Report a blocked site

Free protective DNS for individual users in Europe

A public DNS resolver runs on European infrastructure, under EU data protection rules, independent of non-EU providers. Open to any individual in Europe, at no cost.

Blocks malware, phishing and command-and-control domains at the point of resolution. The one to pick if you are not sure.

IPv4

86.54.11.1

86.54.11.201

IPv6

2a13:1001::86:54:11:1

2a13:1001::86:54:11:201

All variants

Jurisdiction

Resolved inside the union

Every lookup is answered on infrastructure operated in the EU, under EU law. Not routed to a resolver outside it and not dependent on one.

Privacy

Anonymised, and not a product

Queries are anonymised. They are not sold, not profiled and not used to build advertising audiences. The resolver is a public service, so there is nothing to monetise.

Quality

Open to individual users in Europe

Protective, fast DNS resolution for any individual in Europe, at no cost, on infrastructure built for the whole union rather than resold from elsewhere.

Resolution speed is the easy half of the question. The other half is who answers the query, and under whose law.

Narrow the field
Median query speed measured from Europe, July 2026. Lower is better.
Resolver Median query speed
Google 11.14ms
Cisco Umbrella 14.30ms
DNS4EU 17.01ms
UltraDNS 17.36ms
NextDNS 21.29ms
Quad9 21.86ms

Resolvers, measured from Europe

Five variants on the same European infrastructure. Same jurisdiction and the same speed, different filtering. Pick one and use it everywhere.

Protective resolution

Blocks malware, phishing and command-and-control domains at the point of resolution. The one to pick if you are not sure.

Avoid any access to websites with fraudulent or malicious content.

IPv4

86.54.11.1

86.54.11.201

IPv6

2a13:1001::86:54:11:1

2a13:1001::86:54:11:201

DNS over HTTPS

https://protective.joindns4.eu/dns-query

DNS over TLS

protective.joindns4.eu

Protective resolution with child protection

Everything in Protective, plus filtering of content that is not appropriate for children.

Avoid access to websites inappropriate for children, such as explicit content, violence or drugs, on top of the protective functionality.

IPv4

86.54.11.12

86.54.11.212

IPv6

2a13:1001::86:54:11:12

2a13:1001::86:54:11:212

DNS over HTTPS

https://child.joindns4.eu/dns-query

DNS over TLS

child.joindns4.eu

Protective resolution with ad blocking

Everything in Protective, plus advertising and tracking domains.

Hide website and in-app ads on top of the protective functionality.

Some websites and apps have anti-ad detection systems in place, which could prevent the website from displaying properly or cause the app to malfunction.

IPv4

86.54.11.13

86.54.11.213

IPv6

2a13:1001::86:54:11:13

2a13:1001::86:54:11:213

DNS over HTTPS

https://noads.joindns4.eu/dns-query

DNS over TLS

noads.joindns4.eu

Protective resolution with child protection and ad blocking

Everything in Protective, with both the child protection and the ad blocking filters applied.

Avoid access to websites inappropriate for children, such as explicit content, violence or drugs, and filter ads on top of the protective functionality.

Some websites and apps have anti-ad detection systems in place, which could prevent the website from displaying properly or cause the app to malfunction. We recommend configuring this option on a private device only, where you can fall back to another variant. Check and verify everything before finalising the setup.

IPv4

86.54.11.11

86.54.11.211

IPv6

2a13:1001::86:54:11:11

2a13:1001::86:54:11:211

DNS over HTTPS

https://child-noads.joindns4.eu/dns-query

DNS over TLS

child-noads.joindns4.eu

Unfiltered resolution

European resolution with no content filtering applied. Privacy and jurisdiction only.

A valid option for users who are confident their devices and connection are secure, and are looking for fast, reliable and anonymised resolution.

Court-ordered domain blocks apply to every variant, including this one. The complete, up to date registry of court-ordered blocking is published under Legal information and compliance.

IPv4

86.54.11.100

86.54.11.200

IPv6

2a13:1001::86:54:11:100

2a13:1001::86:54:11:200

DNS over HTTPS

https://unfiltered.joindns4.eu/dns-query

DNS over TLS

unfiltered.joindns4.eu

Three steps. No account, no software.

Open network settings

On your device or router, find the DNS settings for the connection you are using.

Enter the address

Replace the addresses already there with the resolver you chose above.

Save and you are protected

Save. Every lookup from that device now resolves through DNS4EU, inside the EU.

Windows 11 and Windows 10

Per connection, in Network and internet.
  1. Open Settings, then Network and internet.
  2. Select the connection you are using, Wi-Fi or Ethernet.
  3. Find DNS server assignment and choose Edit.
  4. Switch from Automatic (DHCP) to Manual and turn on IPv4.
  5. Enter the first address of your chosen resolver as the preferred DNS, and the second as the alternate.
  6. If your connection uses IPv6, turn that on as well and enter both IPv6 addresses.
  7. Save, then reconnect to the network.

Windows 11 offers a DNS over HTTPS setting in the same dialog.

macOS

Per connection, in System Settings.
  1. Open System Settings, then Network.
  2. Select the connection you are using and choose Details.
  3. Open the DNS tab.
  4. Remove the servers listed there, then add the first and second address of your chosen resolver.
  5. Choose OK, then Apply.

iPhone and iPad

Per Wi-Fi network, under Configure DNS.
  1. Open Settings, then Wi-Fi.
  2. Tap the info button beside the network you are on.
  3. Tap Configure DNS and switch from Automatic to Manual.
  4. Delete the servers listed, then add both addresses for your chosen resolver.
  5. Tap Save.

