Skip to main content

Changing DNS What It Fixes and What It Doesn’t

Media Changing DNS Servers What It Fixes and What It Doesn’t

Changing your DNS server is one of the most frequently recommended fixes for internet problems.

A website will not load, browsing feels slow, or a connection test reports a DNS error. Someone then suggests switching to a public DNS service and entering a pair of unfamiliar IP addresses into Windows or the router.

Sometimes it works immediately. Websites begin loading and the connection appears normal again.

In other cases, changing DNS achieves nothing because the real problem lies elsewhere.

DNS is important, but it is not a universal internet repair. Understanding what it does—and what it does not do—can save time and prevent random network changes from creating additional problems.

What Is DNS?

DNS stands for Domain Name System.

People usually access websites through names such as:

example.com

Computers communicate using numerical IP addresses.

DNS translates the website name into the address required to reach the server. It performs a function similar to a directory: you provide a name, and DNS tells the device where to connect.

A simplified process looks like this:

  1. You enter a website address
  2. The computer checks whether it already knows the answer
  3. It asks the configured DNS server
  4. The DNS server returns the website’s IP address
  5. The browser connects to that address
  6. The website begins loading

If DNS resolution fails, the internet connection may still be active, but websites accessed by name will not open.

What a DNS Problem Looks Like

Common signs of a DNS fault include:

  • Websites fail by name but work by IP address
  • Browsers report that a server’s IP address cannot be found
  • Windows displays a DNS-related error
  • nslookup requests time out
  • Some websites work while others do not
  • The connection works after flushing the DNS cache
  • Devices use an old internal DNS server
  • Internet access fails when a business VPN disconnects
  • The router supplies an invalid DNS address
  • A provider’s DNS service is temporarily unavailable

DNS errors can resemble a complete internet outage even though the network itself remains connected.

What Changing DNS Servers Can Fix

Changing DNS can help when the configured DNS service is unavailable, unreliable, slow, or returning incorrect results.

An Unresponsive DNS Server

Your device may have a valid IP address, gateway, and internet route, but the DNS server does not answer.

In that situation, changing to a working DNS service can restore access to websites.

Slow Name Resolution

A slow DNS server can introduce a delay before a website begins loading.

The page itself may download quickly once the connection is established, but there can be a noticeable pause after entering the address.

A faster and more responsive resolver may reduce that initial delay.

Incorrect DNS Information

A DNS server may temporarily hold an outdated or incorrect record.

Changing resolvers can sometimes return the correct address sooner, although caching may still occur on the computer, browser, router, or website’s DNS infrastructure.

ISP DNS Outages

Some internet providers automatically supply their own DNS servers.

If those servers fail while the broadband connection remains active, switching temporarily to another reputable resolver may restore browsing.

Problems Caused by a Router’s DNS Forwarder

Many home routers advertise themselves as the DNS server and then forward requests upstream.

If the router’s forwarding service becomes unstable, configuring a trusted resolver directly on the computer may bypass the problem.

Restarting or updating the router should still be considered, as the fault may affect every device.

Incorrect DNS Supplied by DHCP

DHCP normally gives devices their:

  • IP address
  • Subnet mask
  • Default gateway
  • DNS servers

A misconfigured DHCP service may distribute the wrong DNS address.

Correcting the DHCP configuration is the proper network-wide fix. Manually changing DNS on one computer may provide a temporary workaround.

DNS Filtering Problems

Some networks use DNS filtering to block malicious, inappropriate, or unauthorised destinations.

If that filtering platform is misconfigured or unavailable, legitimate sites may fail to resolve.

Changing DNS might bypass the filter technically, but doing so may violate company policy and weaken security. On a managed business device, report the problem rather than circumventing the control.

What Changing DNS Servers Will Not Fix

DNS is only one part of the connection.

Changing it will not repair faults involving Wi-Fi, routing, cabling, broadband service, or the destination website itself.

It Will Not Fix Weak Wi-Fi

If the wireless signal is poor, changing DNS will not strengthen it.

Weak Wi-Fi can cause:

  • Slow transfers
  • Packet loss
  • Frequent disconnections
  • High latency
  • Failed video calls
  • Devices repeatedly reconnecting

The connection may appear slow during DNS requests, but the real problem is radio coverage or interference.

Check access-point placement, signal strength, wireless channels, and network congestion.

