NextDNS is a configurable encrypted DNS resolver that filters malware domains, trackers, and ads before they reach your devices — but only if you wire it up correctly. A misconfigured deployment means either unencrypted queries leaking past your ISP or the blocklists never firing at all. This guide covers every major platform in 2026 order of priority: router-first to protect every device at once, then per-device for cases where you need granular profiles or you are on a network you do not control.

What NextDNS Does and What It Does Not

NextDNS sits between your devices and the root DNS infrastructure. When a device asks for the IP of a tracking domain, NextDNS checks that name against your enabled blocklists and either resolves it normally or returns NXDOMAIN. It supports DNS-over-HTTPS (DoH), DNS-over-TLS (DoT), and DNS-over-QUIC (DoQ) — all encrypted transports that prevent ISP snooping and man-in-the-middle interception of your DNS queries.

What it does not do: it cannot inspect HTTPS connection content, block arbitrary IPs, or stop malware that uses hardcoded IP addresses and bypasses DNS entirely. It also does not replace a firewall. Think of it as the first layer of defense, not the only one.

The free plan covers 300,000 queries per month — enough for a household with moderate browsing. Paid plans ($1.99/month) remove the cap and add extended analytics retention. The free tier will simply stop filtering after the cap is hit, silently falling back to normal resolution — a common surprise for users who forget to check usage.

Step 1: Create Your Account and Profile

Sign up at nextdns.io. After login, the Setup tab shows your profile ID — a six-character alphanumeric string like abc123. Every configuration below uses this ID. Keep it handy.

Before touching any device, configure the profile itself:

  1. Security tab: Enable Threat Intelligence Feeds, Google Safe Browsing, Cryptojacking Protection, DNS Rebinding Protection, and IDN Homograph Attacks Protection. These are high-value toggles with minimal false-positive risk on normal browsing.
  2. Privacy tab: Add blocklists. The most effective 2026 combination is NextDNS Ads & Trackers Blocklist plus OISD. Avoid stacking 15 lists — overlapping lists slow NXDOMAIN lookups and generate false positives on shared CDNs.
  3. Parental Control tab: Skip on office or personal dev setups. Enabling SafeSearch on a developer machine will break API calls that pass through Google infrastructure.
  4. Settings tab: Enable Log DNS queries for at least 30 days while tuning your blocklists. Enable Block Bypass Methods to prevent DoH-capable browsers and apps from routing around your filters entirely.

Step 2: Router-Level Setup

Router configuration is the highest-leverage option — one change covers every device on the network including smart TVs, IoT sensors, and guests. The method varies significantly by firmware.

ASUS Routers (AsusWRT and Merlin)

Navigate to asusrouter.com or 192.168.1.1, then Advanced Settings → WAN → Internet Connection. Scroll to WAN DNS Setting. Disable automatic DNS and enter the two IPv4 addresses shown on your NextDNS Setup → Routers page. For encrypted DNS, go to Advanced Settings → WAN → DNS Privacy Protocol, select DNS-over-TLS (DoT), and set the resolver hostname to [your-profile-id].dns.nextdns.io on port 853. Merlin firmware adds a Strict mode option — use it if you want guaranteed encryption rather than a plaintext fallback.

TP-Link Routers (Archer Series)

Log in at tplinkwifi.net or 192.168.0.1. Path: Advanced → Network → Internet → DNS. Uncheck Get DNS server automatically and enter your NextDNS IPv4 addresses. TP-Link stock firmware as of 2025–2026 does not support DoT natively on Archer models. For encrypted DNS on TP-Link hardware, either flash OpenWrt or run the NextDNS CLI on a Raspberry Pi as a local resolver — see the Linux section below.

Netgear Orbi and Nighthawk

Log in at orbilogin.com or 192.168.1.1. Path: Advanced → Setup → Internet Setup → Domain Name Server (DNS) Address. Choose Use These DNS Servers and enter both NextDNS IPv4 addresses. Orbi firmware on RBK863S and newer supports DoT under Advanced → Security → DNS over TLS — enter [profile-id].dns.nextdns.io as the hostname.

Linksys Velop and Smart WiFi

Log in at linksyssmartwifi.com. Path: Connectivity → Internet Settings → IPv4 → DNS. Manual DNS entry only — no DoT support in stock Linksys firmware. For encryption, run the NextDNS CLI locally and point your router's DHCP to that machine's IP as the DNS server.

OpenWrt

Install the NextDNS CLI directly on OpenWrt — it handles DoH natively and integrates cleanly with the routing table:

opkg update opkg install nextdns nextdns install nextdns config set profile=[your-profile-id] nextdns config set report-client-info true nextdns start nextdns status

The CLI rewrites /etc/resolv.conf and sets up a local DoH proxy on 127.0.0.1:53. Enabling report-client-info maps per-device hostnames in your NextDNS logs — useful for diagnosing which device is generating blocked requests.

