Starlink's default DNS resolver does its job, but it runs inside a CGNAT stack, carries no DNSSEC validation, and logs every hostname you resolve to SpaceX's infrastructure. Whether you want faster lookups, content filtering via a service like NextDNS, or consistent DNS across a satellite-plus-LTE failover setup, custom DNS on Starlink is fully supported — once you know which method matches your hardware generation and whether you're using Starlink's built-in router or running bypass mode.
What Starlink Uses for DNS by Default
Every Starlink dish ships pre-configured to push 100.64.0.1 as the DNS resolver via DHCP. That address sits inside the RFC 6598 CGNAT shared-address range that Starlink uses for its entire subscriber network. Requests hit SpaceX's recursive resolvers before reaching authoritative nameservers, meaning SpaceX can see every hostname you query, no DNSSEC chain-of-trust is enforced, and you have zero control over caching policy, filtering, or uptime guarantees beyond Starlink's own SLA.
Starlink also assigns a native IPv6 prefix — a /56 from their allocation — and delivers an IPv6 DNS resolver address via Router Advertisement alongside the IPv4 DHCP offer. If you only change your IPv4 DNS and leave IPv6 DNS unconfigured, macOS, Android, and most modern Linux distributions will still query Starlink's IPv6 resolver for AAAA records, bypassing your custom setting entirely. This is the most common reason custom DNS appears to work on Windows but not on other devices.
Three Methods to Override Starlink DNS
Starlink has shipped three hardware generations with different admin surfaces, and the right method depends on your setup:
- Method 1 — Starlink app custom DNS: Gen 2 and Gen 3 rectangular dish owners using the integrated Starlink router can enter custom resolver IPs directly in the app. Fastest path, zero extra hardware, pushes to all LAN devices via DHCP automatically.
- Method 2 — Bypass mode with a third-party router: Disable the Starlink router entirely, connect your own router to the dish's ethernet output, and control DNS from your router's admin panel. More configuration options, works with every router brand, required for full IPv6 DNS control.
- Method 3 — Per-device DNS override: Configure each device's network adapter to ignore DHCP-assigned DNS. No router access needed. Less maintenance overhead but new devices on the network will default to Starlink's resolver unless you configure them individually.
Method 1: Custom DNS via the Starlink App
Available on Gen 2 and Gen 3 hardware running firmware from late 2024 onward. The integrated Starlink router accepts two custom DNS addresses and distributes them to every DHCP client on the network, so no per-device changes are needed.
- Open the Starlink app (iOS or Android) while connected to your Starlink Wi-Fi.
- Tap the hamburger menu (three lines, top-left) then tap Settings.
- Tap Advanced.
- Tap DNS. Two input fields appear: Primary DNS and Secondary DNS.
- Enter your preferred resolver IPs. Common choices: Cloudflare (privacy-first, fast) 1.1.1.1 / 1.0.0.1; Google Public DNS 8.8.8.8 / 8.8.4.4; Quad9 (blocks known malware domains via threat feeds) 9.9.9.9 / 149.112.112.112; NextDNS (custom blocklists, per-device analytics) — use your assigned NextDNS IPs from the NextDNS dashboard.
- Tap Save. The change applies immediately, no reboot required.
The app DNS screen does not expose separate IPv6 DNS fields as of mid-2026 firmware. Clients that resolve over IPv6 will still fall back to Starlink's default IPv6 resolver. For complete IPv6 DNS control, use bypass mode with a third-party router that exposes IPv6 DNS fields, or configure IPv6 DNS at the device level using Method 3 alongside Method 1.
Method 2: Bypass Mode with a Third-Party Router
Bypass mode (Starlink's term for what most vendors call bridge mode or IP passthrough) disables NAT and DHCP on the Starlink router and forwards the public Starlink IP directly to whatever device is connected to the ethernet output. Your router handles all LAN functions including DNS distribution to clients via DHCP.
Enabling Bypass Mode
- Open the Starlink app → Settings → Advanced → Bypass Mode → toggle on.
- Confirm the warning. Starlink Wi-Fi stops broadcasting once bypass mode is active.
- Plug your router's WAN port into the Starlink ethernet adapter — the PoE injector output port on Gen 2, or the integrated ethernet port on Gen 3 with its built-in cable.
- Set your router's WAN connection type to DHCP. Starlink hands a public address to the WAN interface.
If your router's WAN shows a 100.64.x.x address after enabling bypass mode, the dish is still NATting. Power-cycle the dish by unplugging the PoE injector, waiting 30 seconds, and reconnecting. This is a documented Gen 2 firmware quirk that a cold reboot reliably fixes. Confirm the fix:
DNS Settings by Router Brand
Once your router has a public WAN address, set DNS in the admin panel. Use the correct admin URL for your hardware:
- Asus (asusrouter.com or 192.168.1.1): WAN → WAN DNS Setting → uncheck Connect to DNS Server Automatically → enter resolver IPs. For LAN clients: LAN → DHCP Server → DNS Server 1 / DNS Server 2. Asus Merlin firmware also adds DoT under WAN → Internet Connection → DNS Privacy Protocol.
