# Do I have to choose DNS servers?

**URL:** https://boards.straightdope.com/t/do-i-have-to-choose-dns-servers/805636
**Category:** Factual Questions
**Created:** [December 31, 2017, 4:40pm UTC](https://boards.straightdope.com/t/do-i-have-to-choose-dns-servers/805636 "2017-12-31T16:40:44Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![Napier](https://avatars.discourse-cdn.com/v4/letter/n/ce73a5/32.png) [@Napier](https://boards.straightdope.com/u/Napier)
#### Post date: [December 31, 2017, 4:40pm UTC](https://boards.straightdope.com/t/do-i-have-to-choose-dns-servers/805636/1 "2017-12-31T16:40:44Z")

</div>

Do I have to specify DNS servers when configuring my home Mac, my home router, my wireless access points, and various other little devices on my home LAN?

Or is “normal” home user behavior to leave all the configuration boxes in these devices blank?

I always figured I did have to, as there were spaces there to be filled out, and when I set up my home network many years ago it somehow seemed necessary. But now I am picking up clues on the Web that normal behavior is to leave all these blank and let them appear somehow by magic (or maybe DHCP coming down from my ISP).

Note, I did use an optimization program (namebench.app) that ran tests for many minutes and then told me 8.8.8.8 was the fastest for me, so I may want to overwrite defaults. But my main question is whether specifying them is something I should assume I am supposed to do, or something most people don’t do.

Thanks!!

---

<div class="post-metadata">

### Author: ![voltaire](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/voltaire/32/313_2.png) [@voltaire](https://boards.straightdope.com/u/voltaire)
#### Post date: [December 31, 2017, 4:46pm UTC](https://boards.straightdope.com/t/do-i-have-to-choose-dns-servers/805636/2 "2017-12-31T16:46:39Z")

</div>

If you leave them on auto, they will use your ISPs DNS. If you use 8.8.8.8 and 8.8.4.4. those are Google’s DNS servers, which may or may not provide better performance/privacy for your purposes.

---

<div class="post-metadata">

### Author: ![Napier](https://avatars.discourse-cdn.com/v4/letter/n/ce73a5/32.png) [@Napier](https://boards.straightdope.com/u/Napier)
#### Post date: [December 31, 2017, 4:51pm UTC](https://boards.straightdope.com/t/do-i-have-to-choose-dns-servers/805636/3 "2017-12-31T16:51:39Z")

</div>

“leave them on auto” means leave them blank, right?

---

<div class="post-metadata">

### Author: ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)
#### Post date: [December 31, 2017, 4:53pm UTC](https://boards.straightdope.com/t/do-i-have-to-choose-dns-servers/805636/4 "2017-12-31T16:53:52Z")

</div>

ETA: Yes, blank = auto.

More strictly, blank / auto will use whichever DNS your ISP has configured their DHCP to provide to your router. It’s probably their own, but not necessarily.

Some folks get real religious about not using their ISP’s DNS because, gasp, the ISP might do something nefarious with it :eek:. Given that they’re transporting 100% of your traffic that always seemed to me like a pretty silly concern. If they wanted to f\*\*\* with you DNS would be about #437 on their list of options.

If they were really serious, your ISP could also intercept all traffic from your router to known DNS servers and internally redirect it to theirs. Without you ever being the wiser.

All that’s theoretical mumbo jumbo and wannabe guru internet blather. IMO the best advice is leave it blank. DNS is far from the limiting factor in the performance of ordinary people’s internet usage. And a wrong or obsolete config will leave your internet mostly dead and you scratching your head. For most amateur values of “you”. Fiddling with it is about 99% downside and 1% upside.

---

<div class="post-metadata">

### Author: ![Joey\_P](https://avatars.discourse-cdn.com/v4/letter/j/919ad9/32.png) [@Joey\_P](https://boards.straightdope.com/u/Joey_P)
#### Post date: [December 31, 2017, 4:58pm UTC](https://boards.straightdope.com/t/do-i-have-to-choose-dns-servers/805636/5 "2017-12-31T16:58:09Z")

</div>

I use the google ones. Before that, IIRC, I would set them to the address for my router, typically 192.168.1.1 which, I believe will just then go through your IP.

---

<div class="post-metadata">

### Author: ![Rysto](https://avatars.discourse-cdn.com/v4/letter/r/ecccb3/32.png) [@Rysto](https://boards.straightdope.com/u/Rysto)
#### Post date: [December 31, 2017, 5:01pm UTC](https://boards.straightdope.com/t/do-i-have-to-choose-dns-servers/805636/6 "2017-12-31T17:01:50Z")

</div>

> [@LSLGuy](#):
>
> Some folks get real religious about not using their ISP’s DNS because, gasp, the ISP might do something nefarious with it :eek:. Given that they’re transporting 100% of your traffic that always seemed to me like a pretty silly concern. If they wanted to f\*\*\* with you DNS would be about #437 on their list of options.

