Your TP-Link Archer ships pointed at your ISP's DNS resolvers by default — often slow, sometimes unreliable, and occasionally used to redirect NXDOMAIN queries to ad pages. Swapping to a faster, more private resolver is a five-minute job, but the exact menu path depends on which Archer firmware generation you're running. This guide covers every variant: the new 2024–2026 firmware, the classic legacy UI, and the Tether mobile app, along with IPv6 DNS, DoH/DoT notes, and CLI checks to confirm the change actually propagated.

Why Changing DNS on the Router Beats Changing It Per Device

Configuring DNS at the router level means every device on your network — phones, smart TVs, IoT gadgets — benefits automatically without individual configuration. The Archer applies the new resolver in two ways:

  • WAN DNS: The upstream resolver the router uses for its own outbound lookups and for forwarding client queries to the internet.
  • DHCP DNS: The resolver addresses handed to LAN clients via DHCP. By default, Archers advertise their own IP (192.168.0.1) as the DNS server for clients, then forward queries upstream. You can override this to push an external resolver directly to devices.

For most home setups, changing the WAN DNS is sufficient. If you want clients to query an external resolver directly, bypassing the router's forwarder, change the DHCP DNS as well. Both are covered below.

Identify Your TP-Link Archer Firmware Generation First

TP-Link has shipped at least three distinct admin UI generations. Knowing which you have saves significant dead-end clicking:

  • New UI (2022–2026): Blue/white theme, left-side navigation. Found on Archer AX55, AX73, AX90, AXE75, BE550, BE900, and most Wi-Fi 6, 6E, and 7 models. Admin at tplinkwifi.net or 192.168.0.1.
  • Classic UI (2018–2022): Dark top bar, tabbed navigation. Common on Archer A7, C7, C9, A20, AX10, AX20. Same admin addresses.
  • Very Old UI (pre-2018): Basic grey or green interface on older models like C2, C50, C5400. Admin typically at 192.168.1.1 — confirm on the router label.

Log in at http://tplinkwifi.net or http://192.168.0.1 using HTTP, not HTTPS, unless you have manually enabled it. The firmware version appears in the top-right corner or under Advanced → System Tools → Firmware Upgrade.

💡 After changing DNS, use our DNS Propagation Checker to verify the new resolver is returning correct results for your domains — not just from your local network.

Method 1 — Change DNS via the Web Admin Panel

New UI (2022–2026 firmware)

  1. Open a browser and go to http://tplinkwifi.net or http://192.168.0.1.
  2. Log in with your admin credentials. Default is admin / admin on factory-reset units, but TP-Link has required a custom password on new units since 2019 — check the sticker on the underside.
  3. In the left sidebar, click Advanced.
  4. Navigate to Network → Internet.
  5. Scroll to the DNS section. You will see Primary DNS and Secondary DNS fields.
  6. Enter your chosen resolver. Popular options in 2026:
  • Cloudflare: 1.1.1.1 / 1.0.0.1 (fast, privacy-focused, DNSSEC-validating)
  • Google: 8.8.8.8 / 8.8.4.4 (reliable, global anycast)
  • Quad9 (malware-blocking): 9.9.9.9 / 149.112.112.112
  • NextDNS (custom filtering): your assigned IPs from the nextdns.io dashboard
  1. Click Save. The router does not reboot — the change applies to new DNS queries immediately.

Classic UI (2018–2022 firmware)

  1. Log in at http://192.168.0.1.
  2. Click the Advanced tab at the top of the page.
  3. Go to Network → WAN.
  4. Scroll to the DNS Address section at the bottom. If the fields are greyed out, uncheck Get DNS Automatically first.
  5. Enter Primary and Secondary DNS → click Save.

Change DHCP DNS (push resolver directly to clients)

Use this if you are running a local resolver like Pi-hole and want clients to query it directly, bypassing the router's forwarder.

New UI: Advanced → Network → DHCP Server → set Primary DNS and Secondary DNS to your local resolver IP (e.g., 192.168.0.200 for Pi-hole) → Save.

Classic UI: Advanced → Network → DHCP Server → same fields. Leave blank to have clients use the router (192.168.0.1) as forwarder, which is correct for most home networks.

Very Old UI (pre-2018)

  1. Log in at http://192.168.1.1 — confirm address on the router label.
  2. Go to DHCP → DHCP Settings.
  3. Set Primary DNS and Secondary DNS → Save → reboot the router.

