208.67.222.222: OpenDNS primary resolver

208.67.222.222 is the primary resolver address of OpenDNS, the oldest of the large free public DNS services. It started in 2005 and Cisco bought it in 2015 for 635 million dollars. It now runs as the free consumer tier of Cisco Umbrella, with optional account-based content filtering.

Public resolver208.67.222.222

Operated by Cisco Systems (OpenDNS / Cisco Umbrella, AS36692).

Live data

Fetched now, cached at the edge
Classification
public
Reverse DNS
resolver1.opendns.com
ASN
AS36692
AS name
Cisco OpenDNS, LLC
Netname
OPENDNS-NET-1
Registry
ARIN — American Registry for Internet Numbers
Country
United States
Block
208.67.216.0/21
Registered
2006-06-06T17:14:27-04:00
Abuse contact
rir-abuse@cisco.com
Blocklists
1 of 9 zones list it

Hostname: DNS PTR via 1.1.1.1 · ASN: IPinfo Lite · AS name: IPinfo Lite · Geo: IPinfo Lite · Registry record: rdap.arin.net. Registry data from RDAP. Reverse DNS and blocklist checks over DNS-over-HTTPS. Run a full lookup on 208.67.222.222.

208.67.222.222 is the primary resolver address of OpenDNS, the oldest of the large free public DNS services. It started in 2005 and Cisco bought it in 2015 for 635 million dollars. It now runs as the free consumer tier of Cisco Umbrella, with optional account-based content filtering.

Twenty years of history in one address

David Ulevitch launched OpenDNS in July 2006 after founding the company in 2005, years before Google or Cloudflare put resolvers on memorable addresses. The pitch was reliability and features rather than a short address: phishing protection, typo correction, and a dashboard where a parent or an administrator could pick which categories to block.

Cisco acquired it in August 2015 and folded the technology into Cisco Umbrella, its cloud security product. The free tier survived the acquisition and still runs on the same addresses.

What the address does by default

Without an account, 208.67.222.222 resolves names and blocks a phishing domain list. Content categories are not filtered. Register a network in the OpenDNS dashboard and the resolver applies your category choices to queries arriving from that network’s public IP, which is why the service needs a dynamic DNS updater client on a home connection with a changing address.

The related addresses are worth knowing:

Address pair Service
208.67.222.222, 208.67.220.220 OpenDNS Home, no content filter by default
208.67.222.123, 208.67.220.123 FamilyShield, adult content blocked, no account
146.112.61.104 The block page many OpenDNS filters redirect to

When you see it

  • In router presets, where OpenDNS has been a listed option since long before Cloudflare existed.
  • In school and small business firewalls, often paired with a dashboard policy.
  • In network documentation from the late 2000s and 2010s, where it was the standard third-party resolver recommendation.
  • In nslookup output during troubleshooting, as a second opinion against the ISP resolver.

How to configure it

  1. Windows: adapter properties, IPv4, preferred 208.67.222.222, alternate 208.67.220.220.
  2. macOS: System Settings, Network, Details, DNS, add both.
  3. Router: enter the pair on the WAN or LAN DNS page, then register the network at opendns.com if you want filtering.
  4. IPv6: 2620:119:35::35 and 2620:119:53::53.
  5. Dynamic address: install the OpenDNS Updater or configure your router’s DDNS client so the dashboard keeps tracking your public IP.

Privacy and policy

Query data falls under the Cisco privacy statement and the OpenDNS privacy policy. Cisco states that it collects DNS query data including the source IP for the free service and uses it for security research, product improvement, and threat intelligence. That is a materially different posture from Cloudflare or Quad9, both of which commit to not storing client addresses, so read the policy before choosing OpenDNS for privacy reasons.

What it is not

The address is not a filter on its own. Pointing a device at 208.67.222.222 with no dashboard configuration gives you phishing protection and nothing more, so parents expecting content blocking should use the FamilyShield pair instead. It is also not universally reachable: Cisco stopped answering OpenDNS queries in France and Portugal in 2024 in response to court-ordered blocking, so the address can time out for reasons that have nothing to do with your network.

Confirm which resolver your device really uses in /dns-leak-test.

Questions people ask

Is OpenDNS still free?
Yes. OpenDNS Home remains free and needs no account for basic resolution. A free account adds category filtering and per-network settings, and paid Cisco Umbrella tiers add reporting and policy controls.
What is the difference between 208.67.222.222 and FamilyShield?
FamilyShield uses 208.67.222.123 and 208.67.220.123 and blocks adult content by default with no account needed. The .222 address applies no content filter unless you register your network.
Why did I get an OpenDNS search page for a typo?
OpenDNS historically answered non-existent domains with its own guide page instead of NXDOMAIN. The behaviour can be turned off in the dashboard, and it breaks tools that expect a real NXDOMAIN.
Does OpenDNS block sites for legal reasons?
In 2024 Cisco withdrew OpenDNS resolution in France and Portugal after court orders required blocking. Availability varies by country as a result.

Related

Last reviewed 2026-09-04. editorial