Most TP-Link Deco owners never touch the default DNS settings their ISP assigned — and then wonder why certain sites load slowly, ads follow them everywhere, or parental controls only half-work. Swapping in a faster, more privacy-respecting DNS resolver is one of the highest-leverage five-minute changes you can make on a home or office mesh network. This guide covers every method: the Deco mobile app, the local web admin panel at 192.168.68.1, the distinction between WAN DNS and DHCP-advertised DNS, IPv6 nameservers, and DNS-over-HTTPS support added in newer 2025–2026 firmware.

Why Change DNS on Your Deco Mesh

By default, Deco units inherit DNS from the WAN connection — usually whatever your ISP assigns via DHCP or PPPoE. ISP resolvers are notorious for sluggish response times (often 80–150 ms versus 10–20 ms for Cloudflare or Google), DNS hijacking that redirects failed lookups to ad landing pages, and logging every query for analytics. A custom resolver eliminates all three problems.

Deco mesh centralises DNS for every device on your network. Change it once at the Deco level and every phone, laptop, and smart TV automatically uses the new resolver — no per-device configuration required. This is the key advantage over per-device DNS changes, which leave gaps whenever a new device joins.

Common reasons people make this change:

  • DNS leaking through the ISP resolver despite a VPN running at the router level
  • Slow first-page-load times caused by high resolver latency
  • Network-wide ad and malware blocking via a filtering DNS (NextDNS, Quad9, AdGuard DNS)
  • Parental content filtering via CleanBrowsing or OpenDNS Family Shield with no per-device setup
  • DNSSEC validation for security-sensitive home office environments

Find Your Deco Admin Address Before You Start

TP-Link Deco defaults to the 192.168.68.0/24 subnet, placing the primary unit at 192.168.68.1. This is different from most consumer routers, which typically sit at 192.168.1.1 or 192.168.0.1. If you changed the LAN subnet during initial setup, find the actual gateway IP first:

Windows: ipconfig | findstr "Default Gateway" Mac / Linux: ip route | grep default iOS / Android: Settings → Wi-Fi → tap your network name → Gateway field (under IP details)

That IP is your Deco's admin address for both the browser-based panel and to confirm the app is connected to the correct unit on the local network.

💡 Before switching resolvers, record your current DNS behaviour with the DNS Propagation Checker — handy for comparing before-and-after latency or confirming a rollback if something breaks after the change.

Method 1: Deco Mobile App (Recommended)

The Deco app is the canonical management interface for all Deco hardware. Firmware features appear here first, and newer options like DNS-over-HTTPS exist only in the app on most models — they are not exposed in the web UI.

App version 5.x (current in 2026)

  1. Open the TP-Link Deco app and sign in with your TP-Link ID.
  2. On the home screen, tap the menu icon in the top-right corner (three horizontal lines).
  3. Tap Advanced.
  4. Tap DNS under the Network section.
  5. The current mode displays Auto (ISP-assigned). Tap Custom.
  6. Enter your Primary DNS and Secondary DNS addresses.
  7. Tap Save. Changes apply within a few seconds — no reboot required on current firmware.

Older app versions (3.x and 4.x)

The navigation path differs slightly on earlier builds:

  1. Open the Deco app and tap More in the bottom-right tab.
  2. Tap Internet.
  3. Scroll to DNS Server and tap it.
  4. Select Custom and enter your primary and secondary nameservers.
  5. Tap Save.

If the DNS option is missing entirely from the app, the firmware is likely below version 1.6.x — a common situation on M5, M9 Plus, and E4 units shipped before 2022. Navigate to More → Deco Info → Check for Updates and install the latest firmware before proceeding. The DNS field appears after the update without any further action.

Method 2: Web Admin Panel at 192.168.68.1

The local browser interface provides full access without the mobile app — useful when provisioning a Deco remotely, when the app is unavailable, or when scripting configuration changes.

Step-by-step (firmware 2.x and newer)

  1. Open a browser and navigate to http://192.168.68.1. Substitute your actual gateway IP if the LAN subnet was changed during setup.
  2. Log in with your local admin password or TP-Link ID credentials.
  3. Click Advanced in the top navigation bar.
  4. Select Network from the left sidebar.
  5. Click DHCP Server.
  6. Locate the DNS Address fields and enter your primary and secondary nameservers.
  7. Click Save.

