DNS resolver registry · measured 2026-09-24
Public DNS resolvers that validate DNSSEC
Validating
11 resolvers refused every mis-signed domain
Cloudflare 1.1.1.1
1.1.1.1 · 1.0.0.1
Google Public DNS
8.8.8.8 · 8.8.4.4
Quad9
9.9.9.9 · 149.112.112.112
OpenDNS
208.67.222.222 · 208.67.220.220
AdGuard DNS
94.140.14.14 · 94.140.15.15
CleanBrowsing
185.228.168.9 · 185.228.169.9
Control D Free DNS
76.76.2.0 · 76.76.10.0
Mullvad DNS
194.242.2.2
DNS.SB
185.222.222.222 · 45.11.45.11
DNS4EU
86.54.11.1 · 86.54.11.201
DNS.WATCH
84.200.69.80 · 84.200.70.40
Not validating
9 resolvers returned the mis-signed domains
Comodo Secure DNS
8.26.56.26 · 8.20.247.20
Yandex DNS
77.88.8.8 · 77.88.8.1
AliDNS (Alibaba Cloud Public DNS)
223.5.5.5 · 223.6.6.6
DNSPod Public DNS
119.29.29.29
114DNS
114.114.114.114 · 114.114.115.115
CIRA Canadian Shield
149.112.121.10 · 149.112.122.10
SafeDNS
195.46.39.39 · 195.46.39.40
Surfshark DNS
194.169.169.169
LibreDNS
116.202.176.26
Questions
Common questions
How can I test whether my DNS resolver validates DNSSEC?
Look up a deliberately mis-signed name such as dnssec-failed.org. A validating resolver returns SERVFAIL; a non-validating one returns an address. Check a second broken domain as well, because one test name can change.
Which free DNS resolvers validate DNSSEC?
In our 2026-09-24 test: Cloudflare 1.1.1.1, Google Public DNS, Quad9, OpenDNS, AdGuard DNS, CleanBrowsing, Control D Free DNS, Mullvad DNS, DNS.SB, DNS4EU, DNS.WATCH.
More lists
Other ways to compare
Research library
Network registries & open data
Find the reference behind a network decision. Browse the records, follow their sources and download the available datasets.