If you're a Shaw (now Rogers) customer in western Canada and sites aren't loading, you're seeing DNS_PROBE_FINISHED_NXDOMAIN errors, or resolution feels sluggish on a fast connection, the root cause is almost always DNS. Shaw pushes its own resolver addresses to your modem via DHCP, but those servers can go down, get bypassed by a misconfigured router, or get silently overridden at the device level. This article covers the exact IP addresses, how to set them manually on every platform, and how to diagnose and fix each failure mode.

Shaw DNS Server IP Addresses

Shaw Communications — now operating under Rogers after the 2023 merger — provides the following DNS servers for residential customers across BC, Alberta, Saskatchewan, and Manitoba:

  • Primary DNS: 24.222.0.1
  • Secondary DNS: 24.222.0.2

Shaw delivers these addresses to your gateway via DHCP Option 6. As long as your router obtains DNS automatically, your devices use these resolvers. Both IPs have been stable for years and remain active post-merger. Some older Hitron gateways also show 24.66.0.1 as a regional fallback — skip it when configuring manually; it's slower than the primary pair.

💡 Not sure if Shaw's DNS is responding from your location? The DNS Propagation Checker queries from multiple global vantage points so you can confirm whether 24.222.0.1 is resolving correctly right now.

How Shaw Assigns DNS to Your Devices

Shaw uses DHCP Option 6 to deliver DNS addresses to your gateway. Your gateway then either uses those resolvers directly or forwards them to LAN devices via its own DHCP server. This two-layer delegation is where most problems hide. Isolate which layer is broken before touching anything:

  1. Shaw's resolver is down or slow — 24.222.0.1 isn't responding or returns SERVFAIL.
  2. Your router isn't forwarding DNS correctly — it received Shaw's addresses but is using a stale hardcoded IP or its own recursive resolver.
  3. Your device is overriding the router — a manually set DNS on your PC or phone points somewhere unreachable.

Verifying Shaw DNS from the Command Line

Test Shaw's resolvers directly before touching any settings. This immediately tells you whether the problem is upstream or local.

dig (Linux, macOS, WSL)

dig @24.222.0.1 google.com A # Healthy: status: NOERROR with an ANSWER SECTION # Query time over 150ms = congestion or regional outage # SERVFAIL or timeout = Shaw's resolver is the problem

nslookup (Windows, macOS, Linux)

nslookup google.com 24.222.0.1 # Healthy output: # Server: 24.222.0.1 # Non-authoritative answer: # Name: google.com # Address: 142.250.x.x

resolvectl (Linux with systemd-resolved)

resolvectl query google.com resolvectl status # shows DNS server per interface

If dig @24.222.0.1 google.com times out, Shaw's upstream resolver is the issue — jump to the alternatives section. If it responds correctly but browsing fails, the problem is in your router, device cache, or a local hosts file override.

Fixing DNS on Your Shaw Gateway

Shaw supplies residential customers with Hitron gateways (CGNM-2250, CDA3-35) or Arris BlueCurve gateways (XB6, XB7).

Hitron CGNM-2250 and CDA3 Series

  1. Navigate to 192.168.0.1 — the Hitron default admin IP.
  2. Log in with credentials from the label — usually cusadmin / password or admin / password.
  3. Go to Basic → WAN.
  4. Under DNS Server: verify Auto is set, or enter 24.222.0.1 / 24.222.0.2 manually. Remove any stale third-party address.
  5. Click Apply.

Arris XB6 and XB7 (Shaw BlueCurve Gateway)

  1. Navigate to 10.0.0.1 — BlueCurve gateways use this IP, not 192.168.0.1.
  2. Log in with credentials printed on the device.
  3. Go to Connection → DNS.
  4. Set Primary to 24.222.0.1, Secondary to 24.222.0.2, or leave both Automatic.
  5. Click Save Settings and reboot.