WAN DNS vs DHCP DNS — which one matters

The web panel exposes two distinct DNS settings that serve different purposes:

  • WAN DNS (Advanced → Internet): used by the Deco unit itself for outbound system traffic — NTP time sync, firmware update checks, TP-Link cloud telemetry. This setting is not pushed to client devices on your LAN.
  • DHCP DNS (Advanced → Network → DHCP Server): pushed to every connected device via the DHCP lease. This is what phones, laptops, and IoT devices actually use when resolving domain names.

For most users, changing the DHCP DNS is the priority — it controls what every device on the network resolves against. If you also want the Deco's own outbound traffic routed away from the ISP resolver, set both fields. Leaving WAN DNS on Auto while setting DHCP DNS to custom is a valid configuration.

⚠️ Enabling TP-Link HomeShield can silently override your custom DNS by routing queries through TP-Link's own filtering infrastructure. If your resolver unexpectedly reverts to an unknown IP after activating HomeShield features, disable DNS filtering at Advanced → HomeShield → DNS Filter — or accept that HomeShield controls DNS resolution while it remains active.

Recommended DNS Servers in 2026

The choice comes down to speed, privacy, malware filtering, or content controls:

  • Cloudflare — 1.1.1.1 / 1.0.0.1. Fastest globally, strict no-logging policy, DNSSEC-validating. Best general-purpose default.
  • Google Public DNS — 8.8.8.8 / 8.8.4.4. Extremely reliable, full DNSSEC support. See Google's resolver documentation for details on privacy controls and DNSSEC handling.
  • Quad9 — 9.9.9.9 / 149.112.112.112. Blocks known malicious domains via curated threat intelligence feeds, DNSSEC-validating. Free.
  • NextDNS — Per-account IPs assigned on signup. Full ad and tracker blocking, granular allow/blocklists, query log dashboard. Free tier for up to 300,000 queries per month.
  • OpenDNS Family Shield — 208.67.222.123 / 208.67.220.123. Adult content filtering network-wide, no account required — the lowest-friction parental DNS option.
  • AdGuard DNS — 94.140.14.14 / 94.140.15.15. Ad and tracker blocking with DNSSEC. No account needed for the default block list.

For a general home or home-office network, 1.1.1.1 / 1.0.0.1 is the practical default. For households with children who need filtering without account management, OpenDNS Family Shield is the right call.

IPv6 DNS on Deco

If your ISP provides IPv6 connectivity, configure IPv6 DNS servers alongside the IPv4 ones. Without them, IPv6-capable devices fall back to the ISP resolver for AAAA record lookups — a DNS leak on the IPv6 path even when your IPv4 resolver is fully custom. As IPv6 penetration grows past 50% of connections in North America in 2026, this gap matters more than it did two years ago.

In the Deco app go to Advanced → IPv6 → DNS Server fields. Common IPv6 nameserver pairs that match the IPv4 options above:

  • Cloudflare IPv6: 2606:4700:4700::1111 / 2606:4700:4700::1001
  • Google IPv6: 2001:4860:4860::8888 / 2001:4860:4860::8844
  • Quad9 IPv6: 2620:fe::fe / 2620:fe::9

If the IPv6 DNS fields are greyed out, your WAN connection type does not support manual IPv6 DNS assignment from the Deco side — the ISP controls it automatically via DHCPv6 or router advertisements in that configuration.

DNS-over-HTTPS on Newer Deco Models

TP-Link began shipping DNS-over-HTTPS support in Wi-Fi 6 and Wi-Fi 7 Deco models — X20, X55, XE75, BE85, and the full BE series — starting in late 2024. With DoH active, DNS queries are encrypted between the Deco and the upstream resolver, blocking ISP packet inspection of DNS traffic even on an unencrypted WAN connection. This removes one of the main remaining surveillance vectors on a home network.

To enable DoH on a supported unit:

  1. Update to the latest firmware first: More → Deco Info → Check for Updates.
  2. In the app: Advanced → DNS → toggle DNS over HTTPS on.
  3. Enter the DoH endpoint URL for your chosen resolver:
    • Cloudflare: https://cloudflare-dns.com/dns-query
    • Google: https://dns.google/dns-query
    • Quad9: https://dns.quad9.net/dns-query
    • NextDNS: your unique endpoint shown in the NextDNS account dashboard
  4. Tap Save. The Deco tests the DoH endpoint before applying — if the test fails, it rejects the change rather than silently dropping DNS resolution.

Older Deco hardware (M4, M5, M9, S4, P9) does not support DoH at the router level regardless of firmware version. On those units, configure DoH per-device: Android 9+ Private DNS setting, Windows 11 adapter-level DNS-over-HTTPS in Network settings, or macOS Ventura and later System Settings → Network → DNS.

