Changing DNS on an Asus router takes about three minutes — but only if you land in the right menu. The ASUSWRT firmware has shuffled its DNS settings across multiple updates, and the 2026 builds add a DNS Privacy Protocol section (DoT/DoH) directly beside the classic DNS fields, which trips up anyone following an older tutorial. This guide covers every current path: WAN-side DNS, LAN DHCP overrides, DoT configuration, IPv6 DNS, ASUSWRT-Merlin extras, and how to confirm the change actually reached every device on your network.

Why Changing DNS at the Router Level Matters

Setting DNS on the router pushes the change to every device simultaneously via DHCP — no per-device configuration on Windows, macOS, iOS, or Android required. Your ISP's default resolver is typically slow, logs queries, and in some regions performs transparent DNS hijacking to redirect blocked or mistyped domains to ad pages. Replacing it with a faster or more privacy-focused resolver affects every connected device in one step.

The two most common reasons people land here:

  • Slow browsing despite fast internet: ISP resolvers often have 40–100 ms lookup latency and weak caching. Cloudflare (1.1.1.1) and Google (8.8.8.8) consistently benchmark under 10 ms from most Canadian and US locations.
  • DNS-level threat blocking: Quad9 (9.9.9.9) blocks malicious domains by default at the DNS layer with no software to install. Cloudflare's 1.1.1.2 adds a similar malware-blocking feed. Both are free.

Accessing the Asus Router Admin Panel

Open a browser on any device connected to your Asus network and go to http://router.asus.com. If that doesn't load, try http://192.168.1.1 — a small number of Asus models default to 192.168.0.1 instead, which is printed on the label on the underside of the router. Log in with your admin credentials. If unchanged from factory defaults, both the username and password are admin, though current ASUSWRT firmware forces a password change during first-time setup.

After logging in you'll see the Network Map or the Quick Internet Setup splash depending on your firmware build. All DNS settings live under the Advanced Settings section in the left navigation sidebar.

💡 After making DNS changes, use the DNS Propagation Checker to confirm which resolver is answering queries for any domain from external vantage points — useful for verifying the change is visible beyond your LAN.

Changing WAN DNS on ASUSWRT

The WAN DNS setting configures which resolvers the router uses for its own lookups and, by default, passes to LAN devices through DHCP. This is the primary field most guides refer to.

  1. In the left sidebar, click Advanced Settings → WAN.
  2. Select the Internet Connection tab if it is not already active.
  3. Scroll down to the WAN DNS Setting section.
  4. Set Connect to DNS Server Automatically to No.
  5. Enter your preferred addresses in DNS Server 1 and DNS Server 2.
  6. Click Apply.

Reliable resolver pairs to use:

  • Cloudflare (privacy-focused): 1.1.1.1 / 1.0.0.1
  • Google Public DNS: 8.8.8.8 / 8.8.4.4
  • Quad9 (malware-blocking): 9.9.9.9 / 149.112.112.112
  • Cloudflare malware-blocking: 1.1.1.2 / 1.0.0.2
  • OpenDNS: 208.67.222.222 / 208.67.220.220

After clicking Apply the router briefly renegotiates the WAN connection. DHCP clients will receive the new resolver addresses on their next lease renewal — or immediately if you force a renewal (covered in the verification section below).

The LAN DHCP DNS Override — the Field Most People Miss

There is a second DNS field that silently overrides the WAN DNS for all DHCP clients: the LAN DHCP DNS setting. If any IP address is typed there, it takes priority over whatever you set in WAN DNS. This is intentional — it lets you serve different resolvers to LAN devices than the router uses for itself — but it is the leading cause of "I changed WAN DNS but devices still use the old resolver" complaints.

  1. Go to Advanced Settings → LAN.
  2. Click the DHCP Server tab.
  3. Find DNS Server 1 and DNS Server 2 under the DHCP settings section.
  4. If these fields contain IP addresses, they will be pushed to devices instead of the WAN DNS. Either clear them completely (leaving blank inherits from WAN DNS) or set them explicitly to your chosen resolvers.
  5. Click Apply.
💡 Run a quick query against your new resolver using the DNS Lookup tool to confirm which nameserver is actually answering — especially useful when troubleshooting whether the LAN DHCP DNS field is overriding your WAN setting.