It Will Not Fix a Missing IP Address

A device that has not received a valid network address cannot normally reach a DNS server.

An address beginning with:

169.254

usually indicates that Windows failed to receive valid settings through DHCP.

Changing DNS does not correct the failed DHCP process. The device still needs a usable IP address, subnet mask, and default gateway.

It Will Not Fix a Missing or Incorrect Gateway

The default gateway carries traffic beyond the local network.

If the gateway is missing, wrong, or unreachable, the computer may not be able to reach either the internet or an external DNS server.

Check the configuration with:

ipconfig

If the default gateway field is blank or incorrect, resolve that issue before changing DNS.

It Will Not Fix a Broadband Outage

When the router has no working internet connection, changing DNS on the computer will not restore it.

Possible upstream faults include:

  • Provider outage
  • Failed modem or fibre terminal
  • Router WAN problem
  • Authentication failure
  • Damaged external cabling
  • Incorrect router configuration
  • Service suspension
  • Failed firewall route

Test whether the router has a valid external connection before blaming DNS.

It Will Not Fix a Broken Ethernet Cable

A damaged cable can create:

  • Complete disconnection
  • Packet loss
  • Intermittent access
  • A link falling back to 100 Mbps
  • Network errors
  • Unstable communication

DNS settings cannot repair a physical connection.

Test another cable and port where appropriate.

It Will Not Fix an Offline Website

If one website is unavailable for everyone, changing DNS may not help.

The destination may be experiencing:

  • Server outage
  • Maintenance
  • Hosting failure
  • Network attack
  • Application error
  • Expired service
  • Regional disruption

Test several unrelated websites and services.

When everything else works, the problem probably belongs to the affected site rather than your DNS configuration.

It Will Not Fix a Firewall Block

A firewall may block:

  • The destination website
  • The browser
  • A particular application
  • DNS traffic
  • HTTPS connections
  • A network category
  • A device or user account

Changing DNS may appear to help when a block is based only on DNS resolution, but it will not bypass properly configured IP, application, or firewall controls.

Do not disable business firewalls to troubleshoot routine browsing problems.

It Will Not Fix an Incorrect Proxy

A proxy server can route browser or application traffic through another system.

If the proxy is unavailable or incorrectly configured, websites may not open even when DNS works normally.

Check:

Settings > Network & internet > Proxy

On a managed business computer, confirm the correct settings with the IT provider before changing them.

It Will Not Fix a VPN Routing Problem

VPN software can alter:

  • DNS servers
  • Default routes
  • Network priorities
  • Firewall policies
  • Proxy settings
  • Access to internal services

If a VPN fails or disconnects incorrectly, changing DNS may not restore connectivity.

Some VPNs deliberately force all DNS requests through the secure tunnel to prevent leaks. Manually overriding this can break access to company resources or reduce security.

It Will Not Make Your Broadband Connection Faster

Changing DNS does not increase the maximum speed of the internet connection.

It cannot turn:

  • A 100 Mbps service into a 500 Mbps service
  • A poor Wi-Fi link into a fast one
  • An overloaded router into a high-performance one
  • A slow download server into a fast server

A faster resolver may reduce the brief time required to find a website’s address. Once the connection begins, download and upload speeds are controlled by other factors.

Claims that changing DNS will dramatically increase overall broadband speed are usually misleading.

It Will Not Automatically Reduce Gaming Latency

DNS is generally used when the game or service is first located.

Once the connection to the game server is established, DNS is not responsible for the continuous route between your device and that server.

Gaming latency is more strongly affected by:

  • Distance to the server
  • ISP routing
  • Wi-Fi quality
  • Network congestion
  • Packet loss
  • Router performance
  • Other traffic on the connection
  • The game server itself

Changing DNS might improve login or server-discovery behaviour, but it is unlikely to reduce the in-game ping significantly.

It Will Not Remove Malware

Some unwanted software changes DNS settings to redirect users or interfere with security services.

Correcting DNS may stop one symptom, but it does not remove the malicious software.

If DNS settings repeatedly change without permission, investigate:

  • Malware
  • Unwanted applications
  • Browser hijackers
  • Rogue VPN software
  • Router compromise
  • Device-management policies

Run an approved security scan and check the router configuration.

It Will Not Fix Every “DNS Error”

Browsers and operating systems sometimes display DNS-related messages when the true cause is broader network failure.