Verify the DNS Change Worked

After saving the new DNS on the Deco, renew the DHCP lease on your test device so it picks up the updated assignment rather than relying on a cached lease from before the change:

Windows: ipconfig /release ipconfig /renew Linux: sudo dhclient -r && sudo dhclient macOS: sudo ipconfig set en0 DHCP # Replace en0 with your active interface (check with: networksetup -listallnetworkservices)

Then confirm which resolver is actually in use:

dig (Linux and Mac)

dig +short TXT whoami.resolver.arpa # Returns the resolver's own IP — confirm it matches what you configured dig google.com @1.1.1.1 # Direct query to Cloudflare — confirms it responds correctly from your network

nslookup (Windows, Mac, Linux)

nslookup google.com # The "Server:" line in the output shows your active resolver IP nslookup google.com 1.1.1.1 # Explicit query to Cloudflare to verify connectivity to the new resolver

resolvectl (Linux with systemd-resolved)

resolvectl status # Look for "DNS Servers:" on your active network interface # Should display 1.1.1.1 or whichever server you configured on the Deco

For a broader propagation check from outside your own network, use the DNS Lookup tool to query your domain from multiple global vantage points and confirm records are resolving as expected worldwide.

Per-Device DNS Override When Needed

The Deco's DNS setting is network-wide — it applies to every device via DHCP. If a specific device needs a different resolver (a work laptop querying a corporate internal DNS, a test machine using an alternate provider, or a device that must bypass a filtering DNS for legitimate reasons), configure DNS statically on that device. Device-level DNS overrides DHCP-pushed DNS without affecting any other device on the network:

  • Windows 10/11: Settings → Network → adapter properties → IPv4 → Use the following DNS server addresses
  • macOS: System Settings → Network → interface → Details → DNS tab → add custom nameservers
  • iOS: Settings → Wi-Fi → tap your network name → Configure DNS → Manual
  • Android: Settings → Wi-Fi → long-press your network → Modify → Advanced → IP settings: Static, then fill in DNS 1 and DNS 2
  • Android 9+ shortcut: Settings → Network → Private DNS — enter a DoT hostname such as 1dot1dot1dot1.cloudflare-dns.com to completely bypass DHCP DNS with encrypted queries at the OS level

Common Misdiagnoses

Several issues appear after a DNS change on Deco but stem from different causes than they seem:

  • ISP resolver still appears after the change — You updated one field (WAN DNS or DHCP DNS) but not the other, or the device is using a cached DHCP lease from before the change. Renew the lease manually and re-check with nslookup or dig.
  • DNS shows correct resolver but pages still load slowly — The resolver round-trip time is fine, but the destination site's authoritative nameserver is slow or overloaded. These are independent layers of DNS performance and require separate investigation.
  • Custom DNS reverted to Auto after a firmware update — TP-Link firmware upgrades have silently reset DNS to Auto on the M4, M5, and X20 model lines. Always verify DNS configuration immediately after any firmware update cycle.
  • HomeShield overriding custom DNS — HomeShield's DNS filtering routes queries through TP-Link's infrastructure when the feature is active. Disable the DNS Filter toggle under Advanced → HomeShield, or accept that HomeShield controls DNS resolution as long as it is enabled.
  • DNS leaks to ISP despite custom Deco DNS — If a VPN runs at the router level, the VPN's own DNS handling and the Deco's DHCP DNS are independent paths. Confirm the VPN provider's DNS leak protection is explicitly enabled in the VPN configuration.
  • One device ignores the custom DNS — That device has a static IP address with a manually configured DNS, or uses OS-level DoT or DoH that bypasses DHCP entirely. Check the device's own network settings directly rather than the Deco panel.

Confirming the Fix Holds Over Time

A single verification check isn't enough. Run a quick round-trip benchmark from a device on the Deco network right after making the change:

## Linux or Mac — test three resolvers back to back: for server in 1.1.1.1 8.8.8.8 9.9.9.9; do echo "=== $server ===" time dig @$server google.com > /dev/null done

On a typical broadband connection expect sub-30 ms per query. If the new resolver consistently returns 150 ms or more while a direct dig to that same IP is fast, the Deco is adding proxy latency — check for active HomeShield DNS scanning or temporarily disable QoS to isolate the bottleneck.

Check again 24 to 48 hours after the initial change. The Deco M4 and M5 series running firmware 1.4.x have a documented regression where DNS silently reverts to Auto on every reboot. If the setting fails to persist, update the firmware — the bug was patched in release 1.6.2 for those models. After updating, re-enter the custom DNS and it will hold through reboots and scheduled update cycles going forward.