Public DNS Resolvers Compared: 1.1.1.1, 8.8.8.8 and Quad9
Technical
Cloudflare’s 1.1.1.1, Google Public DNS at 8.8.8.8 and Quad9 at 9.9.9.9 do the same job, and on the technical basics they are hard to tell apart. What separates them is written in their policies: what each keeps about you, what each declines to answer, and what each passes on to the servers it asks for you.
What switching resolver actually moves is set out in changing your DNS resolver, so this sticks to the policies. Speed is left out on purpose. Google’s own troubleshooting page says the network distance to its resolver “directly contributes to the resolution speed”, so somebody else’s measurement tells you little about yours.
One caveat governs everything below. Every statement about the operators’ practices comes from their own documentation as published on 21 September 2026. We have not verified any of it, and what each keeps and shares cannot be checked from your side of the connection at all.
What the three have in common
All three validate DNSSEC. Cloudflare calls 1.1.1.1 “a DNSSEC-validating resolver”, Google says its service has fully supported DNSSEC since January 2013, and Quad9 lists validation as part of its recommended 9.9.9.9 service.
All three accept encrypted connections, over both DNS over TLS and DNS over HTTPS. What separates those two protocols is covered in DNS over HTTPS vs DNS over TLS.
All three rule out advertising use. Cloudflare and Google both commit not to use personal data from their resolvers to target ads, and Quad9 says it “does not and never will share any of its data with marketers”.
Who you would be trusting
1.1.1.1 is Cloudflare’s service on an address Cloudflare does not hold. Its policy page says Cloudflare operates the resolver in partnership with APNIC, the Asia-Pacific regional internet registry, which “provided the 1.1.1.1 IP address for use as a public DNS resolver”. Put 1.1.1.1 into our IP WHOIS lookup and the organisation on the record is APNIC Research and Development, not Cloudflare.
8.8.8.8 is registered to the company that runs it. The same lookup returns Google LLC, and the service’s privacy page says it “adheres to the Google Privacy Policy”.
9.9.9.9 is run by a Swiss foundation. Quad9’s privacy policy names “the Swiss foundation Quad9” in Zürich as the responsible party and describes it as “a public-benefit not-for-profit foundation”. The registry record names Quad9 too.
How long your address stays with your questions
Quad9 says it holds your address for milliseconds. Its policy says the address a query comes from is held “only in volatile memory”, for “microseconds to milliseconds”, and that Quad9 “does not collect or record user IP addresses”. What it keeps is mainly counters, including how often each name is asked, which can be broken down by network prefix no finer than a /24 for IPv4 or a /56 for IPv6.
Cloudflare says your full address is never written to lasting storage, apart from a sample. Its policy rules out keeping query source addresses in non-volatile storage, except for “randomly sampled network packets captured from at most 0.05% of all traffic sent to Cloudflare’s network infrastructure”, used for troubleshooting and denial-of-service mitigation. Addresses are truncated, losing the last octet of IPv4 or the last 80 bits of IPv6, and the truncated form is deleted within 25 hours. So are the resolver logs, which record the querying network’s AS number and country.
Google’s standard is 24 to 48 hours. Its “temporary logs” are “the only logs that store both your IP address and your DNS query”, and they are “subject to our deletion processes within 24-48 hours”, though information may be kept longer “solely for the limited purpose” of resolving security and abuse issues. A sample then becomes what Google calls permanent logs, with the address “removed and replaced by a city or region-level location”, keeping the requested domain and your network’s AS number among other fields. The page gives no deletion period for those.
All three also keep a coarser record for much longer. Cloudflare says aggregated data may be stored indefinitely, Google calls its sampled logs permanent, and Quad9 says its counters “may be kept in full or partial form in permanent archives”.
Who else gets a look
Cloudflare shares with APNIC. Its logs go to no third party “except for APNIC pursuant to a Research Cooperative Agreement”, and APNIC can see “query names, query types, resolver location, and other metadata” but no client addresses.
