloudflare DNS learning guide is a reliable reference.
Preventing Configuration Drift
The most common reason AdGuard DNS silently stops working: ISPs push new resolver addresses via DHCP during modem replacements or firmware updates, and routers set to Obtain DNS automatically revert without any notification. Prevent this by:
- Setting WAN DNS to static/manual on the router — never automatic from the ISP
- If using AdGuard Home, specifying upstream resolvers as static entries rather than relying on ISP DHCP to supply them
- Running a quick monthly check: dig +short whoami.adguard-dns.com should return an AdGuard IP, not your ISP's
- On Android, re-checking Private DNS after major OS updates — some OEM update processes have been known to reset network settings to defaults
- On iOS, confirming the DNS profile is still installed after major iOS upgrades via Settings > General > VPN & Device Management