A DNS request may fail simply because:

  • Wi-Fi disconnected
  • The gateway is unavailable
  • The router lost internet access
  • A firewall blocked traffic
  • The network adapter failed
  • The VPN intercepted the request

Treat the error as a clue, not a final diagnosis.

How to Confirm That DNS Is Really the Problem

Before changing anything, test the connection in stages.

Check the Network Configuration

Open Command Prompt and run:

ipconfig

Confirm that the active adapter has:

  • A valid IP address
  • A suitable subnet mask
  • A default gateway
  • One or more DNS servers

If the address begins with 169.254, resolve the DHCP issue first.

Test the Gateway

Ping the gateway shown by ipconfig.

For example:

ping 192.168.1.1

Use the actual address for your network.

If the gateway cannot be reached, DNS is unlikely to be the first problem to solve.

Test an External IP Address

Try:

ping 1.1.1.1

A successful reply suggests that the computer can reach the internet without using a website name.

Some networks block ping, so this test is useful but not definitive.

Test DNS Resolution

Run:

nslookup example.com

The response should show which DNS server was queried and the address returned for the domain.

If the request times out while external IP connectivity works, DNS is a strong suspect.

Try Another Domain

One failed domain may have its own DNS or hosting problem.

Test several unrelated, reputable websites before deciding that the DNS service has failed.

Flush the DNS Cache First

Windows stores previous DNS responses locally to speed up repeated access.

A stale or corrupted cache entry can cause a website to resolve incorrectly.

Open Command Prompt as administrator and run:

ipconfig /flushdns

Then close and reopen the browser.

This clears the computer’s local DNS resolver cache, but not caches held by:

  • The browser
  • Router
  • DNS provider
  • Website operator
  • Content delivery network

Some browsers also maintain their own DNS and connection caches.

Restart the Router

A home or small-office router may cache DNS answers or forward requests to another resolver.

Restarting it can clear temporary forwarding problems.

Do not restart business routers or firewalls without approval, as this may interrupt:

  • Internet access
  • Cloud telephones
  • VPNs
  • Payment systems
  • Servers
  • Remote workers

Repeated router DNS failures may indicate that firmware, configuration, or the hardware itself needs attention.

Renew the DHCP Lease

If the device received incorrect DNS settings through DHCP, request a fresh lease:

ipconfig /release

ipconfig /renew

Then run:

ipconfig /all

Check the DNS servers listed for the active adapter.

If the wrong addresses return, the DHCP server must be corrected.

Where Can DNS Be Changed?

DNS can be configured in several places.

On One Computer

Changing DNS on an individual device affects only that device.

This is useful for testing, but it can create inconsistent behaviour across an organisation.

On the Router

Changing DNS on a home router can distribute the new resolver to devices through DHCP.

Some routers continue advertising themselves as the DNS server and forward requests upstream.

On a DHCP Server

Business networks often distribute DNS through a dedicated DHCP service.

Correcting the DHCP options is usually preferable to editing every computer manually.

On the Firewall or Network Gateway

A firewall may provide DNS forwarding, filtering, internal name resolution, or security inspection.

Changing public DNS settings without understanding this design can break access to internal services.

Through a VPN

VPN clients often apply their own DNS configuration while connected.

Manual DNS changes may be ignored or overridden by the VPN policy.

Through Device Management

Intune, Group Policy, mobile-device management, or endpoint-security products may enforce DNS settings.

A setting that returns after restart may be centrally managed rather than faulty.

How to Change DNS in Windows 11

To configure DNS for a particular network adapter:

  1. Open Settings
  2. Select Network & internet
  3. Choose Wi-Fi or Ethernet
  4. Open the active connection’s properties
  5. Find DNS server assignment
  6. Select Edit
  7. Choose Manual
  8. Enable IPv4 or IPv6 as required
  9. Enter the preferred and alternate DNS addresses
  10. Save the settings
  11. Disconnect and reconnect, or restart the adapter
  12. Test resolution with nslookup

Record the original setting before making changes.

For most users, the original configuration will be Automatic (DHCP).

Do Not Copy Random DNS Addresses

Use only reputable DNS services or addresses approved by your organisation.

An unknown DNS operator may be able to observe the domain names your device requests and could potentially return misleading responses.

Consider:

  • Reliability
  • Privacy policy
  • Security features
  • Filtering behaviour
  • Logging practices
  • Support for encrypted DNS
  • Suitability for business use
  • Whether internal domains must resolve

Free does not automatically mean private, secure, or appropriate.

