Your Linksys Smart WiFi router ships pointing at your ISP's DNS servers — often slow, sometimes unreliable, and logging every query your household generates. Swapping to Cloudflare (1.1.1.1) or Google (8.8.8.8) takes under five minutes, but the exact admin panel path differs depending on whether you have an EA-series router, a Velop mesh node, or a WRT-series device running stock, OpenWrt, or DD-WRT firmware. This guide covers every variant with the precise steps, CLI commands to confirm the change actually took effect, and the IPv6 and encrypted-DNS angles that matter in 2026.

Why Change DNS at the Router, Not the Device

Changing DNS at the router applies to every device on your network simultaneously — phones, smart TVs, game consoles, and IoT devices that expose no DNS settings at all. A per-device DNS change only covers that one device and resets when it joins a different network.

Common reasons for the change:

  • Speed: ISP resolvers frequently have higher latency than anycast resolvers like Cloudflare (1.1.1.1 / 1.0.0.1), Google (8.8.8.8 / 8.8.4.4), or Quad9 (9.9.9.9 / 149.112.112.112).
  • Reliability: ISP DNS outages are common and often precede broader connectivity failures. Third-party resolvers run redundant global infrastructure.
  • Privacy: ISP resolvers log queries for advertising and, in many jurisdictions, comply with data-retention laws. Cloudflare's 1.1.1.1 commits to no 24-hour-plus query logging.
  • Content filtering: Quad9 (9.9.9.9) blocks known malicious domains via threat-intelligence feeds. Cloudflare's 1.1.1.3 blocks both malware and adult content.
  • DNSSEC validation: Not all ISP resolvers validate DNSSEC signatures. Cloudflare, Google, and Quad9 all do.

The Two DNS Settings on a Linksys Router

Before touching anything, understand that a Linksys router exposes DNS in two separate places — conflating them causes most of the confusion:

  • WAN / Internet DNS: The upstream resolvers the router queries when forwarding lookups from your LAN. This is almost always the setting you want to change.
  • DHCP DNS advertised to clients: The DNS address pushed to LAN devices via DHCP. By default this is the router's own LAN IP (192.168.1.1) — clients query the router, which forwards to the WAN DNS. Changing WAN DNS is sufficient. Overriding the DHCP-advertised DNS bypasses the router's caching layer entirely and is an advanced option most users should skip.

The cleanest approach: set WAN DNS to your preferred resolvers and leave DHCP DNS pointing at the router. All devices benefit from the change without losing the router's local cache.

Which DNS Resolver to Use

Three reliable choices, each with a different emphasis:

  • Cloudflare 1.1.1.1 / 1.0.0.1 — Consistently the fastest globally by independent benchmarks, DNSSEC-validating, strong privacy posture. For malware blocking use 1.1.1.2 / 1.0.0.2; for malware plus adult-content filtering use 1.1.1.3 / 1.0.0.3.
  • Google 8.8.8.8 / 8.8.4.4 — Extremely reliable, fast, and universally reachable. Good for troubleshooting because it almost never goes down. Less privacy-focused than Cloudflare. See the Google Public DNS documentation for technical details on their anycast infrastructure.
  • Quad9 9.9.9.9 / 149.112.112.112 — Non-profit, DNSSEC-validating, blocks malicious domains from 25-plus threat feeds at query time. Good default for households with less technical users.
💡 Before committing to a resolver, test which one responds fastest from your location. Our DNS Propagation Checker lets you query multiple servers and compare response times in real time.

EA-Series and E-Series Routers (Linksys Smart WiFi Firmware)

This covers the EA6350, EA6400, EA7300, EA7500, EA7500v3, EA8300, EA9300, EA9500, and most E-series routers running the Linksys Smart WiFi firmware — recognizable by the dark-blue gradient login screen at linksyssmartwifi.com.

Changing DNS via the Web Interface

  1. Open a browser and navigate to http://linksyssmartwifi.com. If that does not load — common when DNS itself is broken or you are not on the Linksys network — try the direct IP: http://192.168.1.1. Use http, not https; the local admin UI lacks a valid TLS certificate on most firmware builds and browsers will block it.
  2. Enter your router admin password. The default is usually blank or printed on the label on the router's underside.
  3. In the left-side navigation panel, click Connectivity.
  4. At the top of the Connectivity screen, click the Internet Settings tab.
  5. Scroll to the IPv4 section. Locate the DNS Server dropdown — it defaults to Automatic (DHCP).
  6. Change the dropdown to Static. Two input fields appear: DNS 1 and DNS 2.
  7. Enter your primary resolver in DNS 1 (e.g., 1.1.1.1) and your secondary in DNS 2 (e.g., 1.0.0.1).
  8. Click the OK button at the bottom of the panel. A confirmation dialog appears immediately.
  9. Click Yes, Apply. The router applies the change within about 30 seconds without a full reboot. Its internal DNS cache flushes automatically.

