dnsdome
Setup guide · Any router

Set dnsdome as the DNS server on any router

The three settings that exist on every home router, in the right order, to send the whole network through dnsdome: WAN DNS, DHCP DNS, and a public IP on your allowlist. Plus how to verify and the mistakes that leak queries.

Last updated 24 September 2026

Why the router

Every device asks the router for DNS by default. Change the router once and phones, laptops, TVs, consoles and smart plugs are all filtered, with no software on any of them. It is the setup we recommend for a household or a small office, and it takes about five minutes.

The steps

  1. Sign in to the dnsdome panel, open your profile and add your network's public IP to the allowlist. The panel shows the IP you are connecting from; on a home connection that is the router's WAN address.
  2. Open the router's admin page, usually 192.168.0.1, 192.168.1.1 or the address printed on the router. Find the Internet, WAN or Network settings.
  3. Change the DNS setting from Automatic or from ISP to Manual, and set the primary DNS to 87.244.198.165. Leave the secondary empty or set it to the same address. A different secondary is a leak, not a backup: routers use it whenever it answers first.
  4. If the router has a separate DHCP or LAN DNS field that hands servers to clients, either leave it pointed at the router itself, or set it to 87.244.198.165 too. Either way all queries end up at dnsdome.
  5. Save and reboot the router. Devices pick up the change when their DHCP lease renews; reconnect Wi-Fi on a phone to hurry it along.
  6. Verify: on any device, load a website, then look at the panel's query log. Entries appear within a minute. With Ads & Tracking on, visiting doubleclick.net shows as blocked.

Where the setting hides, by brand

RouterPath
TP-LinkAdvanced → Network → Internet → Advanced settings → Use the following DNS addresses. DHCP hand-out under Advanced → Network → DHCP Server.
ASUSWAN → Internet Connection → WAN DNS Setting → Connect to DNS server automatically: No. Newer firmware also offers DNS-over-TLS under WAN → DNS Privacy Protocol; use your profile hostname <token>.dns.dnsdome.com there.
NetgearInternet → Domain Name Server (DNS) Address → Use These DNS Servers.
LinksysConnectivity → Local Network → DHCP Server → Static DNS 1.
Google Wifi / Nest WifiGoogle Home app → Wi-Fi → Settings → Advanced networking → DNS → Custom.
Amazon eeroeero app → Settings → Network settings → DNS → Customized DNS.
Huawei / ZTE ISP boxesNetwork → LAN → DHCP Server → Primary DNS. WAN DNS is often locked by the ISP; the LAN DHCP field is what matters.
Telekom / Orange / O2 ISP routersSame idea: the DHCP DNS field under LAN settings. If everything is locked, put your own router behind the ISP box and set DNS there.

Have a MikroTik, OpenWrt, pfSense, UniFi or Fritz!Box? Those have their own guides in Docs, including encrypted upstream that does not depend on your public IP.

Three ways queries still leak

My public IP changes

Plain DNS identifies your network by IP. When your ISP gives you a new one, dnsdome refuses your queries until you update the allowlist, and devices see "no internet" for DNS. Options: a router that supports DNS-over-TLS or DNS-over-HTTPS upstream (the token identifies you instead), a static IP from your ISP, or simply re-adding the IP in the panel when it happens. Home connections in most of Europe keep an IP for weeks between changes.

Will this slow my internet?
DNS is a few milliseconds per new domain and the router caches answers. Pages that load ads and trackers get faster, because those requests never leave the house.
Can I still reach a blocked site when I need to?
Yes. Add the domain to the profile's allowlist in the panel, or use Pause protection for a few minutes; it switches itself back on.
Guests on my Wi-Fi are filtered too?
Yes, everything behind the router is. Guests who prefer not to be can use their mobile data. If you would rather give the guest network a lighter policy, put it on its own profile; the UniFi guide shows how.

Put a dome over your network.

Free plan, no card. Create a profile, point your DNS, and watch the first blocked queries within minutes.