Preferred and Alternate DNS Do Not Always Work as Expected

Windows allows you to enter a preferred and alternate DNS server.

It is tempting to assume that the alternate is used only when the preferred server completely fails.

In practice, operating systems and applications may query servers according to their own timing, health checks, and connection logic.

Both configured servers should therefore be:

  • Trusted
  • Correctly configured
  • Able to resolve the domains you need
  • Consistent with your security policy

Do not combine an internal business DNS server with an unrelated public DNS server unless the network design specifically supports it.

Why Businesses Need Internal DNS

Business networks often use internal DNS to locate resources such as:

  • Domain controllers
  • File servers
  • Print servers
  • Internal websites
  • Management systems
  • Remote desktop gateways
  • Line-of-business applications
  • Microsoft Active Directory services

Changing a company computer to public DNS may allow ordinary websites to load while breaking access to internal systems.

Active Directory environments are particularly dependent on correctly configured internal DNS.

Employees should not replace business DNS settings with public resolvers without IT approval.

Split DNS and VPN Access

Some organisations use split DNS.

The same name may return different results depending on whether the user is:

  • Inside the office
  • Connected through VPN
  • Using the public internet

A public resolver may not know the internal answer.

If internal systems stop working after changing DNS, restore the approved settings and contact the network administrator.

DNS Filtering and Security

DNS filtering can block access to:

  • Malware
  • Phishing sites
  • Newly registered domains
  • Adult content
  • Gambling sites
  • Unapproved cloud services
  • Known command-and-control systems

Replacing a filtered business resolver with a public one may weaken protection and visibility.

A user may see the filtering as a DNS fault when the block is intentional.

Check the organisation’s policy and security alerts before changing it.

DNS over HTTPS and DNS over TLS

Traditional DNS requests are commonly sent without encryption.

Encrypted DNS technologies include:

  • DNS over HTTPS, or DoH
  • DNS over TLS, or DoT

These can protect DNS queries from some forms of local observation or tampering.

However, encrypted DNS does not automatically provide anonymity. The DNS provider may still process requests, and the destination service can still see connections.

In business environments, browser-level encrypted DNS may bypass approved filtering and monitoring. It should be configured in line with company security policy.

Will Changing DNS Improve Privacy?

It may change who handles and potentially logs your DNS requests.

Instead of the internet provider or local network resolver, the chosen DNS operator may receive them.

This is not the same as hiding all browsing activity.

DNS changes do not conceal:

  • The IP addresses contacted
  • Traffic from the destination service
  • Browser cookies
  • Account sign-ins
  • Data sent to websites
  • Activity from endpoint-security software
  • Information visible to a VPN provider

Review the resolver’s privacy policy rather than assuming that a public service is automatically more private.

Will Changing DNS Bypass Website Blocks?

Sometimes, but not reliably—and it may not be appropriate.

A block based solely on DNS may stop working when another resolver is used.

However, websites can also be blocked through:

  • Firewall rules
  • IP filtering
  • Proxy controls
  • Application controls
  • Account policies
  • Device-management restrictions
  • Secure web gateways

Bypassing workplace, school, or parental controls may breach policy.

If a legitimate site has been blocked incorrectly, request a review rather than attempting to work around the security system.

Can DNS Protect Against Malicious Websites?

Some resolvers block domains associated with malware, phishing, or unwanted content.

This can provide a useful extra layer of protection.

It is not a replacement for:

  • Endpoint protection
  • Browser security
  • Email filtering
  • Software updates
  • Multi-factor authentication
  • User training
  • Firewall controls
  • Secure backups

DNS filtering may block known malicious domains, but it cannot identify every unsafe page or prevent all attacks.

DNS and Content Delivery Networks

Large websites often use content delivery networks to direct users to nearby or suitable servers.

The DNS resolver’s location can influence which server is selected.

A resolver located far from the user could occasionally result in a less suitable destination, although modern delivery systems use several techniques to reduce this problem.

The nearest DNS server is not always the fastest or best choice. Real-world performance should be tested rather than assumed.

DNS and Email Problems

DNS is critical for email systems because it is used to locate mail servers and validate security information.

However, changing the DNS resolver on a laptop will not normally fix:

  • A full mailbox
  • Incorrect password
  • Account lockout
  • Email-server outage
  • Rejected messages
  • Spam filtering
  • Incorrect mail-client settings
  • Expired licence

It may help only when the device cannot resolve the email service’s domain or when the assigned DNS server returns incorrect information.