This isn’t theoretical problem. ISPs have been known to use DNS servers that redirect people to advertising sites when they mistype a domain name. My own ISP was doing that to me for some time (I use the Google DNS now, so I’m not sure if they still do it)

---

<div class="post-metadata">

### Author: ![Napier](https://avatars.discourse-cdn.com/v4/letter/n/ce73a5/32.png) [@Napier](https://boards.straightdope.com/u/Napier)
#### Post date: [December 31, 2017, 5:13pm UTC](https://boards.straightdope.com/t/do-i-have-to-choose-dns-servers/805636/7 "2017-12-31T17:13:31Z")

</div>

My network appliances typically have spaces for DNS servers, too. For example, my network security cameras, and my network IP clock, and my wireless network extenders. Is this so I can override my overall network behavior for that device in particular for some reason? If I leave them all blank, they will wind up following whatever lead my router is set up for, correct?

---

<div class="post-metadata">

### Author: ![Napier](https://avatars.discourse-cdn.com/v4/letter/n/ce73a5/32.png) [@Napier](https://boards.straightdope.com/u/Napier)
#### Post date: [December 31, 2017, 5:15pm UTC](https://boards.straightdope.com/t/do-i-have-to-choose-dns-servers/805636/8 "2017-12-31T17:15:08Z")

</div>

> [@Rysto](#):
>
> This isn’t theoretical problem. ISPs have been known to use DNS servers that redirect people to advertising sites when they mistype a domain name. My own ISP was doing that to me for some time (I use the Google DNS now, so I’m not sure if they still do it)

Interesting! I often get redirects to ad sites, maybe when I’ve mistyped. I may try blank versus 8.8.8.8 to test this. Thanks!

---

<div class="post-metadata">

### Author: ![Riemann](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/riemann/32/3133_2.png) [@Riemann](https://boards.straightdope.com/u/Riemann)
#### Post date: [December 31, 2017, 5:18pm UTC](https://boards.straightdope.com/t/do-i-have-to-choose-dns-servers/805636/9 "2017-12-31T17:18:54Z")

</div>

I found that the Comcast default DNS servers were just failing to respond with annoying frequency, and that switching to Google solved the problem.

---

<div class="post-metadata">

### Author: ![BlueMerle](https://avatars.discourse-cdn.com/v4/letter/b/a87d85/32.png) [@BlueMerle](https://boards.straightdope.com/u/BlueMerle)
#### Post date: [December 31, 2017, 5:18pm UTC](https://boards.straightdope.com/t/do-i-have-to-choose-dns-servers/805636/10 "2017-12-31T17:18:55Z")

</div>

> [@Rysto](#):
>
> This isn’t theoretical problem. ISPs have been known to use DNS servers that redirect people to advertising sites when they mistype a domain name. My own ISP was doing that to me for some time (I use the Google DNS now, so I’m not sure if they still do it)

Agreed. It’s far from theoretical.

In addition to Google DNS there’s a new player on the scene that’s getting high marks from various sources, [Quad9](https://www.quad9.net/#/about)

Here’s one [comparison of the major players](https://hackernoon.com/dns-performance-comparison-google-quad9-opendns-norton-cleanbrowsing-and-yandex-d62d24e38f98) and Quad9 ranked 2nd overall.

I’m currently using Quad9 on one of my laptops at home and have been pleased with it’s performance.

---

<div class="post-metadata">

### Author: ![Doug\_K](https://avatars.discourse-cdn.com/v4/letter/d/b5ac83/32.png) [@Doug\_K](https://boards.straightdope.com/u/Doug_K)
#### Post date: [December 31, 2017, 5:55pm UTC](https://boards.straightdope.com/t/do-i-have-to-choose-dns-servers/805636/11 "2017-12-31T17:55:34Z")

</div>

> [@LSLGuy](#):
>
> ETA: Yes, blank = auto.
> 
> More strictly, blank / auto will use whichever DNS your ISP has configured their DHCP to provide to your router. It’s probably their own, but not necessarily.
> 
> Some folks get real religious about not using their ISP’s DNS because, gasp, the ISP might do something nefarious with it :eek:. Given that they’re transporting 100% of your traffic that always seemed to me like a pretty silly concern. If they wanted to f\*\*\* with you DNS would be about #437 on their list of options.
> 
> If they were really serious, your ISP could also intercept all traffic from your router to known DNS servers and internally redirect it to theirs. Without you ever being the wiser.
> 
> All that’s theoretical mumbo jumbo and wannabe guru internet blather. IMO the best advice is leave it blank. DNS is far from the limiting factor in the performance of ordinary people’s internet usage. And a wrong or obsolete config will leave your internet mostly dead and you scratching your head. For most amateur values of “you”. Fiddling with it is about 99% downside and 1% upside.