Third-Party Router in Bridge Mode

Configure DNS on the third-party device, not the Shaw modem:

  • Asus: asusrouter.com → Advanced Settings → WAN → Internet Connection → DNS Server 1/2
  • TP-Link Archer: tplinkwifi.net → Advanced → Network → Internet → DNS Address (Manual)
  • Netgear: routerlogin.net → Internet → Internet Setup → DNS Addresses
  • Linksys: linksyssmartwifi.com → Router Settings → Connectivity → Internet Settings → DNS Manual
  • Netgear Orbi: orbilogin.com → Internet → Internet Setup → DNS. Eero: app → Settings → Network Settings → DNS.

OpenWrt and DD-WRT

On OpenWrt, edit the WAN stanza of /etc/config/network:

config interface 'wan' option dns '24.222.0.1 24.222.0.2'

Run service network restart. DD-WRT: Setup → Basic Setup → Network Address Server Settings → Static DNS 1 and 2.

Setting Shaw DNS on Windows

  1. Settings → Network & Internet → Ethernet (or Wi-Fi).
  2. Click your connection → Edit next to DNS server assignment.
  3. Switch to Manual. Under IPv4: Preferred = 24.222.0.1, Alternate = 24.222.0.2.
  4. Save, then flush in an elevated Command Prompt:
ipconfig /flushdns

Windows 11 24H2 added per-adapter DNS-over-HTTPS in the GUI. Shaw's resolvers do not support DoH — leave the encryption dropdown set to Off. To get encrypted DNS, switch to Cloudflare (1.1.1.1) or Google (8.8.8.8) and enable DoH against those addresses instead.

Setting Shaw DNS on macOS

  1. System Settings → Network → click your connection → Details → DNS tab.
  2. Remove existing entries. Add 24.222.0.1 then 24.222.0.2.
  3. Click OK → Apply, then flush cache:
sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder

Setting Shaw DNS on Linux

NetworkManager (Ubuntu, Fedora, most desktop distros) — replace connection name with output of nmcli con show:

nmcli con mod "Wired connection 1" ipv4.dns "24.222.0.1 24.222.0.2" nmcli con mod "Wired connection 1" ipv4.ignore-auto-dns yes nmcli con up "Wired connection 1"

For systemd-resolved, add to /etc/systemd/resolved.conf:

[Resolve] DNS=24.222.0.1 24.222.0.2 FallbackDNS=1.1.1.1 8.8.8.8

Restart: sudo systemctl restart systemd-resolved. Verify with resolvectl status.

Setting Shaw DNS on iOS and Android

iOS

  1. Settings → Wi-Fi → tap (i) next to your network → Configure DNS → Manual.
  2. Delete existing servers. Add 24.222.0.1 then 24.222.0.2. Tap Save.

iCloud Private Relay (iOS 15+) bypasses all local DNS settings. Disable it under Settings → [Your Name] → iCloud → Private Relay if you need Shaw's resolver specifically.

Android (Stock 9+ and Samsung One UI)

  1. Settings → Network & Internet → Internet → tap your network → pencil icon → Advanced options.
  2. Change IP settings to Static. Set DNS 1 = 24.222.0.1, DNS 2 = 24.222.0.2. Save.

Samsung One UI: Settings → Connections → Wi-Fi → long-press network → Manage network settings → Show advanced options. On Android 9+, a system-wide Private DNS at Settings → Network & Internet → Private DNS overrides per-network DNS entries — clear it if it points to an unreachable DoT server.

Confirming the Fix

After any DNS change, use the DNS Lookup tool to confirm correct A records are returned for a domain you were having trouble with. If lookup succeeds but browsing still fails, the problem has shifted downstream: TLS, firewall, or the origin server.

dig +short google.com ping google.com # confirms routing is intact, not just DNS

Shaw Internet Security and DNS Filtering

Shaw (Rogers) sells an Internet Security add-on that performs DNS-layer filtering of malware domains, phishing sites, and adult content. If subscribed, blocked domains return a redirect to a Shaw block page rather than a true NXDOMAIN. Symptoms:

  • Domain resolves on LTE or Google DNS but fails on Shaw
  • dig @24.222.0.1 returns Shaw's block-page IP rather than NXDOMAIN
  • HTTPS sites show a TLS certificate error for a Shaw domain, not the target

Fix: disable Internet Security in the Shaw/Rogers MyAccount portal, or override DNS at the router with an unfiltered resolver like 1.1.1.1.