Known quirk: If you navigate away from the Connectivity panel before clicking OK, the change is silently discarded. Always wait for the confirmation dialog before closing the tab.

IPv6 DNS (2026 Note)

If your ISP provides IPv6 connectivity, scroll down in the same Internet Settings panel to the IPv6 section and set those resolvers manually too. Leaving IPv6 DNS on automatic while setting IPv4 manually means roughly half your lookups — those using IPv6 transport — still hit the ISP resolver. Cloudflare's IPv6 addresses are 2606:4700:4700::1111 and 2606:4700:4700::1001. Google's are 2001:4860:4860::8888 and 2001:4860:4860::8844. Quad9's are 2620:fe::fe and 2620:fe::9.

Linksys Velop and MX-Series Mesh Systems

Velop nodes (WHW01, WHW03, WHW0302) and MX-series routers (MX5300, MX8500, MX10600) use the Linksys mobile app as the primary configuration interface. The web UI at 192.168.1.1 exists but deliberately exposes limited settings on most Velop and MX firmware — DNS configuration is app-only on these devices unless you are in local admin mode.

Via the Linksys App (iOS and Android)

  1. Open the Linksys app and sign in with your Linksys account credentials.
  2. Tap the WiFi Settings gear icon in the top-right corner of the dashboard.
  3. Tap Advanced Settings.
  4. Tap Internet Settings.
  5. Tap IPv4.
  6. Under DNS Provider, switch from Automatic to Manual.
  7. Enter your primary and secondary DNS addresses.
  8. Tap Save. The app pushes the configuration to the parent node; child nodes pick it up within about 60 seconds.

If you are running Velop in local admin mode with no Linksys cloud account, go to 192.168.1.1, sign in, and follow the same Connectivity → Internet Settings path as the EA-series above.

WRT-Series Routers (WRT1900AC, WRT3200ACM, WRT32X)

WRT routers can run either stock Linksys firmware or third-party firmware. The steps differ significantly.

Stock Linksys WRT Firmware

  1. Go to http://192.168.1.1 and log in.
  2. Click Connectivity in the left navigation.
  3. Click Internet Settings.
  4. Set the DNS Server dropdown to Static, enter your resolvers in DNS 1 and DNS 2, click OK, then Apply — same procedure as the EA-series.

OpenWrt on WRT Routers

OpenWrt uses dnsmasq as the local resolver and forwards upstream queries to whatever WAN DNS you configure. Via LuCI:

  1. Log into LuCI at http://192.168.1.1.
  2. Navigate to Network → Interfaces → WAN → Edit.
  3. Click the Advanced Settings tab.
  4. Uncheck Use DNS servers advertised by peer.
  5. In the Use custom DNS servers field, enter your resolver IPs one per line.
  6. Click Save & Apply.

Via SSH on OpenWrt:

uci set network.wan.peerdns='0' uci add_list network.wan.dns='1.1.1.1' uci add_list network.wan.dns='1.0.0.1' uci commit network /etc/init.d/network restart

For finer control, configure dnsmasq's upstream forwarders directly so they persist independent of the WAN interface:

uci add_list dhcp.@dnsmasq[0].server='1.1.1.1' uci add_list dhcp.@dnsmasq[0].server='1.0.0.1' uci set dhcp.@dnsmasq[0].noresolv='1' uci commit dhcp /etc/init.d/dnsmasq restart

DD-WRT on WRT Routers

  1. Log in to DD-WRT at http://192.168.1.1.
  2. Go to Setup → Basic Setup.
  3. Under Network Address Server Settings (DHCP), find Static DNS 1 and Static DNS 2. Enter your resolvers.
  4. Click Save, then Apply Settings.

If your WAN connection type is PPPoE or Static IP, also check the WAN Connection Type section on the same page — there is a separate DNS field for WAN-side resolution that must also be set manually, otherwise that field reverts to the ISP-provided value on reconnect.

Verify the Change Took Effect

Clicking Save is not confirmation. Run a quick check from a connected device before closing the browser. You can also use the DNS Lookup tool to query a domain through multiple resolvers and compare results instantly without installing anything locally.

Windows

ipconfig /flushdns nslookup google.com nslookup google.com 1.1.1.1

The first nslookup shows which resolver Windows is querying — should still be 192.168.1.1 (the router) if you changed WAN DNS only. The second queries Cloudflare directly as a comparison. Both should return the same A record. To confirm what the router is forwarding to, check the router's WAN Status page — look for the DNS 1 and DNS 2 fields.

macOS

sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder dig google.com scutil --dns | grep nameserver

The scutil output shows the DNS address macOS received via DHCP — expect 192.168.1.1. The dig answer should resolve correctly and quickly. For a definitive upstream check, a DNS leak test site will show which ASN is actually resolving your queries; if you set Cloudflare, you should see Cloudflare ASN 13335.