DNS-over-TLS and DNS Privacy Protocol (2026 ASUSWRT)

Starting with ASUSWRT firmware 3.0.0.4.388, Asus added a DNS Privacy Protocol option directly in the WAN settings. The 2026 builds have matured this feature to the point it is reliable for home and small-office use. Enabling it encrypts all DNS queries between the router and the upstream resolver, preventing ISP-level snooping on the DNS layer even when the underlying IP packets are visible.

DNS-over-TLS (DoT) uses port 853. DNS-over-HTTPS (DoH) uses port 443 and blends in with regular HTTPS traffic, making it harder to intercept or block. The ASUSWRT GUI currently implements DoT natively; DoH requires ASUSWRT-Merlin with Entware or a custom dnsmasq setup.

To enable DoT on stock ASUSWRT:

  1. Go to Advanced Settings → WAN → Internet Connection.
  2. Set Connect to DNS Server Automatically to No and enter your DNS IPs as described above.
  3. Scroll to DNS Privacy Protocol and select DNS-over-TLS (DoT) from the dropdown.
  4. In the DNS-over-TLS Profile List, click the + icon to add a profile.
  5. Enter the resolver details. For Cloudflare: IP 1.1.1.1, TLS Port 853, TLS Hostname cloudflare-dns.com. For Google: IP 8.8.8.8, Port 853, Hostname dns.google. For Quad9: IP 9.9.9.9, Port 853, Hostname dns.quad9.net.
  6. Set the Preset to Strict (only resolve when encryption succeeds) or Opportunistic (falls back to plaintext if DoT fails).
  7. Click OK then Apply.

Strict mode is preferable for privacy. Opportunistic is safer for reliability — some ISPs block port 853 outbound, and Opportunistic ensures DNS still resolves even if DoT is blocked. Start with Opportunistic, verify it's working, then switch to Strict if port 853 is unobstructed.

ASUSWRT-Merlin Firmware DNS Settings

ASUSWRT-Merlin is a popular third-party build based on Asus's own code with additional features. The standard DNS change procedure is identical to stock, but Merlin exposes several extras worth knowing:

  • Custom dnsmasq configuration: Under Tools → Other Settings → dnsmasq custom configuration, you can inject raw dnsmasq directives. Adding server=1.1.1.1 on a line here works alongside the GUI fields and survives most firmware updates.
  • DNS Filter: Available at Advanced Settings → LAN → DNS Filter. This forces specific devices — or the entire LAN — to use a particular resolver regardless of any static DNS configured on the device itself. Useful for locking down smart TVs or IoT devices that hardcode 8.8.8.8.
  • Stubby for DoH: On Merlin with Entware installed, you can run Stubby as a local DoT forwarder listening on 127.0.0.1:5453, then point dnsmasq at that local address. This gives finer-grained control than the built-in DoT GUI and supports DoH as well.

Verifying the DNS Change Worked

Never assume the change took effect. Verify it explicitly on an affected device after forcing a DHCP lease renewal.

Forcing a DHCP Lease Renewal

  • Windows: Open Command Prompt as administrator and run ipconfig /release then ipconfig /renew
  • macOS: System Settings → Network → select your Wi-Fi adapter → Details → TCP/IP → Renew DHCP Lease
  • Linux: sudo dhclient -r && sudo dhclient
  • iOS: Settings → Wi-Fi → tap the (i) next to your network → Renew Lease
  • Android: Forget the network and reconnect, or toggle Wi-Fi off and on

Windows Verification

ipconfig /flushdns ipconfig /all nslookup google.com

In the ipconfig /all output, find the DNS Servers line under your active network adapter. It should show your configured addresses. The nslookup output will show which server actually answered.

macOS and Linux Verification

dig google.com +short dig google.com +stats | grep SERVER

The SERVER line in dig output shows the resolver IP that answered. On Linux with systemd-resolved, also run:

resolvectl status

This shows per-interface DNS servers and confirms the new addresses are active on the correct interface.

Router-Level Verification via SSH

If SSH is enabled on the router (under Administration → System → Enable SSH), connect and run:

nslookup google.com 127.0.0.1 cat /etc/resolv.conf

The resolv.conf on the router itself should reflect your configured servers. If it still shows ISP addresses, the WAN DNS change didn't save correctly — click Apply again and look for any firmware prompts requiring a reconnect.