A lot of ISP’s DNS does do something at least arguably nefarious: Highjacking the [NXDOMAIN](https://en.wikipedia.org/wiki/DNS_hijacking) response you’re supposed get if you type in a nonexistent domain and replacing it with a “helpful” search page. It’s a violation of web standards and can cause vulnerability to cross-scripting attacks.

---

<div class="post-metadata">

### Author: ![friedo](https://avatars.discourse-cdn.com/v4/letter/f/8edcca/32.png) [@friedo](https://boards.straightdope.com/u/friedo)
#### Post date: [December 31, 2017, 5:59pm UTC](https://boards.straightdope.com/t/do-i-have-to-choose-dns-servers/805636/12 "2017-12-31T17:59:53Z")

</div>

> [@Napier](#):
>
> My network appliances typically have spaces for DNS servers, too. For example, my network security cameras, and my network IP clock, and my wireless network extenders. Is this so I can override my overall network behavior for that device in particular for some reason?

That, or so you can configure them manually in the event that your network does not have a DHCP setup.

---

<div class="post-metadata">

### Author: ![engineer\_comp\_geek](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/engineer_comp_geek/32/504_2.png) [@engineer\_comp\_geek](https://boards.straightdope.com/u/engineer_comp_geek)
#### Post date: [December 31, 2017, 6:01pm UTC](https://boards.straightdope.com/t/do-i-have-to-choose-dns-servers/805636/13 "2017-12-31T18:01:30Z")

</div>

On most machines, you have a choice to either use a DHCP server or to manually configure your IP and DNS servers. Most operating systems have either a check box or a radio button to choose one or the other. Macs are apparently fairly unique in that you just leave them blank to choose DHCP. I’ve never seen any other operating system do it that way.

Almost everyone these days uses DHCP. It’s pretty rare to manually configure a DNS server. I do it in my home because all of the computers and devices in my home are on a private local network and don’t use DHCP. I manually configure everything to use the gateway as their DNS server, and the internet gateway uses DHCP to get its IP and DNS from Comcast.

There’s generally no reason to use anything other than what your ISP provides, except in cases where your ISP is a sneaky bastard and forwards you to advertising and such if the DNS lookup fails (as noted upthread) or if your DNS server is unreliable.

> [@Riemann](#):
>
> I found that the Comcast default DNS servers were just failing to respond with annoying frequency, and that switching to Google solved the problem.

I’ve never had an issue with Comcast’s DNS servers. Must be the DNS servers in your particular area.

I’ve had plenty of other issues with Comcast, and if I had any choice at all I would use a different internet provider, but DNS hasn’t been an issue for me.

---

<div class="post-metadata">

### Author: ![Napier](https://avatars.discourse-cdn.com/v4/letter/n/ce73a5/32.png) [@Napier](https://boards.straightdope.com/u/Napier)
#### Post date: [December 31, 2017, 6:37pm UTC](https://boards.straightdope.com/t/do-i-have-to-choose-dns-servers/805636/14 "2017-12-31T18:37:09Z")

</div>

> [@engineer\_comp\_geek](#):
>
> On most machines, you have a choice to either use a DHCP server or to manually configure your IP and DNS servers. Most operating systems have either a check box or a radio button to choose one or the other. Macs are apparently fairly unique in that you just leave them blank to choose DHCP. I’ve never seen any other operating system do it that way.
> 
> […]

Not only this, but Macs, or at least the one I’m working with right now, put DNS addresses into those spaces, but write them in gray. One might take a clue from this that they are being generated automatically, or can’t be changed for whatever reason.

Thanks!!

---

<div class="post-metadata">

### Author: ![Napier](https://avatars.discourse-cdn.com/v4/letter/n/ce73a5/32.png) [@Napier](https://boards.straightdope.com/u/Napier)
#### Post date: [December 31, 2017, 6:42pm UTC](https://boards.straightdope.com/t/do-i-have-to-choose-dns-servers/805636/15 "2017-12-31T18:42:06Z")

</div>

> [@Doug\_K](#):
>
> A lot of ISP’s DNS does do something at least arguably nefarious: Highjacking the [NXDOMAIN](https://en.wikipedia.org/wiki/DNS_hijacking) response you’re supposed get if you type in a nonexistent domain and replacing it with a “helpful” search page. It’s a violation of web standards and can cause vulnerability to cross-scripting attacks.

