9.9.9.9: Quad9 public DNS

9.9.9.9 is the primary address of Quad9, a free public DNS resolver run by a Swiss non-profit foundation. It differs from other large resolvers by refusing to answer for domains that appear on threat intelligence feeds, returning NXDOMAIN instead of the real address.

Public resolver9.9.9.9

Operated by Quad9 Foundation, Zurich (AS19281).

Live data

Fetched now, cached at the edge
Classification
public
Reverse DNS
dns9.quad9.net
ASN
AS19281
AS name
Quad9
Netname
CLEAN-97
Registry
ARIN — American Registry for Internet Numbers
Country
United States
Block
9.9.9.0/24
Registered
2017-09-13T14:00:44-04:00
Abuse contact
abuse@quad9.net
Blocklists
1 of 9 zones list it

Hostname: DNS PTR via 1.1.1.1 · ASN: IPinfo Lite · AS name: IPinfo Lite · Geo: IPinfo Lite · Registry record: rdap.arin.net. Registry data from RDAP. Reverse DNS and blocklist checks over DNS-over-HTTPS. Run a full lookup on 9.9.9.9.

9.9.9.9 is the primary address of Quad9, a free public DNS resolver run by a Swiss non-profit foundation. It differs from other large resolvers by refusing to answer for domains that appear on threat intelligence feeds, returning NXDOMAIN instead of the real address.

Who runs it

Quad9 launched in November 2017 as a joint effort by IBM Security, Packet Clearing House, and the Global Cyber Alliance. IBM contributed the 9.9.9.0/24 address space, PCH contributed its global anycast footprint, and GCA supplied the governance model. In February 2021 the operation moved to Zurich and became the Quad9 Foundation, a non-profit under Swiss law, which puts it under Swiss data protection rules rather than United States jurisdiction.

The service is funded by donations and sponsorship rather than by selling data.

What the blocking actually does

Quad9 subscribes to threat intelligence feeds from a published list of partners. When a lookup matches a domain on those feeds, the resolver answers NXDOMAIN, so the connection never starts. There is no interstitial page and no redirect to a warning server, which means a blocked domain looks to your browser like a domain that does not exist.

That design has a practical consequence. If a site fails to load on Quad9 and resolves fine on another resolver, check the domain on /blacklist-check before assuming the resolver is broken.

The address family

Address Behaviour
9.9.9.9 and 149.112.112.112 Blocklist on, DNSSEC validation on, no EDNS Client Subnet
9.9.9.10 and 149.112.112.10 No blocklist, no DNSSEC validation
9.9.9.11 and 149.112.112.11 Blocklist on, DNSSEC on, EDNS Client Subnet sent

149.112.112.112 sits in Packet Clearing House address space, so the pair spans two organisations as well as two prefixes.

When you see it

You meet 9.9.9.9 in router DNS presets, in security hardening checklists, in the DNS fields of small business firewalls, and in resolv.conf on servers where an administrator wanted a resolver that fails closed on known-bad domains. Several national CERTs and public sector networks recommend it, so it also appears in government IT guidance.

How to set it up

  1. Windows or macOS: enter 9.9.9.9 as preferred and 149.112.112.112 as alternate in the adapter’s DNS settings.
  2. IPv6: 2620:fe::fe and 2620:fe::9.
  3. Android 9 and later: Private DNS hostname dns.quad9.net, which gives DNS over TLS.
  4. DNS over HTTPS: https://dns.quad9.net/dns-query.
  5. Router: set the pair on the LAN DHCP page so every device inherits it.

Privacy and policy

The Quad9 privacy policy states that the service does not store client IP addresses at all. It records aggregate query counts, timestamps, and the city or region a query arrived in, for capacity planning and threat research, and it shares only aggregated data with its threat intelligence partners. Being a Swiss foundation, it is subject to the Swiss Federal Act on Data Protection.

What it is not

Quad9 is not an ad blocker and not a parental filter. It is not a substitute for endpoint security either, because it only sees domain names: a malicious file downloaded from a domain nobody has reported yet resolves normally. And blocking at the resolver only works when the device uses the resolver, so a browser with its own DNS over HTTPS setting bypasses it entirely. Check which resolver is really in use with /dns-leak-test.

Questions people ask

Who owns Quad9?
The Quad9 Foundation, a non-profit under Swiss law based in Zurich. The service began in 2017 as a project of IBM Security, Packet Clearing House, and the Global Cyber Alliance, and moved its legal home to Switzerland in 2021.
What does 9.9.9.9 block?
Domains flagged as malware command and control, phishing, or exploit hosts by the threat intelligence partners Quad9 lists publicly. It does not block ads, trackers, or adult content.
How do I use Quad9 without blocking?
Use 9.9.9.10 and 149.112.112.10. Those addresses skip the blocklist and also skip DNSSEC validation.
Does Quad9 log my IP address?
Quad9's privacy policy states it does not store client IP addresses. It keeps aggregate counts and the geographic region of queries for capacity and threat research.

Related

Last reviewed 2026-09-04. editorial