Netgear Orbi ships pointing every device on your network to your ISP's resolver — typically the slowest, least private option available. Switching to Cloudflare (1.1.1.1) or Google (8.8.8.8) takes under five minutes, and because Orbi pushes the change via DHCP, one update at the base unit covers your entire mesh automatically. This guide walks through the exact admin panel paths, the two DNS fields you must set (most walkthroughs miss one of them), and how to verify the change actually took effect.
Why Change DNS on Orbi?
ISP resolvers are the default but rarely the best choice. Independent latency benchmarks consistently put Cloudflare and Google DNS 20–80ms faster than major ISP resolvers for cold first-lookup queries. Beyond speed, ISP resolvers log every query and, in some regions, redirect NXDOMAIN responses to ad-laden search pages — a practice called DNS hijacking. Some ISPs also use DNS to enforce content filters or assist with traffic shaping. Changing DNS at the Orbi base unit means every connected device — phones, smart TVs, laptops, IoT gear on every band — gets the benefit without touching each one individually. Satellites inherit the setting automatically; they are access points, not independent routers.
Before You Start
- Admin credentials: username admin, password printed on the label stuck to the base unit (factory default is password if never changed)
- A device on the main Orbi network — not a guest SSID, which cannot reach the admin panel
- Your chosen DNS addresses — pick a primary and secondary from the options below
- 30–60 seconds of tolerance — saving the settings triggers a brief router restart
Common DNS pairs worth considering in 2026:
- Cloudflare: 1.1.1.1 / 1.0.0.1 — fastest in most regions, strong no-log policy
- Google Public DNS: 8.8.8.8 / 8.8.4.4 — most consistent globally
- Quad9: 9.9.9.9 / 149.112.112.112 — malware-blocking with DNSSEC validation
- OpenDNS: 208.67.222.222 / 208.67.220.220 — configurable content filtering via dashboard
Method 1: Orbi Admin Panel (Recommended)
Open a browser on any device connected to the Orbi network and go to orbilogin.com or orbilogin.net. If those hostnames fail — which can happen when Orbi's own DNS is broken — use the direct IP 192.168.1.1. Log in with username admin and your password.
Step 1: Set WAN-Side DNS
This tells the Orbi what to use when the router itself resolves names — firmware update servers, NTP, Netgear cloud features.
- Click the Advanced tab at the top of the page
- In the left sidebar go to Setup > Internet Setup
- Scroll to the Domain Name Server (DNS) Address section near the bottom of the page
- Select the radio button labeled Use These DNS Servers
- Enter your primary DNS in the first field, secondary in the second
- Click Apply
On newer firmware (V3.2.x and above, covering RBK960, RBK863S, and recent RBK760 units), the layout is similar but the DNS section sometimes sits inside a collapsed Advanced Settings accordion at the bottom of the Internet Setup page. Scroll fully before assuming the field is absent.
Step 2: Set LAN-Side DHCP DNS
This is the setting that actually pushes DNS server addresses to your devices. Skipping this step is the single most common reason a device continues using ISP DNS after someone believes they already made the change — the router may use the new resolver for itself while still handing the old one to every client.
- Still under the Advanced tab, go to Advanced Setup > LAN Setup
- Scroll to the Domain Name Server (DNS) Servers section
- Replace the existing entries with your chosen DNS addresses
- Click Apply
The router restarts. Once back online (usually 30–60 seconds), devices will receive the new DNS on their next DHCP lease renewal. To force it immediately without waiting: on Windows run ipconfig /release && ipconfig /renew in an elevated command prompt; on macOS run sudo ipconfig set en0 DHCP (replace en0 with your active interface name from ifconfig); on mobile, toggle Airplane Mode off and on.
Method 2: Orbi App (Limited)
The Orbi app (and the older Nighthawk app used on RBK750 and RBK850 models) handles basic network management but DNS configuration has never been fully surfaced in the mobile UI. As of mid-2026, a handful of advanced settings are gradually appearing in the app for newer SKUs, but for DNS specifically the browser admin panel remains the only reliable path. If orbilogin.com is unreachable from your phone, connect to the main Orbi SSID and navigate directly to 192.168.1.1 in your mobile browser.
Method 3: Custom Firmware (OpenWrt / DD-WRT)
Select older Orbi units — certain RBR50 hardware revisions — can run OpenWrt. On OpenWrt, DNS lives under Network > DHCP and DNS using dnsmasq. Set the DHCP-pushed DNS addresses on the General Settings tab. For the upstream resolver the router itself queries, go to Network > Interfaces > WAN > Advanced Settings > Use custom DNS servers. On DD-WRT, add entries via Services > Services > DNSMasq > Additional DNSMasq Options in the format server=1.1.1.1, one line per server.
Per-Device DNS Override
Sometimes you need one machine to use a different resolver — a work laptop locked to a corporate DNS, a device pointing at a local Pi-hole, or a phone you want to test with Quad9 while the rest of the network stays on Cloudflare. Here is how to override per-platform without touching the router.
Windows 11
- Settings > Network & Internet > Wi-Fi (or Ethernet) > [network name] > Hardware properties
- Under DNS server assignment click Edit
- Switch from Automatic (DHCP) to Manual
- Enable IPv4 and enter preferred and alternate DNS addresses
- Optionally enable DNS over HTTPS and set it to On (automatic template) — works natively with Cloudflare and Google
macOS Sonoma / Sequoia
- System Settings > Network > [interface] > Details > DNS tab
- Click + to add server addresses and remove the DHCP-assigned entry
- Click OK then Apply
Linux (systemd-resolved)
Edit /etc/systemd/resolved.conf and add:
Restart the resolver: sudo systemctl restart systemd-resolved
iOS 16+ / iPadOS
- Settings > Wi-Fi > tap the (i) next to your Orbi SSID
- Tap Configure DNS, switch to Manual
- Tap Add Server and enter your addresses
Android 12+
Android does not support per-network DNS by IP address. The system-wide encrypted option is Private DNS: Settings > Network & Internet > Private DNS > Private DNS provider hostname. Enter 1dot1dot1dot1.cloudflare-dns.com for Cloudflare or dns.google for Google. For IP-based per-network DNS you need either a static IP lease from the router or a third-party VPN-based DNS app.