Quad9 shares with its threat-intelligence suppliers. Analysts whose feeds drive its blocking receive counts and timestamps of queries for the malicious domains they reported. Its FAQ says this telemetry “never includes the source IP information of the user”, and that Quad9 logs “the geo-location of the system (city, state, country)”, which forms part of what those partners receive.
Google names no research partner. Its privacy page says Google does not associate personal information in these logs with your use of other Google services “except for addressing security and abuse”.
What each declines to answer
Quad9 blocks by default. Its FAQ says it aggregates threat intelligence about malicious domains “from a variety of public and private sources” and blocks access to them “when your system attempts to connect to them”. Its 9.9.9.10 service resolves without that blocking.
Cloudflare keeps filtering on separate addresses. Its policy says it “does not block or filter any content through the 1.1.1.1 Public DNS Resolver”, and that it would pursue its legal remedies before complying with a government request to block through it. Filtering comes from 1.1.1.1 for Families instead, where 1.1.1.2 blocks malware and 1.1.1.3 blocks malware and adult content.
Google says it does not filter, with two exceptions. Its FAQ says the service “does not perform blocking or filtering of any kind”, except for certain domains in rare cases, where Google believes a block protects its users from security threats or where it is “legally required to block a specific domain or domains”.
Quad9 and Cloudflare signal a block differently. Quad9’s FAQ says a blocked domain gets an NXDOMAIN response, “which communicates that the domain does not exist”. 1.1.1.1 for Families answers a domain it classifies as malicious with the address 0.0.0.0.
Mixing providers weakens the filter. Google’s FAQ warns that where configured resolvers differ, “you get the weakest level of security or filtering of all the resolvers”, and Quad9 advises against mixing its filtered and unfiltered addresses because your devices “will not be protected 100% of the time”. Pairing 9.9.9.9 with 8.8.8.8 as a secondary gives you a filter that covers some lookups and not others.
What each passes on
EDNS Client Subnet carries a fragment of your address beyond the resolver, so that a content network can pick a server near you.
Cloudflare does not send it. Its FAQ says 1.1.1.1 “does not send the EDNS Client Subnet (ECS) header”, with one exception, a debugging domain belonging to Akamai.
Google does, where the server at the other end supports it. Its guidance for server operators describes ECS as a mechanism “for recursive resolvers like Google Public DNS to send partial client IP address information to authoritative DNS name servers”, and says Google detects which servers support it.
Quad9 does not by default. Its FAQ says client subnet data “falls into a grey area of personally identifiable information” and is not transmitted on the default service. Its 9.9.9.11 service sends it.
The fragment comes from the public address your queries arrive from, which in an ordinary setup is the one your IP address page shows. What you gain and give up by sending it is set out in changing your DNS resolver.
Checking which one is answering you
Two of the three operators publish a page that checks whether you are actually using them. Cloudflare’s FAQ points to 1.1.1.1/help, which reports whether your system is connected to 1.1.1.1, and Quad9’s to on.quad9.net, which it says gives a simple yes or no. Google’s troubleshooting documentation uses command-line tests instead.
Our tools answer a different question, whose address it is, which helps when a router or an app has filled in a resolver you did not choose. The WHOIS lookup names the organisation an allocation was made to, and our reverse DNS lookup returns the hostname an address points back to: one.one.one.one for 1.1.1.1, dns.google for 8.8.8.8 and dns9.quad9.net for 9.9.9.9. Neither of them can see which resolver your device is actually using.
Choosing between them
Each of the three has made a different set of promises, so the choice is about which set you want. If retention matters most, compare the three accounts above, each of them the operator describing itself. If you want malicious domains blocked without installing anything, Quad9’s default and Cloudflare’s 1.1.1.2 both do it, and signal a block differently. If you want content networks to pick servers near you, at the cost of part of your address travelling further, Google sends that fragment where the other end supports it and Quad9 offers it on 9.9.9.11.
Whichever you choose, use that operator’s own secondary address rather than another provider’s, so that a second resolver with a different policy is not quietly answering some of your questions.