Private DNS in Windows 11 usually refers to configuring a custom DNS resolver and, when supported, protecting DNS requests with DNS over HTTPS (DoH). DNS, or Domain Name System, translates website names such as example.com into the IP addresses that your computer needs to connect to a server.
Changing your DNS can sometimes improve reliability, security, privacy, or content filtering, depending on the DNS provider you choose. When you enable DNS over HTTPS, Windows encrypts DNS queries between your PC and the supported DNS resolver, making those requests harder for others on the network to inspect or modify. Microsoft confirms that Windows 11 supports encrypted DNS through DoH.
If you’re new to DNS settings, don’t worry. You don’t need to change complicated network settings. Windows 11 lets you configure the DNS server address and its encryption preference directly through Settings.
Add and Use Private DNS in Windows 11 [Easy Steps]

To add a private DNS server in Windows 11:
- Open Settings > Network & internet.
- Select Wi-Fi or Ethernet, depending on how your PC connects to the internet.
- Open the connected network and find DNS server assignment.
- Select Edit, change the setting to Manual, and turn on IPv4.
- Enter your preferred DNS server addresses in the Preferred DNS and Alternate DNS fields.
- Set DNS over HTTPS to On (automatic template) or On (manual template) when the resolver supports it.
- Select Save, reconnect to the network if necessary, and test your internet connection.
The process is straightforward, but it helps to understand what you’re actually changing. Let’s go into detail!
Step 1: Open Windows 11 Network Settings
Start by opening the Windows Settings app. You can do this quickly by pressing Windows + I on your keyboard. Once Settings opens, select Network & internet from the navigation panel.
You’ll see options such as Wi-Fi, Ethernet, VPN, proxy, and other networking settings. Choose the connection you’re currently using.
If your PC is connected wirelessly, select Wi-Fi. If you’re using a network cable, select Ethernet. The available options can vary slightly depending on your connection type, but the DNS configuration is available through the network settings.
Step 2: Open Your Active Network Connection
If you’re using Wi-Fi, select the Wi-Fi network you’re currently connected to. Windows will open the settings for that connection.
If you’re using Ethernet, select Ethernet and then open the connected network interface.
The goal here is to reach the settings for the network adapter that is actually providing your internet connection. If your computer has both Wi-Fi and Ethernet available, make sure you change the settings for the connection you’re actively using.
You don’t need to modify unrelated network adapters. Changing the wrong adapter won’t affect the connection you’re currently using.
Step 3: Find DNS Server Assignment
Scroll through the network settings until you find DNS server assignment. This area tells Windows where it gets its DNS server information.
You’ll normally see Automatic (DHCP) here. This means your router or network automatically supplies the DNS server information to Windows.
To use a custom DNS provider, select Edit next to DNS server assignment.
A small Edit DNS settings window will appear. This is where you’ll make the main change.
Step 4: Change DNS Assignment to Manual
In the Edit DNS settings window, open the dropdown currently showing Automatic (DHCP) and select Manual.
After selecting Manual, Windows will display switches for IPv4 and, depending on your configuration, IPv6.
For a beginner-friendly setup, start with IPv4. Turn the IPv4 switch on.
You’ll now see fields for Preferred DNS and Alternate DNS. These are the fields where you enter the DNS addresses supplied by your chosen DNS provider.
You should use addresses from a reputable DNS provider rather than entering random addresses found online. The DNS resolver you choose determines which service handles your DNS requests, so selecting a provider you trust is important.
Step 5: Enter the Preferred and Alternate DNS Addresses
Enter your chosen provider’s primary address in Preferred DNS and its secondary address in Alternate DNS.
For example, if your DNS provider gives you two IPv4 addresses, enter the first address in Preferred DNS and the second one in Alternate DNS.
Be careful when typing these addresses. A single incorrect number can prevent DNS resolution and make websites appear to be offline even though your internet connection itself is working.
You don’t need to enter an IP address, subnet mask, or gateway just to change DNS. Windows can continue using DHCP for your normal IP configuration while you manually specify the DNS servers. Microsoft’s current Windows networking guidance supports manually specifying DNS server addresses while keeping the other IP settings managed automatically.
Step 6: Configure DNS over HTTPS
Now look for the DNS over HTTPS setting. This is the part that makes the configuration more privacy-focused.
Windows 11 can provide options such as Off, On (automatic template), and On (manual template), depending on the DNS server you’ve entered and your Windows configuration.
Choose On (automatic template) if Windows recognizes your DNS provider and can automatically determine the appropriate DoH configuration.
If your provider gives you a specific DoH template, choose On (manual template) and enter the template supplied by that provider.
A DoH template commonly uses an HTTPS address ending in something such as /dns-query. Don’t invent a template yourself. Use the exact template provided by your DNS provider.