When to Switch Away from Shaw DNS

Shaw's resolvers handle normal traffic reliably but have documented regional outages and slow during evening peak hours. According to Cloudflare's DNS documentation, resolver latency adds directly to perceived page load time — a 50ms increase is measurable even on fast connections.

Best alternatives for Shaw customers in Canada:

  • Cloudflare: 1.1.1.1 / 1.0.0.1 — fastest in most Canadian cities; supports DoH and DoT
  • Google Public DNS: 8.8.8.8 / 8.8.4.4 — highly reliable; DoH at dns.google
  • OpenDNS: 208.67.222.222 / 208.67.220.220 — built-in content filtering

Setting any of these at router level overrides Shaw DNS for all devices. Shaw Go WiFi portal and some Shaw TV endpoints are optimized for Shaw's resolver — this rarely breaks in practice, but be aware.

Common Misdiagnoses

  • Browser DNS cache: Flush Chrome at chrome://net-internals/#dns; Firefox at about:networking#dns. Failures that disappear in a private window are cache issues.
  • IPv6 DNS mismatch: An empty IPv6 DNS with a working IPv4 DNS causes roughly half your lookups to fail as the OS rotates between address families. Check your IPv6 DNS assignment separately.
  • DNSSEC validation failure: Shaw validates DNSSEC. A broken DNSSEC chain returns SERVFAIL from Shaw but resolves fine on non-validating resolvers. Run dig @24.222.0.1 +dnssec problem-domain.com — SERVFAIL with no AD flag means a broken chain on the authoritative side, not a Shaw problem.
  • Hosts file override: Check C:\Windows\System32\drivers\etc\hosts (Windows) or /etc/hosts (Linux/macOS) for stale entries.
  • VPN DNS interference: A VPN with leak protection routes DNS through its own resolver. What looks like Shaw failing is the VPN resolver being down — disconnect and retest first.

2026 Update: Rogers Migration, IPv6, and Encrypted DNS

The Rogers-Shaw merger closed April 2023. As of late 2026, legacy Shaw infrastructure still predominantly uses 24.222.0.1 / 24.222.0.2, but Rogers is re-provisioning gateways in phases. If your automatic DNS shifted after a gateway swap, check what's actually being handed out:

ipconfig /all # Windows: DNS Servers line under your adapter resolvectl status # Linux: per-interface assignments scutil --dns # macOS: all active resolvers

Customers in recently upgraded areas may receive Rogers residential DNS in the 96.51.0.0/16 range. Both work — if latency changed, benchmark both with dig and compare query times before assuming a problem.

Neither Shaw nor Rogers currently publishes a public DoH or DoT endpoint for residential resolvers. If encrypted DNS is required, switch to a third-party provider. Windows 11 24H2 and macOS Sequoia can enforce DoH in some configurations — a resolver that doesn't support the protocol silently fails even though port-53 DNS works fine. If an OS upgrade broke your DNS, check whether the system tried to promote your Shaw resolver to DoH automatically.

For dual-stack connections: Rogers is expanding IPv6 on legacy Shaw nodes through 2025–2026. If your gateway was recently replaced and you see intermittent failures every few lookups, the most common cause is an empty IPv6 DNS field in DHCPv6 config. IPv6-capable clients attempt AAAA lookups via the empty IPv6 path, time out, then fall back to IPv4 — adding several seconds to every cold lookup. Confirm an IPv6 DNS address is populated alongside the IPv4 entry in your gateway's WAN settings.