Method 2 — Change DNS via the TP-Link Tether App

The Tether app (iOS and Android) supports DNS changes on most Archer models running 2021 or later firmware. The path is less obvious than the web UI:

  1. Open Tether with your phone on the same Wi-Fi network as the Archer.
  2. Tap the router name to open its management panel.
  3. Tap Tools — the wrench icon at the bottom.
  4. Tap Internet Connection.
  5. Scroll to the DNS section. If it is not visible, your firmware does not expose DNS through Tether — use the web admin panel instead.
  6. Toggle off Obtain DNS Automatically.
  7. Enter Primary and Secondary DNS → tap Save.

On some models, DNS settings appear under Advanced → WAN Settings within Tether rather than the main Tools screen. If DNS fields are entirely absent, update the firmware first (Tools → Firmware Upgrade) — you may need two incremental update cycles to reach a version that exposes the DNS UI.

IPv6 DNS Settings on Archer Routers (2026)

With native IPv6 now standard on most Canadian and US ISPs, devices may send AAAA queries over IPv6 — and those bypass your IPv4 DNS change entirely if you have not also set IPv6 DNS. This is a very common reason a router DNS change appears to have no effect on some lookups.

New UI path: Advanced → IPv6 → within the IPv6 WAN settings section, locate the IPv6 Primary DNS and Secondary DNS fields. These are separate from the IPv4 DNS fields on DHCPv6 and SLAAC+Stateless DHCP connections. IPv6 resolver addresses:

  • Cloudflare: 2606:4700:4700::1111 / 2606:4700:4700::1001
  • Google: 2001:4860:4860::8888 / 2001:4860:4860::8844
  • Quad9: 2620:fe::fe / 2620:fe::9

If your firmware does not expose IPv6 DNS fields, disable IPv6 on the router (Advanced → IPv6 → toggle off). This forces all traffic to IPv4 DNS where your manual setting applies. Re-enable once firmware adds the IPv6 DNS option.

DNS-over-HTTPS and DNS-over-TLS on Archer Routers (2026)

Several Archer models added native encrypted DNS in 2025–2026 firmware. Confirmed as of mid-2026: Archer BE900, BE550, AXE300, AX90, AX73, AX55 running firmware 1.3.0 or later. Find the option at:

Advanced → Security → DNS Security or Advanced → Network → Internet → DNS Encryption (path varies by model).

The toggle enables DNS-over-HTTPS (DoH) and on some models DNS-over-TLS (DoT), wrapping all router-level DNS queries in encrypted transport and preventing ISP-level query logging. Cloudflare and Google are pre-populated options on most models. On Archers without built-in DoH, the practical alternative is to run cloudflared on a Raspberry Pi on your LAN and point the Archer's DHCP DNS at that Pi's IP.

DNSSEC validation is separate from transport encryption. Cloudflare (1.1.1.1) and Quad9 (9.9.9.9) both perform DNSSEC validation upstream, so switching to either gives you spoofing protection without requiring router-level support. For technical background, see the IETF RFC 4033 DNS Security specification.

Verify Your DNS Change Actually Worked

Do not assume the change applied. Browsers cache DNS aggressively, and existing DHCP leases retain the old resolver IP until they expire (default 24 hours on most Archers) or are manually renewed.

Windows

ipconfig /flushdns ipconfig /all

Under your active network adapter, find the DNS Servers line. It typically shows 192.168.0.1 — the router acting as forwarder — which is correct. Confirm the router is forwarding to your new upstream:

nslookup google.com 192.168.0.1

A resolved IP with no error confirms the chain is working. Query time over 200ms suggests the upstream resolver is not responding correctly.

macOS

sudo dscacheutil -flushcache && sudo killall -HUP mDNSResponder scutil --dns

scutil --dns displays the resolver configuration per interface. Under Wi-Fi you should see 192.168.0.1 as nameserver (router forwarding), or your external resolver if you changed DHCP DNS directly.

Linux (systemd-resolved)

resolvectl status resolvectl dns

On systems without systemd-resolved:

cat /etc/resolv.conf

iOS

Settings → Wi-Fi → tap your network name → scroll to Configure DNS. Automatic means it uses whatever DHCP advertises. To confirm the actual upstream resolver, run a lookup from the DNS Lookup tool in your iOS browser and check which server responds.

Android

Settings → Network & Internet → Wi-Fi → long-press the network → Modify network → Advanced → IP settings → check the DNS fields. Android's Private DNS setting (Settings → Network & Internet → Advanced → Private DNS) overrides all DHCP-assigned DNS. If a hostname is set there, your router DNS change has no effect on that device — clear Private DNS first.