Verifying With CLI Tools
Never assume the settings took effect — confirm it. Run the following from a terminal after reconnecting:
In nslookup output the Server: line must show your new resolver IP (e.g., 1.1.1.1), not your ISP's address. If the old resolver still appears, the device has not yet renewed its DHCP lease — toggle Wi-Fi off and on to force it.
Use the DNS Lookup tool to query a domain from multiple global vantage points and confirm your Orbi is serving the correct DNS responses to devices across your network, including from outside your LAN.
Common Misdiagnoses
Setting Only WAN DNS and Skipping LAN DNS
The most frequent mistake by far. Internet Setup controls what the router resolves for itself. LAN Setup DHCP DNS controls what gets handed to clients via DHCP option 6. Change only Internet Setup and your router uses the new resolver while every device on the network still gets the old one. Always update both fields.
ISP DHCP Option 6 Override on the WAN Side
Some ISPs inject DNS server addresses in their WAN DHCP offer, which silently overrides your setting if you left Orbi on Get Automatically from ISP. In Internet Setup, confirm the radio button is set to Use These DNS Servers rather than automatic. If Orbi is running in bridge mode or IP passthrough, the upstream modem may be supplying DNS that bypasses Orbi entirely — you'd need to configure the modem instead.
Orbi Running in Access Point Mode
If Orbi is deployed as an access point behind another router, it does not run its own DHCP server. The upstream router controls what DNS clients receive. Make the change on that upstream device, not on the Orbi.
Long DHCP Lease Times
Orbi's default DHCP lease duration is 24 hours. Devices won't see new DNS until their lease expires or is manually renewed. This makes it appear the change failed when it actually worked. Force renewal on each device to confirm immediately.
Stale OS DNS Cache
Even after lease renewal, the OS caches recent records. Flush to see the change immediately: Windows: ipconfig /flushdns; macOS: sudo dscacheutil -flushcache && sudo killall -HUP mDNSResponder; Linux: sudo systemd-resolve --flush-caches.
2026: DoH, DoT, DNSSEC, and IPv6 on Orbi
Orbi firmware does not natively support DNS-over-HTTPS (DoH) or DNS-over-TLS (DoT) at the router level as of late 2026. Queries between your devices and the Orbi base unit travel unencrypted over the LAN, and queries between Orbi and its upstream resolver are likewise unencrypted from the router's perspective. For most households this is an acceptable risk — the LAN is a trusted network segment and the main privacy exposure is the last-mile ISP link, which is eliminated by simply switching away from the ISP resolver.
If encrypted DNS at the router level matters to you, the practical options are:
- AdGuard Home or Pi-hole with encrypted upstream — run on a Raspberry Pi or spare machine; configure a DoH upstream (
https://1.1.1.1/dns-queryorhttps://dns.quad9.net/dns-query); then point Orbi LAN DNS to that machine's static LAN IP - Per-device DoH/DoT — Windows 11, macOS, iOS 14+, Firefox, and Chrome all support encrypted DNS natively without any router changes
- NextDNS — provides a personal DoH endpoint plus lightweight profile apps that configure DoH system-wide on each device
DNSSEC: Quad9 validates DNSSEC by default. If you switch to Quad9 and certain domains suddenly stop resolving, they likely have misconfigured DNSSEC records — test with dig +dnssec example.com to confirm.
IPv6 DNS: If your ISP provides IPv6 connectivity, Orbi has separate IPv6 DNS fields under Advanced > Advanced Setup > IPv6. Cloudflare's IPv6 addresses are 2606:4700:4700::1111 and 2606:4700:4700::1001; Google's are 2001:4860:4860::8888 and 2001:4860:4860::8844. Leaving the IPv6 DNS fields blank causes noticeably slower resolution on dual-stack devices because the router falls back to ISP-supplied DNS for AAAA record queries. Set both IPv4 and IPv6 DNS entries for complete coverage.
For a deeper look at how DNS resolution works end to end — from stub resolver to recursive resolver to authoritative nameserver — Cloudflare's DNS explainer is a thorough reference.
Confirming the Fix Worked
- Run
nslookup example.com— the Server line must show your new DNS IP, not an ISP address - Visit 1.1.1.1/help if using Cloudflare — it confirms whether you are resolving through their network
- If using Quad9 or OpenDNS, attempt to resolve a known malware domain — it should return NXDOMAIN or redirect to a block page rather than resolving
- Benchmark first-lookup latency with
dig google.com +stats | grep timeand compare to your baseline — a 30–60ms improvement is common when moving off a congested ISP resolver
Preventing Reversion After Firmware Updates
Orbi firmware updates occasionally reset Internet Setup back to Get Automatically from ISP and can clear LAN Setup DNS entries. After any automatic firmware update — Orbi updates silently by default — log back into orbilogin.com and verify both the Internet Setup and LAN Setup DNS fields still contain your entries. It takes 30 seconds and prevents the frustration of diagnosing a mysterious slowdown weeks later. Store your DNS settings in a password manager entry alongside the admin credentials so they are trivial to reapply after any reset.