Yup. That’s what mine does. Putting 8.8.8.8 into my Mac settings above the existing ones prevents this.

---

<div class="post-metadata">

### Author: ![Napier](https://avatars.discourse-cdn.com/v4/letter/n/ce73a5/32.png) [@Napier](https://boards.straightdope.com/u/Napier)
#### Post date: [December 31, 2017, 6:44pm UTC](https://boards.straightdope.com/t/do-i-have-to-choose-dns-servers/805636/16 "2017-12-31T18:44:05Z")

</div>

> [@Napier](#):
>
> Not only this, but Macs, or at least the one I’m working with right now, put DNS addresses into those spaces, but write them in gray. One might take a clue from this that they are being generated automatically, or can’t be changed for whatever reason.
> 
> Thanks!!

Wait, wrong, this isn’t it (and I missed the edit window). They were gray because I hadn’t authenticated as an admin.

---

<div class="post-metadata">

### Author: ![ftg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ftg/32/2801_2.png) [@ftg](https://boards.straightdope.com/u/ftg)
#### Post date: [December 31, 2017, 9:10pm UTC](https://boards.straightdope.com/t/do-i-have-to-choose-dns-servers/805636/17 "2017-12-31T21:10:02Z")

</div>

I did a DNS test recently using the older program [DNSBench.exe](https://www.grc.com/dns/benchmark.htm) from Gibson Research. Interesting to confusing results.

One thing I saw reading up about choosing a DNS server is some unexpected complications. Example:

Many companies have servers provided by Akamai. Akamai takes the DNS lookup IP\* as indicating where the user is and directs the user to the “nearest” server farm.

If you use a DNS server not in your region, or even country, this can impact the service significantly.

This is considered an error by all but Akamai who considers it a feature. :rolleyes:

- While using the users’ actual IP address is better, it takes more time to do a lookup of geographic location as opposed to a much smaller table of common DNS servers. Fractions of a second count here.

---

<div class="post-metadata">

### Author: ![CookingWithGas](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cookingwithgas/32/485_2.png) [@CookingWithGas](https://boards.straightdope.com/u/CookingWithGas)
#### Post date: [December 31, 2017, 9:14pm UTC](https://boards.straightdope.com/t/do-i-have-to-choose-dns-servers/805636/18 "2017-12-31T21:14:46Z")

</div>

> [@Doug\_K](#):
>
> A lot of ISP’s DNS does do something at least arguably nefarious: Highjacking the [NXDOMAIN](https://en.wikipedia.org/wiki/DNS_hijacking) response you’re supposed get if you type in a nonexistent domain and replacing it with a “helpful” search page. It’s a violation of web standards and can cause vulnerability to cross-scripting attacks.

Verizon does this to me. Annoying but neither deceptive nor harmful. I am unaware of cross-scripting attacks and how this presents a vulnerability.

---

<div class="post-metadata">

### Author: ![Napier](https://avatars.discourse-cdn.com/v4/letter/n/ce73a5/32.png) [@Napier](https://boards.straightdope.com/u/Napier)
#### Post date: [December 31, 2017, 9:15pm UTC](https://boards.straightdope.com/t/do-i-have-to-choose-dns-servers/805636/19 "2017-12-31T21:15:55Z")

</div>

> [@ftg](#):
>
> I did a DNS test recently using the older program [DNSBench.exe](https://www.grc.com/dns/benchmark.htm) from Gibson Research […[

I would have used this, but it’s for PCs (and Macs running Windows emulators), which leaves me out. Still, I may run it on Mrs. Napier’s PC if she lets me. It appears to be way more informative than namebench.app. Though, namebench gives you the single fastest result, which I guess is all that gets used in the end.

---

<div class="post-metadata">

### Author: ![don\_t\_ask](https://avatars.discourse-cdn.com/v4/letter/d/e68b1a/32.png) [@don\_t\_ask](https://boards.straightdope.com/u/don_t_ask)
#### Post date: [December 31, 2017, 9:26pm UTC](https://boards.straightdope.com/t/do-i-have-to-choose-dns-servers/805636/20 "2017-12-31T21:26:01Z")

</div>

In Australia the government’s crackdown on internet piracy has been implemented via a [big expansion for Australia’s anti-piracy website blocking regime](https://www.computerworld.com.au/article/626178/big-expansion-australia-anti-piracy-website-blocking-regime/). Someone who uses the same ISP as me was recently complaining about all the sites he could no longer access. I was puzzled that I had no such problems until I recalled that years ago I had started using Google’s DNS servers to get around problems that seemed to have me editing my _hosts_ file every few weeks.

[Next page](https://boards.straightdope.com/t/do-i-have-to-choose-dns-servers/805636.md?page=2)
