DNS resolver registry · measured 2026-09-24
Which public DNS resolvers send EDNS Client Subnet?
Results
6 operators sent a client subnet; 12 sent none
| Resolver | ECS observed | DNSSEC |
|---|---|---|
| Google Public DNS | Sends /24 | Validates |
| Quad9 | Some addresses send /24 | Validates |
| OpenDNS | Sends /24 | Validates |
| AdGuard DNS | Sends /24 | Validates |
| AliDNS (Alibaba Cloud Public DNS) | Sends /25 | Does not validate |
| DNSPod Public DNS | Sends /24 | Does not validate |
| Cloudflare 1.1.1.1 | None sent | Validates |
| CleanBrowsing | None sent | Validates |
| Control D Free DNS | None sent | Validates |
| DNS.SB | None sent | Validates |
| Comodo Secure DNS | None sent | Does not validate |
| Yandex DNS | None sent | Does not validate |
| 114DNS | None sent | Does not validate |
| CIRA Canadian Shield | None sent | Does not validate |
| DNS4EU | None sent | Validates |
| SafeDNS | None sent | Does not validate |
| Surfshark DNS | None sent | Does not validate |
| DNS.WATCH | None sent | Validates |
Measured 2026-09-24 from one vantage point, three rounds per address, majority result. Anycast resolvers can behave differently from other networks. How we test
Quad9 documents a separate ECS-enabled variant (9.9.9.11), so it appears with some addresses sending a subnet. Mullvad and LibreDNS are encrypted-only and were not part of this plain DNS test.
Questions
Common questions
What does /24 mean for ECS?
The resolver sent the first 24 bits of your IPv4 address, which identifies a block of 256 addresses rather than your exact address.
Which DNS resolvers do not send ECS?
In our 2026-09-24 test: Cloudflare 1.1.1.1, CleanBrowsing, Control D Free DNS, DNS.SB, Comodo Secure DNS, Yandex DNS, 114DNS, CIRA Canadian Shield, DNS4EU, SafeDNS, Surfshark DNS, DNS.WATCH.
More lists
Other ways to compare
Research library
Network registries & open data
Find the reference behind a network decision. Browse the records, follow their sources and download the available datasets.