IPv6 DNS — the Hidden Gap in 2026

In 2026, a significant number of Canadian and US ISPs assign IPv6 addresses by default. IPv6 DNS is configured separately in ASUSWRT, and skipping it means devices use ISP-provided DNS for all AAAA record lookups even when IPv4 A record lookups go through your chosen resolver. This split behavior is the source of many "DNS change didn't fully work" reports.

  1. Go to Advanced Settings → IPv6.
  2. If IPv6 is active, scroll down to the DNS Setting subsection.
  3. Set Connect to DNS Server Automatically to No.
  4. Enter IPv6 resolver addresses:
    • Cloudflare: 2606:4700:4700::1111 / 2606:4700:4700::1001
    • Google: 2001:4860:4860::8888 / 2001:4860:4860::8844
    • Quad9: 2620:fe::fe / 2620:fe::9
  5. Click Apply.

Common Misdiagnoses

Several things look like a failed DNS change but have a different root cause:

  • Browser DNS cache: Chrome, Firefox, and Edge cache DNS records independently of the OS. After a router DNS change, clear the browser's own DNS cache. In Chrome, navigate to chrome://net-internals/#dns and click Clear host cache.
  • Hardcoded device DNS: A device with a manually configured static DNS (e.g., 8.8.8.8 set in Windows adapter settings) ignores DHCP-provided DNS entirely. Check per-adapter settings on any device that isn't picking up the new resolver.
  • ISP DNS hijacking: Some ISPs intercept all outbound UDP/TCP traffic on port 53 and redirect it to their own resolver regardless of what you configure. If nslookup consistently returns ISP servers, this is likely the cause. Enabling DoT (port 853) or DoH (port 443) bypasses this hijacking since those transports can't be transparently redirected the same way.
  • LAN DHCP DNS field not cleared: As described above, the LAN DHCP DNS field silently overrides WAN DNS for client devices. This is the most common cause of WAN DNS changes that appear to have no effect.
  • VPN client DNS push: If the router runs an OpenVPN or WireGuard client, the tunnel commonly pushes its own DNS servers. Check under VPN → VPN Client → DNS mode and set it to Exclusive or Disabled if you want router DNS to apply.

Preventing DNS Settings from Reverting

Asus routers can silently revert DNS settings under a few conditions:

  • Automatic firmware updates: If Administration → Firmware Upgrade → Automatic Firmware Upgrade is on, a major update can reset WAN DNS to automatic. After any firmware update, recheck WAN DNS and re-enter your addresses.
  • Factory reset: Any full factory reset wipes DNS configuration. Export a config backup before performing one: Administration → Restore/Save/Upload Setting → Save Setting. Restoring this file after a reset brings all settings back in one step.
  • ISP DHCP overriding DNS: If Connect to DNS Server Automatically ever gets re-enabled, the ISP DHCP will supply DNS again. Always set it explicitly to No and treat it as a checklist item after any router reconfiguration.

For a deeper look at how resolver behavior is defined at the protocol level, the original DNS specification (RFC 1035) covers the query and response format that ASUSWRT's dnsmasq implementation follows.

2026 Notes: DoH in Browsers, DNSSEC, and Expanded Threat Feeds

A few developments that are particularly relevant right now:

  • Browser-level DoH bypasses router DNS: Chrome, Firefox, and Edge enable DoH by default for many users in 2026, meaning the browser queries Cloudflare or Google's HTTPS endpoints directly — completely bypassing your router's DNS configuration. If consistent resolver control matters, disable per-browser DoH in browser settings (Firefox: Settings → Privacy & Security → DNS over HTTPS → Off; Chrome: Settings → Privacy and security → Security → Use secure DNS → Off), or ensure your router is already using the same resolver so the bypass is harmless.
  • DNSSEC validation in dnsmasq: Newer ASUSWRT firmware supports DNSSEC validation. Enable it under Advanced Settings → LAN → DHCP Server → Enable DNSSEC support. Cloudflare, Google, and Quad9 all sign their responses and support validation.
  • Expanded malware feeds: Quad9 and Cloudflare's 1.1.1.2 have broadened their threat intelligence in 2026 to cover AI-generated lookalike domains and phishing infrastructure that rotates rapidly. If you are using 1.1.1.1 or 8.8.8.8 purely for speed and want threat blocking added, switching DNS Server 1 to 9.9.9.9 or 1.1.1.2 requires only a single field change in the WAN DNS Setting panel.