This applies to that Wi-Fi network only. Mobile data keeps using the carrier's resolver.

Android

Private DNS covers Wi-Fi and mobile data at once.

Private DNS is the better route on Android. It is DNS over TLS, it takes a hostname rather than an address, and it applies to Wi-Fi and mobile data together.

  1. Open Settings, then Network and internet, then Private DNS.
  2. Choose Private DNS provider hostname.
  3. Enter the DNS over TLS hostname for your chosen resolver, for example protective.joindns4.eu.
  4. Save.

To set plain addresses on one Wi-Fi network instead, edit that network, change IP settings from DHCP to Static, and enter the two addresses as DNS 1 and DNS 2.

Google Chrome

DNS4EU is in Chrome's own secure DNS list.

A browser setting covers what the browser resolves, not the rest of the device.

  1. Click the three dots in the top right corner of Chrome and select Settings.
  2. Go to Privacy and security in the left sidebar, then click Security.
  3. Scroll to Advanced. Under Use secure DNS, turn the switch on, then under Select DNS provider choose DNS4EU Public Service (Protective).

Chrome 144 or newer is needed for DNS4EU to appear in that list.

Mozilla Firefox

A custom provider, using the encrypted endpoint.

Firefox takes the DNS over HTTPS address of the resolver you chose above.

  1. Open Settings, then Privacy & Security, and scroll to DNS over HTTPS.
  2. Choose Max Protection, then Custom as the provider.
  3. Enter the DoH address of your variant, for example https://protective.joindns4.eu/dns-query.

Your router

One change, every device on the network.

Setting it once on the router covers every device on the network, including the ones with no DNS setting of their own.

  1. Open the router's administration page. The address and the sign-in details are usually printed on the device.
  2. Find the DNS settings, normally under WAN, Internet or DHCP.
  3. Replace the addresses supplied by your provider with the first and second address of your chosen resolver.
  4. Save, then restart the router.

Encrypted DNS, DoH and DoT

A hostname rather than an address, so the query itself is encrypted in transit.

DNS over HTTPS and DNS over TLS use a hostname rather than an address. Every variant above lists both of its endpoints. Plain DNS is readable by anything between you and the resolver; encrypted DNS is not.

  1. Android: Settings, Network and internet, Private DNS, then the DoT hostname.
  2. Firefox: Settings, Privacy and Security, DNS over HTTPS, then Custom and the DoH URL.
  3. Chrome and Edge: Settings, Privacy and security, Security, Use secure DNS, then Custom and the DoH URL.
  4. Windows 11: the DNS over HTTPS option sits in the same Edit dialog as the manual addresses.

A browser's own secure DNS setting overrides the system resolver. If you have set the addresses on the device or the router, either turn the browser setting off or point it at DNS4EU too.

If the change does not take effect

Four things hold on to the previous resolver.
  1. Reconnect to the network, or restart the device. Some systems keep the previous resolver until the connection is renewed.
  2. Clear the DNS cache. On Windows, run ipconfig /flushdns. On macOS, run sudo dscacheutil -flushcache.
  3. Check the browser. Chrome, Edge and Firefox can each use their own secure DNS, which bypasses whatever the device is set to.
  4. Check the router. If it hands out its own DNS over DHCP, a device left on Automatic keeps using it.

Whalebone quarterly report

DNS4EU Public Service Report, Q1 2026

What the free resolver actually carried and blocked between January and March 2026, three campaigns taken apart in detail, and where the traffic came from.

  • 4 billion requests resolved over the quarter
  • About 70,000 queries a second at peak
  • Over 200 domains blocked in February alone, in one WhatsApp account-takeover campaign running in more than 15 countries
  • Most used from Germany, the Netherlands, France, Czechia and Spain

Get the report

Not for business networks

ORGANIZATIONS

This resolver is built for individual citizens

It carries no reporting, no policy control and no support that an organization would need, and it is not intended for business networks. The quarterly report ends on the same point: corporate and public sector networks face different threat profiles and different regulatory requirements, and consumer protection is not enough for them.

  • Public institutions have their own service, with reporting and policy control
  • Private companies use Whalebone Immunity, the same protective DNS commercially
  • Both keep resolution on European infrastructure, under the same rules

Public institutions Private companies

Who it is for

The DNS4EU Public Service is provided exclusively for individual citizens and is not suited for organisations due to rate-limiting in place. See the Terms of Use for detail.

What is logged

The client's IP address is fully anonymised before being logged directly onto the resolver. No private data is collected anywhere, ensuring full alignment with GDPR and other European data protection regulations, your data stays yours. Find complete information in the DNS4EU Public Resolvers Policy.

Whether it is running

For the latest operational details and technical updates regarding the DNS4EU Public Service, please visit our Status Page.

Report a problem

Blocked something that should not be blocked?

Tell us the address and we will look at it. This is also the place to report a malicious site we are missing.

Court-ordered blocking is not a false positive, and every order is published under Legal information and compliance.

Download

Where should we send it?