DD-WRT

Go to Setup → Basic Setup → Network Address Server Settings (DHCP) and enter your NextDNS IPv4 addresses as Static DNS 1 and 2. For DoT, go to Services → Services → DNSMasq → Additional DNSMasq Options and add: server=45.90.28.0@853#[profile-id].dns.nextdns.io. Restart dnsmasq after saving.

💡 After updating DNS at the router, devices should route through NextDNS within 60 seconds. Use our DNS Propagation Checker to confirm your domain resolves from NextDNS infrastructure before assuming the router config is live.

Step 3: Windows 11

Windows 11 supports DoH natively. Path: Settings → Network & Internet → [your adapter] → DNS server assignment → Edit → Manual. Toggle IPv4 on, enter your NextDNS profile IPv4 in Preferred DNS, and set DNS over HTTPS to On (automatic template). Windows auto-detects the DoH endpoint because NextDNS is on Microsoft's registered DoH-provider list.

For the NextDNS CLI with richer profile analytics on Windows:

winget install nextdns nextdns install --profile=[your-profile-id] --report-client-info nextdns start

Verify in PowerShell:

Resolve-DnsName -Name test.nextdns.io -Type TXT # Should return your profile ID if active

Common Windows-specific issue: Group Policy in domain-joined environments overrides manual DNS settings. Check gpedit.msc → Computer Configuration → Administrative Templates → Network → DNS Client for conflicting policies before assuming the GUI setting is in effect. If policy is the problem, the fix belongs in GPO, not the adapter settings.

Step 4: macOS (Ventura, Sonoma, Sequoia)

macOS does not support DoH natively through System Settings — you need either a mobileconfig profile or the NextDNS CLI.

Option A — mobileconfig (fastest): Log in to nextdns.io, go to Setup → Apple, and download the profile for your profile ID. Double-click it in Finder, then go to System Settings → General → VPN & Device Management to install it. This enforces DoH system-wide across all apps.

Option B — CLI (recommended for always-on use):

brew install nextdns/tap/nextdns sudo nextdns install --profile=[your-profile-id] --report-client-info sudo nextdns start nextdns status

The CLI runs as a LaunchDaemon and survives reboots. Verify:

dig txt test.nextdns.io # Look for "You are using NextDNS." and your profile ID in the answer section

macOS-specific issue: VPNs with split-tunnel configurations often override system DNS with their own resolver. Check System Settings → VPN → [your VPN] → DNS and confirm it is not silently pushing 8.8.8.8 or a corporate resolver over your NextDNS config.

Step 5: Linux

The right approach depends on your init system and resolver stack. Ubuntu 22.04+, Debian 12+, and Fedora 38+ all use systemd-resolved by default.

systemd-resolved

sudo mkdir -p /etc/systemd/resolved.conf.d/ sudo tee /etc/systemd/resolved.conf.d/nextdns.conf << 'EOF' [Resolve] DNS=45.90.28.0#[profile-id].dns.nextdns.io FallbackDNS= DNSSEC=yes DNSOverTLS=yes EOF sudo systemctl restart systemd-resolved resolvectl status

Setting FallbackDNS= empty is intentional — it prevents systemd-resolved from silently falling back to your ISP's resolver when NextDNS is temporarily unreachable. If uptime matters more than guaranteed filtering, add a fallback; if filtering integrity matters more, leave it blank.

NextDNS CLI on Linux

sh -c "$(curl -sL https://nextdns.io/install)" nextdns config set profile=[your-profile-id] nextdns config set report-client-info true nextdns config set cache-size 10MB nextdns start

The CLI takes over /etc/resolv.conf and proxies queries locally. If NetworkManager is fighting it, drop a config to disable NetworkManager's DNS management:

sudo tee /etc/NetworkManager/conf.d/dns.conf << 'EOF' [main] dns=none EOF sudo systemctl restart NetworkManager

Verify on any Linux distro:

dig txt test.nextdns.io @127.0.0.1 nslookup -type=txt test.nextdns.io 127.0.0.1
💡 Not sure which resolver your Linux box is actually querying? Use our DNS Lookup tool to query specific record types and compare results across resolvers — useful when debugging split-DNS or VPN overrides on multi-homed machines.

Step 6: iOS 17 and iOS 18

iOS supports encrypted DNS via configuration profiles. The fastest path: open Safari on your iPhone, navigate to nextdns.io, tap your profile ID, then tap Apple → Download. Go to Settings → General → VPN & Device Management, tap the downloaded profile, and install it. The profile enforces DoH for all apps, including those that normally bypass system DNS.

One iOS-specific conflict: iCloud Private Relay (iCloud+ plans) routes DNS through Apple's infrastructure and overrides your NextDNS profile entirely. If your NextDNS dashboard shows zero iOS queries after setup, check Settings → [your name] → iCloud → Private Relay and disable it, or accept that Private Relay takes priority.

Per-app DNS (iOS 14+) is available via enterprise MDM profiles. For personal setups, the system profile covers everything adequately.