If the DoH option is unavailable or remains disabled, your selected DNS server may not be recognized as supporting DoH, or the computer may be controlled by an organization policy. Microsoft notes that Windows can also be configured by administrative policies that control DoH behavior.
Step 7: Decide Whether to Allow Unencrypted Fallback
If Windows displays the Fallback to plaintext option, pay attention to this setting.
When fallback is enabled, Windows can send a DNS query without encryption if it cannot complete the request through HTTPS. This can improve compatibility, but it means some DNS queries could potentially be sent without encryption.
When fallback is disabled, Windows won’t switch to unencrypted DNS if the encrypted request cannot be completed. This provides a stricter encryption approach, although certain networks or DNS providers may not work correctly with that configuration. Microsoft documents both behaviors in its Windows DNS settings.
For everyday users, the best choice depends on whether compatibility or strict encryption is your priority. If you’re experimenting with DoH for the first time, you can start with the provider’s recommended setting.
Step 8: Save the DNS Configuration
Once you’ve entered the DNS addresses and selected your preferred encryption option, select Save.
Windows should return you to the network settings page.
At this point, your PC should begin using the new DNS configuration. You normally don’t need to restart Windows.
If websites don’t load immediately, wait a few seconds and try refreshing the page. You can also disconnect and reconnect to Wi-Fi if the connection doesn’t appear to update properly.
Step 9: Test Your Internet Connection
Open your web browser and visit a few familiar websites.
If everything loads normally, your DNS configuration is probably working correctly.
If websites fail to open, return to Settings > Network & internet > Wi-Fi or Ethernet > DNS server assignment > Edit and check the DNS addresses carefully.
Also check whether DNS over HTTPS is configured correctly. If you selected a manual DoH template, verify that the template exactly matches the information supplied by your DNS provider.
If the problem continues, temporarily return to Automatic (DHCP). If the internet immediately starts working again, the custom DNS configuration is likely the source of the problem.
Understand What Private DNS Does
It’s important not to confuse private DNS with complete internet anonymity.
DNS over HTTPS encrypts the DNS communication between your Windows 11 computer and the DoH resolver. This helps protect DNS queries from passive monitoring and certain forms of interception or manipulation.
However, DoH doesn’t encrypt every connection your computer makes. Your normal website traffic is protected by HTTPS when a website supports it, while other network traffic has its own security mechanisms.
Your selected DNS provider can also receive DNS requests because it is handling the DNS resolution. That’s why choosing a trusted DNS provider matters.
Faqs
What is Private DNS in Windows 11?
Private DNS generally means using a DNS resolver other than the one automatically provided by your network, often with DNS over HTTPS enabled for encrypted DNS queries. Windows 11 provides settings that let you manually specify DNS servers and configure DoH.
Does Private DNS make my internet completely private?
No. Private DNS does not make you anonymous online. It mainly protects DNS queries while they travel between your computer and the configured DNS resolver. Other parts of your internet activity can still be visible to websites, services, network administrators, or other parties depending on the connection.
Is DNS over HTTPS better than regular DNS?
For privacy and security, DNS over HTTPS provides an important advantage because DNS queries are transmitted through an encrypted HTTPS connection. Traditional DNS traffic can be sent without encryption.
Can I use any DNS server in Windows 11?
You can manually enter a DNS server address, but you should use a reputable DNS provider and follow its published configuration instructions. If you want DoH, the DNS provider must also support the appropriate encrypted DNS configuration.
The selected DNS server may not be recognized as a supported DoH server, the provider may not support DoH, or your PC could have an organization-managed DNS policy. Windows also provides administrative controls for DNS encryption.
Can I go back to my original DNS settings?
Yes. Go to Settings > Network & internet > your connection > DNS server assignment > Edit, change Manual back to Automatic (DHCP), and select Save. Windows will then obtain DNS information automatically from your network.
Will changing DNS make my internet faster?
It can sometimes improve DNS lookup responsiveness, particularly if your previous DNS resolver was slow or unreliable. However, changing DNS does not automatically increase your internet connection’s bandwidth or maximum download speed.
Summary
Adding and using Private DNS in Windows 11 is a relatively simple way to take more control over how your computer handles domain-name lookups. Start at Settings > Network & internet, open your active Wi-Fi or Ethernet connection, and edit DNS server assignment.
Set the option to Manual, enter the DNS addresses from a trusted provider, and configure DNS over HTTPS when the provider supports it. For additional privacy, pay attention to the Fallback to plaintext option so you understand whether Windows can send DNS queries without encryption.
Most importantly, remember that private DNS is a DNS privacy and security measure, not a complete privacy solution. Choose your DNS provider carefully, follow its recommended settings, and keep your original configuration in mind so you can easily switch back if something doesn’t work.