208.67.220.220: OpenDNS secondary
208.67.220.220 is the secondary resolver address for OpenDNS, now part of Cisco Umbrella. It applies the same account policies and phishing protection as 208.67.222.222 and is announced from a separate /24, so the pair survives a routing problem with either prefix.
Operated by Cisco Systems (OpenDNS / Cisco Umbrella, AS36692).
Live data
- Classification
- public
- Reverse DNS
- resolver2.opendns.com
- ASN
- AS36692
- AS name
- Cisco OpenDNS, LLC
- Netname
- OPENDNS-NET-1
- Registry
- ARIN — American Registry for Internet Numbers
- Country
- United States
- Block
- 208.67.216.0/21
- Registered
- 2006-06-06T17:14:27-04:00
- Abuse contact
- rir-abuse@cisco.com
- Blocklists
- 1 of 9 zones list it
Hostname: DNS PTR via 1.1.1.1 · ASN: IPinfo Lite · AS name: IPinfo Lite · Geo: IPinfo Lite · Registry record: rdap.arin.net. Registry data from RDAP. Reverse DNS and blocklist checks over DNS-over-HTTPS. Run a full lookup on 208.67.220.220.
208.67.220.220 is the secondary resolver address for OpenDNS, now part of Cisco Umbrella. It applies the same account policies and phishing protection as 208.67.222.222 and is announced from a separate /24, so the pair survives a routing problem with either prefix.
The pair and the pattern
OpenDNS chose two /24s inside 208.67.216.0/21, a block registered to OpenDNS and now held under Cisco. Both addresses use repeated digits so they can be dictated over the phone, a design decision from 2006 when the alternative was memorising an ISP resolver nobody advertised.
Cisco announces the prefixes from AS36692 and anycasts them from its Umbrella data centres. A whois lookup on either address returns Cisco OpenDNS as the organisation.
Why filtering follows the network, not the address
OpenDNS applies policy by looking at the public IP a query arrives from and matching it against a network registered in the dashboard. That mechanism has two consequences worth planning for.
First, both resolver addresses behave identically for you, because they consult the same account. There is no “filtered” and “unfiltered” member of the pair.
Second, home connections with a changing public IP need a dynamic DNS updater, or the dashboard loses track of the network and the resolver silently falls back to unfiltered answers. Most consumer routers can run that updater in their DDNS section.
When you see it
The address shows up in the alternate DNS field on router setup pages, in the second nameserver entry in /etc/resolv.conf, and in printed IT handbooks from the era when OpenDNS was the default third-party recommendation. School and library networks that adopted OpenDNS filtering in the 2010s still carry the pair in their DHCP scopes.
How to configure it
- Windows: alternate DNS server field, with
208.67.222.222as preferred. - macOS: System Settings, Network, Details, DNS, second entry.
- Linux:
nameserver 208.67.220.220as the second line, or inresolved.conf. - IPv6:
2620:119:53::53pairs with2620:119:35::35. - FamilyShield instead: swap in
208.67.220.123and208.67.222.123for adult content blocking without an account.
Privacy and policy
Use of either address falls under the Cisco privacy statement and the OpenDNS service terms. Cisco collects query data including source IP addresses from the free service and uses it for security research and threat intelligence feeds that support its commercial products. That is the trade the free tier makes explicit, and it is a different bargain from resolvers that commit to discarding client addresses.
Court-ordered blocking has also affected availability. Cisco stopped resolving for users in France and Portugal in 2024 rather than implement site blocking there, so both OpenDNS addresses can be unreachable depending on where you are.
What it is not
208.67.220.220 is not a backup that bypasses your policy, and it is not a separate product. It is also not required: OpenDNS works with a single address configured, though listing only one removes the redundancy the pair exists for. If neither address answers, test a resolver from another operator such as 9.9.9.9 before assuming your connection is down.
Compare answers between providers in /dns-lookup.
Questions people ask
- Do the two OpenDNS addresses apply the same filtering rules?
- Yes. Filtering is tied to the network your query comes from, not to the resolver address, so both apply whatever policy your registered network has.
- Is 208.67.220.220 the FamilyShield address?
- No. FamilyShield is 208.67.220.123 and 208.67.222.123. The .220 address applies no content filter unless you register the network in the dashboard.
- Can I mix OpenDNS with another provider?
- You can list them together, but the results become unpredictable. Your device may query either one, so filtering will apply inconsistently. Pick one provider and list both of its addresses.
Related
Last reviewed 2026-09-04. editorial