- TP-Link (tplinkwifi.net or 192.168.0.1): Advanced → Network → DHCP Server → Primary DNS / Secondary DNS.
- Netgear (routerlogin.net or 192.168.1.1): Advanced → Setup → Internet Setup → Use These DNS Servers.
- Linksys (linksyssmartwifi.com or 192.168.1.1): Connectivity → Internet Settings → DNS → Manual.
- Eero (app-only): Settings → Network Settings → DNS → Custom DNS.
- Orbi (orbilogin.com or 192.168.1.1): Advanced → Setup → Internet Setup → Use These DNS Servers.
- Ubiquiti UniFi: Networks → [your LAN] → DHCP → DNS Server 1 / DNS Server 2. For the router's own upstream resolver: Internet → your WAN → DNS Server.
- MikroTik (miwifi.com or 192.168.31.1 for Xiaomi; 192.168.88.1 for MikroTik): IP → DNS → Servers field (MikroTik WinBox / WebFig).
OpenWrt and DD-WRT
On OpenWrt running behind Starlink in bypass mode, set DHCP-pushed DNS via LuCI at Network → Interfaces → LAN → Edit → DHCP Server → Advanced Settings → DHCP-Options. Add the option string 6,1.1.1.1,1.0.0.1. For IPv6, also add 6,2606:4700:4700::1111,2606:4700:4700::1001. Via UCI on the command line:
DD-WRT: Setup → Basic Setup → Network Setup → Static DNS 1 / Static DNS 2. Enable Use DNSMasq for DNS to make dnsmasq the authoritative resolver for LAN clients, preventing any upstream resolver leakage.
Method 3: Per-Device DNS Override
No router access required. Override the DNS assignment on each device's network adapter. Changes apply immediately and survive DHCP lease renewals because the OS ignores the DHCP-assigned DNS option when a static resolver is configured at the adapter level.
Windows 11 and Windows 10
- Settings → Network & Internet → Wi-Fi (or Ethernet) → click your network name → click Edit next to DNS server assignment.
- Switch from Automatic (DHCP) to Manual.
- Toggle on IPv4. Enter Preferred DNS and Alternate DNS (for example, 1.1.1.1 and 1.0.0.1).
- Toggle on IPv6. Enter IPv6 resolver addresses: 2606:4700:4700::1111 and 2606:4700:4700::1001 for Cloudflare.
- Save.
Windows 11 adds native DNS over HTTPS. After entering each resolver IP, set the DNS over HTTPS dropdown to On (automatic template) for Cloudflare, Google, or Quad9. This encrypts every DNS query at the OS level regardless of what the router or Starlink does.
macOS (Sequoia / Sonoma)
- System Settings → Network → select your interface (Wi-Fi or Ethernet) → Details → DNS tab.
- Click the + button and add your resolver IPs. Remove the DHCP-assigned entry if you want to force exclusively your resolvers.
- Click OK → Apply.
macOS does not have a built-in DoH/DoT option in system preferences. For encrypted DNS on macOS, install a configuration profile from your DNS provider — Cloudflare, NextDNS, and AdGuard all publish signed profiles that configure encrypted DNS system-wide.
Linux (systemd-resolved)
Ubuntu 20.04+, Fedora 33+, and Debian 12+ all use systemd-resolved by default. Set custom DNS per-interface or system-wide:
iOS (iPhone and iPad)
Settings → Wi-Fi → tap the (i) next to your Starlink network → Configure DNS → Manual → tap Add Server and enter your resolver IPs. Remove the existing automatic entries.
For system-wide encrypted DNS that follows you across all networks, install a signed mobileconfig profile from your DNS provider. Cloudflare's 1.1.1.1 app installs a DoH profile via one tap; NextDNS generates a custom profile per account in their dashboard.
Android
Android 9 and later includes a system-wide Private DNS feature using DNS over TLS. It overrides per-network DNS settings and works regardless of which Wi-Fi or cellular network you're on:
Settings → Network & Internet → Private DNS → Private DNS provider hostname. Enter a DoT hostname: 1dot1dot1dot1.cloudflare-dns.com for Cloudflare, dns.google for Google, or dns.quad9.net for Quad9. Android connects to these resolvers over port 853 with TLS certificate verification. If the DoT connection fails, Android falls back to the network-assigned DNS — set a reliable secondary resolver to avoid gaps.
IPv6 DNS on Starlink
Starlink provides genuine dual-stack connectivity with a native /56 IPv6 prefix — not tunneled or 6rd. In practice, this means DNS queries from a dual-stack device will go over IPv6 if an IPv6 resolver is reachable. If you only set IPv4 custom DNS and leave IPv6 DNS at the Starlink default, you have a split-resolver situation: A record lookups may go to your custom server while AAAA record lookups go to Starlink's IPv6 resolver.