Step 7: Android 14 and Android 15

Android 9 and later includes a built-in Private DNS feature that uses DNS-over-TLS. Path: Settings → Network & Internet → Private DNS → Private DNS provider hostname. Enter:

[your-profile-id].dns.nextdns.io

This applies system-wide across both WiFi and mobile data. Android shows a lock icon in the status bar when Private DNS is active and the connection is verified.

The built-in Private DNS only supports DoT (port 853). For DoH or DoQ, install the NextDNS app from the Play Store — it creates a local VPN tunnel to proxy DNS, similar to how the CLI works on desktop.

Samsung One UI note: on Galaxy devices look under Settings → Connections → More connection settings → Private DNS instead. The option is identical, just buried a level deeper in Samsung's firmware.

Verifying the Full Setup

After configuring any platform, run these checks before assuming it is working:

# Primary verification — should return your profile ID: dig txt test.nextdns.io # Should include: "You are using NextDNS." and "Profile ID: [your-id]" # Windows equivalent: nslookup -type=txt test.nextdns.io # Test a blocked domain — should return NXDOMAIN or 0.0.0.0: dig doubleclick.net

The NextDNS dashboard Logs tab shows every query in near-real-time. If you see no entries appearing after a minute of browsing, DNS is not routing through NextDNS yet. Flush your OS DNS cache and recheck the resolver address:

# Windows: ipconfig /flushdns # macOS: sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder # Linux (systemd-resolved): sudo resolvectl flush-caches # Linux (nscd): sudo systemctl restart nscd

Common Misdiagnoses

  • "NextDNS is not blocking ads" — The browser has its own DoH enabled and is bypassing your system resolver entirely. Disable it: Firefox → Settings → Privacy & Security → Enable DNS over HTTPS → Off. Chrome → Settings → Privacy and security → Security → Use secure DNS → Off. Brave has the same setting under Settings → Privacy and security → Security.
  • "ISP DNS still appears in my logs" — The router is advertising the ISP's DNS via DHCP, overriding per-device settings. Open the router's DHCP configuration and set the advertised DNS server to your NextDNS IPv4 address (or 127.0.0.53 if running the CLI locally on a home server).
  • "It worked for two weeks, then stopped filtering" — The free tier hit the 300,000 query monthly cap. The dashboard Analytics tab shows usage. Upgrade or reduce the number of devices on the profile.
  • "Certain sites became unreachable after setup" — A blocklist is triggering on a shared CDN or delivery domain. Check Logs → Blocked, identify the domain, and allowlist it under the Allowlist tab. OISD occasionally over-blocks subdomain clusters used by legitimate services.
  • "Setup works on WiFi but not mobile data" — Per-device config (iOS profile, Android Private DNS) applies to both. Router config only covers WiFi. For mobile data coverage, the per-device config is mandatory — router DNS never touches cellular traffic.

2026 Notes on IPv6, DoH Ecosystem, and DNSSEC

NextDNS provides both IPv4 and IPv6 resolver addresses. If your ISP delivers native IPv6 (most residential providers do in 2026), you must add the IPv6 addresses from your profile's Setup page alongside the IPv4 ones. Failing to include IPv6 means all AAAA-record queries and any IPv6-only traffic bypass your blocklists entirely — a common and silent gap on dual-stack networks.

DNS-over-QUIC (DoQ) is now supported by NextDNS and exposed in the Android app. QUIC-based DNS reduces latency on high-loss connections such as mobile and satellite links, but it is not yet available in iOS configuration profiles or most router firmware. Desktop CLI users get DoQ automatically when the path supports it.

DNSSEC validation: enable it under Settings → DNSSEC in the NextDNS dashboard. With DNSSEC active, NextDNS validates cryptographic signatures on DNS responses before returning them, protecting against cache poisoning attacks as defined in RFC 4033. The performance overhead is negligible and the protection against response forgery is real.

Encrypted Client Hello (ECH): Firefox and Chrome both ship ECH enabled in 2026. ECH encrypts the TLS SNI field so your ISP cannot see which HTTPS host you are connecting to even when your IP is known. NextDNS resolves the HTTPS record types that ECH bootstrapping requires — no configuration changes needed on your end, but it is worth knowing the DNS layer is keeping pace with the TLS stack.

Preventing Configuration Drift

Once NextDNS is running cleanly, three things cause it to break silently over time:

  1. Router firmware updates that reset DNS to auto-detect. After every firmware update, open the NextDNS Logs tab and confirm queries are still appearing within 60 seconds of browsing.
  2. Browser updates re-enabling DoH after major version releases. Chrome and Edge have re-enabled their own secure DNS after updates before. Audit browser DNS settings after any major version bump.
  3. VPN client installation or updates that push their own resolver and override system DNS. Always check VPN DNS settings immediately after installation or update.

Set a monthly reminder to check nextdns.io → Analytics → Last 30 days. A zero or near-zero query count means your routing has broken. The Logs tab shows the last successful query timestamp — that timestamp is your starting point for diagnosing when the break occurred and which change on that date caused it.