DNS and Microsoft 365

Microsoft 365 depends heavily on DNS, but there are two different contexts.

DNS on the User’s Device

This allows the computer to locate Microsoft’s services.

Public DNS Records for the Organisation’s Domain

These include records used for:

  • Email delivery
  • Domain verification
  • Autodiscover
  • SPF
  • DKIM
  • DMARC
  • Other services

Changing the DNS server on a computer does not modify the organisation’s public Microsoft 365 records.

If email delivery or domain verification is failing, the public DNS zone may need to be corrected by an administrator.

DNS and Website Hosting

Changing your computer’s resolver does not change where your website is hosted.

It also does not update the public DNS records visitors use to find your site.

Website owners must change records through the authoritative DNS provider for the domain.

These are different tasks:

  • Changing the resolver affects how your device looks up names
  • Changing authoritative DNS affects what answer the world receives for your domain

DNS Changes May Take Time

When a website owner changes a public DNS record, old answers can remain cached according to their time-to-live value.

Changing your device to another resolver may return a newer result, but it does not force every network worldwide to update immediately.

Propagation delays may involve:

  • Recursive resolver caches
  • Local operating-system caches
  • Browser caches
  • Router caches
  • Provider infrastructure
  • Application-level caches

Repeatedly changing DNS settings does not necessarily speed up a legitimate global record change.

Signs That DNS Is Not the Real Problem

DNS is less likely to be the primary fault when:

  • The device has a 169.254 address
  • The default gateway is missing
  • No external IP address can be reached
  • Wi-Fi repeatedly disconnects
  • Ethernet has no link
  • Every device loses internet simultaneously
  • The router reports no WAN connection
  • Only one application fails
  • The affected website is down for everyone
  • The computer uses an unavailable proxy
  • A VPN kill switch is active

Investigate the earlier failure in the network path first.

A Practical Troubleshooting Order

Use this order before permanently changing DNS:

  1. Check whether other devices can access the internet
  2. Confirm the device has a valid IP address
  3. Confirm that a default gateway is present
  4. Test the gateway
  5. Test an external IP address
  6. Test domain resolution with nslookup
  7. Flush the local DNS cache
  8. Restart or reconnect the network adapter
  9. Renew the DHCP lease
  10. Check proxy and VPN settings
  11. Test another approved DNS server temporarily
  12. Correct DHCP, router, firewall, or internal DNS settings if required
  13. Restore the original configuration if changing DNS does not help

This approach confirms whether DNS is genuinely responsible rather than using it as a guess.

When to Restore Automatic DNS

Return the setting to Automatic (DHCP) when:

  • The test made no difference
  • The device moves between networks
  • It is a managed business computer
  • Internal systems stop resolving
  • The VPN requires company DNS
  • The network provides filtered or secured DNS
  • You are uncertain which resolver is appropriate

Leaving an undocumented manual setting can cause future problems when the computer moves to another office, network, or VPN.

When to Contact an IT Professional

Professional assistance is recommended when:

  • Several users experience DNS failures
  • Internal company names do not resolve
  • DNS settings keep changing
  • The network uses Active Directory
  • A VPN applies incorrect DNS information
  • DHCP is distributing outdated servers
  • DNS filtering blocks legitimate services
  • Multiple DNS servers return inconsistent answers
  • Public website or email records may be wrong
  • The problem repeatedly returns
  • A router or firewall provides DNS forwarding

An IT technician can test recursive resolution, inspect DHCP options, review internal and public DNS records, check VPN policies, and identify where requests are failing.

Change DNS for the Right Reason

Changing DNS servers can fix problems caused by an unavailable, slow, incorrectly configured, or unreliable resolver.

It can also help diagnose whether name resolution is the reason websites are not loading.

However, it will not repair weak Wi-Fi, a failed internet service, a missing gateway, broken cabling, an offline website, or a routing problem.

Test the connection in the correct order:

IP address, gateway, internet reachability, then DNS resolution.

Hamilton Group can diagnose DNS, DHCP, gateway, Wi-Fi, firewall, and Microsoft 365 connectivity problems, ensuring that the underlying issue is corrected rather than temporarily hidden.

Call 0330 043 0069 or visit hgmssp.com to book a meeting with one of our networking experts.