Set IPv6 DNS addresses alongside every IPv4 change you make:
- Cloudflare: 2606:4700:4700::1111 / 2606:4700:4700::1001
- Google: 2001:4860:4860::8888 / 2001:4860:4860::8844
- Quad9: 2620:fe::fe / 2620:fe::9
On routers that expose a single DNS field for both address families, check whether there's a separate Advanced IPv6 section. Asus routers have IPv6 DNS fields under Advanced Settings → IPv6 → DNS Server 1/2. UniFi exposes them per-network under the IPv6 tab. If your router doesn't surface IPv6 DNS fields, set IPv6 DNS at the OS level using Method 3 in addition to your router-level IPv4 configuration.
Verifying Custom DNS Is Actually Working
Always confirm the change took effect. Don't rely on a successful page load — browsers cache aggressively.
Use the DNS Lookup tool to compare what different resolvers return for the same domain — particularly useful when debugging stale cached records or split-horizon discrepancies between Starlink's resolver and your custom one.
For a browser-based check, the Google Public DNS documentation includes a test domain you can query to verify whether responses are originating from Google's infrastructure. Cloudflare's resolver serves a diagnostic page at one.one.one.one/help that reports whether your traffic is reaching their network.
2026 Specifics: DNSSEC, DoH, and DoT
Starlink's default resolver does not enforce DNSSEC validation for consumer accounts. Responses with invalid signatures are passed through rather than returned as SERVFAIL. If you handle sensitive lookups — remote access infrastructure, financial, or healthcare domains — switch to a resolver that validates. Quad9 (9.9.9.9) validates DNSSEC and drops domains in threat intelligence feeds. Cloudflare (1.1.1.1) validates without blocking. Google (8.8.8.8) validates and returns SERVFAIL on bad signatures.
The Starlink Gen 2 and Gen 3 integrated routers do not support DNS over HTTPS or DNS over TLS as a forwarding mode in current firmware. For encrypted DNS without bypass mode, use OS-level encrypted DNS: Windows 11 native DoH, iOS/Android Private DNS profiles or Private DNS hostname setting, macOS DNS profiles, or a DNS-aware VPN. In bypass mode, encrypted DNS forwarding is available via Asus Merlin's built-in DoT setting, OpenWrt's https-dns-proxy package, or OPNsense/pfSense Unbound configured with DoT upstreams.
IPv6 adoption on North American Starlink connections exceeded 65% of sessions by mid-2026. The IPv6 DNS configuration steps above are not optional edge cases — for most households, skipping them means roughly half of all DNS queries bypass your custom resolver entirely.
Common Misdiagnoses
App DNS setting wiped after factory reset. The Starlink app DNS setting is stored in the router's firmware configuration. A factory reset — triggered by holding the button on the dish base or through the app — wipes it back to 100.64.0.1. Reapply after any reset.
Android ignoring your router. Android devices with a Private DNS hostname configured will ignore DHCP-pushed DNS entirely. If one device on the network isn't using your custom resolver, check Settings → Network & Internet → Private DNS before blaming the router.
VPN overriding everything. Every major VPN client hijacks DNS to prevent leaks through the unencrypted path. Your custom DNS at the router or OS level is irrelevant while a VPN tunnel is active. Disable the VPN entirely, then test base DNS behavior with the dig commands above.
DHCP lease not renewed. After changing DNS in the Starlink app or your router, clients keep using the cached resolver for the remaining duration of their DHCP lease (often 24 hours). Force an immediate refresh: ipconfig /release then ipconfig /renew on Windows; toggle Wi-Fi off and on for iOS and Android; or sudo dhclient -r && sudo dhclient on Linux.
Bypass mode not fully bypassing. WAN shows 100.64.x.x — the dish is still NATting. Cold-restart the dish by unplugging the PoE injector for 30 seconds. Do not rely on a soft reboot from the app; the Gen 2 firmware quirk requires a full power cycle to release bypass mode into effect.
Split IPv4/IPv6 resolver. Custom IPv4 DNS is set, IPv6 is not. The symptom is inconsistent behavior: Windows shows your resolver in nslookup (uses IPv4 DNS first on most builds) but macOS and Android still hit Starlink (prefer IPv6). Fix by adding IPv6 resolver addresses everywhere you set IPv4 addresses.
Preventing DNS Drift
The most durable setup is DNS enforcement at the router level via DHCP option 6. Method 1 (Starlink app) does this for IPv4 automatically. In bypass mode, configure it on your router as shown above and both new and existing devices pick up the correct resolver on their next lease renewal.
For environments where some devices override DHCP DNS — managed laptops with GPO-enforced settings, iOS devices with DNS profiles, Android with Private DNS set — you can redirect all outbound port-53 traffic at the firewall to your local resolver:
This intercepts plain port-53 queries. DNS over HTTPS runs on port 443 and DNS over TLS runs on port 853 — both are encrypted transports that you cannot intercept without breaking the TLS certificate chain. That's by design. Accept that DoH/DoT-capable devices use their encrypted resolver of choice, and focus port-53 interception on legacy devices and IoT that cannot do encrypted DNS.