CLI Verification with dig and nslookup

To confirm the full chain, query through the router then directly to your chosen upstream:

dig @192.168.0.1 google.com +short

A fast response with a valid IP confirms the router is handling DNS. Then verify the upstream:

dig @1.1.1.1 google.com +stats | grep "Query time" nslookup google.com 1.1.1.1

Cloudflare 1.1.1.1 typically runs 10–30ms from Canadian metro areas. ISP resolvers range from 10ms to over 150ms. On Windows, use PowerShell if dig is not installed:

Resolve-DnsName -Name google.com -Server 192.168.0.1 Resolve-DnsName -Name google.com -Server 1.1.1.1

Common Reasons the DNS Change Did Not Stick

Ranked by frequency:

  1. DHCP lease not renewed. Clients retain their old DNS assignment until the lease expires or is manually renewed. Windows: ipconfig /release then ipconfig /renew in Command Prompt. Mac: toggle Wi-Fi off and on. Mobile: toggle airplane mode. This resolves the majority of reported cases.
  2. Device has a static DNS or Private DNS override. Android Private DNS, iOS DNS profiles, or a manually set DNS in Windows adapter settings all override DHCP-advertised DNS. Check each affected device directly.
  3. Archer is in Access Point mode. Go to Advanced → System Tools → Operation Mode. If it shows Access Point Mode, the Archer is not handling DHCP or DNS forwarding — the upstream modem/router is. Change DNS on that device instead.
  4. Firmware bug on AX20/AX21 (some 2022–2023 builds). A known issue caused manual DNS entries to silently reset after a reboot. Update to latest firmware (Advanced → System Tools → Firmware Upgrade), then re-enter and save the DNS values.
  5. Browser DoH overriding system DNS. Chrome and Firefox can use their own encrypted DNS resolvers entirely bypassing the OS and router. Chrome: chrome://settings/security → Advanced → Use secure DNS. Firefox: Settings → Privacy & Security → DNS over HTTPS. Disable or align these with your router's resolver.
  6. Admin session timeout before saving. Some firmware versions discard changes if the session expired before you clicked Save. Log out, log back in, enter DNS, and Save promptly.

Third-Party Firmware: OpenWrt and DD-WRT

Popular Archer targets including the C7, A7, C2600, and AX23 run OpenWrt or DD-WRT. DNS configuration is entirely different on custom firmware:

OpenWrt: DNS forwarding uses dnsmasq. Change upstream resolvers at Network → DHCP and DNS → General Settings → DNS Forwardings, or via CLI:

uci add_list dhcp.@dnsmasq[0].server='1.1.1.1' uci add_list dhcp.@dnsmasq[0].server='1.0.0.1' uci commit dhcp service dnsmasq restart

For encrypted DNS on OpenWrt, install the https-dns-proxy or stubby package:

opkg update && opkg install https-dns-proxy service https-dns-proxy enable && service https-dns-proxy start

DD-WRT: Administration → Management → DNS server fields accept upstream IPs directly. Encrypted DNS via dnscrypt-proxy is available on select DD-WRT builds.

Preventing Your DNS Settings from Reverting

Several routine events can silently reset your DNS configuration:

  • Firmware auto-updates. TP-Link's automatic update feature has been documented to reset DNS on certain Archer models. After any firmware update, verify your DNS entries under Advanced → Network → Internet before assuming they carried through.
  • Factory reset (hardware button). A hard reset wipes all customisation including DNS. Photograph or note your resolver IPs somewhere persistent.
  • ISP DHCP option 6 override. If the Archer WAN connection is DHCP-based, your ISP can push DNS addresses in the offer. Ensure Obtain DNS Automatically is unchecked so the router ignores the ISP push and holds your manual entries.

Run periodic spot-checks using the DNS Lookup tool on key domains. Unexpected IPs or sudden latency increases are usually the first sign that DNS settings have reverted.

Common Misdiagnoses

These situations frequently get blamed on DNS when the real cause is elsewhere:

  • Browsing is still slow after switching resolvers. DNS lookup adds 5–50ms to a page load. A 3–4 second page load is your ISP connection, CDN routing, or origin server response time — not the resolver. Use a network trace to isolate where the delay actually occurs.
  • Specific sites fail after the DNS change. Almost always a stale browser or OS cache pointing to an old IP. Flush both and do a hard reload (Ctrl+Shift+R). If the problem is limited to one site, verify the site is not simply down before blaming the resolver.
  • Cloudflare 1.1.1.1 timing out intermittently. A small number of ISPs in certain regions selectively rate-limit or block 1.1.1.1 anycast addresses. Add Quad9 (9.9.9.9) as your secondary DNS for fallback. For background on how DNS resolution works at the protocol level, the Cloudflare DNS learning center is a solid reference.
  • DNSSEC failures returning NXDOMAIN. If you switch to a DNSSEC-validating resolver and certain domains suddenly return NXDOMAIN, those domains have broken DNSSEC records. Use a DNSSEC debugger to confirm — it is a domain configuration problem, not a resolver problem.