Linux

resolvectl flush-caches resolvectl status dig google.com dig google.com @1.1.1.1

On systemd-resolved systems, resolvectl status shows the DNS server per interface — expect the router's LAN IP on your primary link. If the direct Cloudflare query is significantly faster than the router-proxied one, the router's DNS cache or upstream connectivity may have a problem worth investigating separately.

Mobile Devices: iOS and Android

After changing router DNS, mobile devices need to renew their DHCP lease. The quickest method: toggle WiFi off and back on, or forget and rejoin the network.

Per-device DNS overrides take precedence. If a device has a manually configured DNS in its WiFi settings — iOS: Settings → WiFi → tap the (i) icon → Configure DNS → Manual; Android: WiFi → long-press the network → Modify network → Advanced → IP settings → Static → DNS 1 — that device-level setting overrides the router's WAN DNS. Clear the per-device override to let the router's setting apply uniformly.

iOS Private DNS profiles: iOS 14 and later supports DNS over HTTPS and DNS over TLS profiles. If a DoH or DoT profile is installed from NextDNS, Cloudflare, or another provider, it overrides everything — including the router — because queries are encrypted to a named resolver endpoint. Check Settings → General → VPN & Device Management for installed DNS profiles before troubleshooting router-level DNS on an iPhone.

Common Misdiagnoses

Several things look like a failed DNS change but are not:

  • Browser DNS cache: Chrome caches DNS independently from the OS. After changing router DNS, flush it at chrome://net-internals/#dns and click Clear host cache. Firefox has a similar cache at about:networking#dns.
  • OS cache not flushed: Windows: ipconfig /flushdns. macOS: sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder. Linux systemd: resolvectl flush-caches. Stale cached answers from the old resolver persist until their TTL expires otherwise.
  • DHCP lease not renewed: The device is still operating under its old DHCP configuration. Windows: ipconfig /release && ipconfig /renew. Linux: sudo dhclient -r && sudo dhclient. Toggling WiFi achieves the same result on any platform.
  • Velop web UI silently discarding saves: On several Velop firmware versions, the 192.168.1.1 interface shows DNS fields but silently discards changes — the app is the authoritative interface. If your web UI change keeps reverting on a Velop or MX device, use the Linksys app instead.
  • ISP DNS hijacking: Some ISPs intercept all outbound DNS queries on port 53 and redirect them to their own resolvers regardless of the destination IP you configured. If a DNS leak test still shows ISP servers after setting Cloudflare, your ISP is hijacking port 53. The fix is encrypted DNS — DoT on port 853 or DoH on port 443 — which cannot be transparently redirected without breaking certificate validation.
  • Firmware update reset DNS: Linksys firmware updates sometimes silently revert DNS to automatic. After any automatic or manual firmware update, re-verify your settings under Connectivity → Internet Settings.

Encrypted DNS in 2026: DoH, DoT, and DNSSEC

Standard DNS over port 53 is unencrypted — anyone on the path between your router and the resolver can read and modify your queries. In 2026 this matters more as ISP-level DNS interception and query logging are documented across multiple regions and carrier tiers.

  • Stock Linksys EA and Velop firmware: No native DNS over HTTPS or DNS over TLS support. To get encrypted DNS on stock firmware, run a local resolver such as Pi-hole with Unbound, or AdGuard Home, configured to forward to Cloudflare or Quad9 over DoT — then point the Linksys router's WAN DNS at that device's LAN IP.
  • OpenWrt: Install the https-dns-proxy package for DoH forwarding, or configure stubby for DoT. Both proxy encrypted queries upstream and serve plain DNS locally — no client-side changes needed on any device.
  • DD-WRT: Encrypted DNS requires DNSCrypt-proxy from the optional packages feed. Not available in all hardware-specific builds; check your build's feature list first.

DNSSEC: Cloudflare, Google, and Quad9 all validate DNSSEC and return SERVFAIL for domains with broken signatures — protecting against DNS spoofing. Stock Linksys dnsmasq does not re-validate DNSSEC locally; it trusts the upstream resolver's AD (Authenticated Data) flag. On OpenWrt, local DNSSEC validation can be enabled in dnsmasq via LuCI under Network → DHCP and DNS → Advanced → Enable DNSSEC, adding a second layer of verification between your LAN and the upstream.

Preventing the Setting From Reverting

Three things cause DNS settings to reset on Linksys routers:

  1. Firmware updates: Linksys firmware updates can reset DNS to automatic without warning. After any firmware update, log into the admin panel and re-verify under Connectivity → Internet Settings before assuming the setting persisted.
  2. Factory reset: A factory reset wipes all custom settings including DNS. Document your resolvers before performing any reset, especially when following support articles that recommend it as a first troubleshooting step.
  3. ISP DHCP override: If the Linksys router's WAN connection is set to Automatic (DHCP), the ISP's DHCP offer can push DNS server addresses that override a manual entry on the next WAN reconnect. Setting the DNS Server dropdown to Static — the step in the walkthrough above — explicitly prevents this. The router ignores DNS addresses in the ISP's DHCP offer once the field is pinned to static.