Logo: Quad9

Quad9

Swiss nonprofit public recursive DNS at 9.9.9.9 that blocks malware and phishing lookups without storing client IP addresses.

Quad9 is a free public recursive DNS resolver operated by the Swiss foundation Quad9 (c/o SWITCH, Werdstrasse 2, 8004 Zurich). You point devices or a network at published anycast addresses such as 9.9.9.9. The resolver answers name lookups and, on the recommended profile, refuses names that threat-intelligence partners flag as malware, phishing, spyware, or botnet infrastructure.

The foundation exists so that recursive DNS does not have to be a data-collection product. The official privacy policy treats client (reply-to) IP addresses as personal data, keeps them only in volatile memory for the milliseconds needed to answer, and states that they are not written to permanent storage or sent to any destination other than the user. There is no signup, account, or contract.

The concrete differentiator for European buyers is legal posture plus blocking policy. Headquarters moved from California to Zurich in February 2021. Quad9 publishes Swiss government findings that the resolver is not a telecommunications service under Swiss surveillance and know-your-customer rules, and it will not implement content filtering or government censorship lists. Encrypted transports (DNS-over-TLS, DNS-over-HTTPS, and DNSCrypt) are available. The platform is anycast and global, not an EU-only host.

Swiss foundationMalware/phishing blockingDoT / DoH / DNSCryptNo client-IP logs (claimed)Free, no signup

Shortlist Quad9 when you want a free, no-account public resolver with malware blocking and a Swiss-foundation privacy policy. Skip it when you need EU-only query processing, a signed DPA, category filtering, or an admin console. Consider Cloudflare 1.1.1.1 for a US consumer anycast resolver, or a self-hosted recursive stack when residency must be contractual.

Key capabilities

The recommended anycast profile (9.9.9.9 / 149.112.112.112 and IPv6 2620:fe::fe / 2620:fe::9) returns NXDOMAIN for names Quad9's blended threat feeds mark as malware, phishing, spyware, or botnet infrastructure. The homepage cites 25+ threat-intelligence providers. Quad9 does not offer parental or category filtering. False positives can be reported; blocks are searchable on the site with the contributing analyst named.

The data policy treats every reply-to address as personal data. It says the address is held only in RAM for microseconds to milliseconds, is not copied to permanent storage, and is not sent anywhere except back to the user. Aggregate counters (PoP, /24 or /56 prefix, ASN, coarse geography with a 10,000-person floor) may be archived. Attack traffic is covered by a separate anomalous-conditions policy.

All three published profiles accept DNS-over-TLS (tls://dns.quad9.net, port 853) and DNS-over-HTTPS (https://dns.quad9.net/dns-query, plus dns10/dns11 hostnames). DNSCrypt stamps are published. Cleartext UDP/TCP on port 53 is also available, with port 9953 as a fallback when an ISP intercepts port 53. Encryption is optional and depends on the client.

Secured (9.9.9.9): malware blocking plus DNSSEC. Secured with ECS (9.9.9.11): same protections but sends EDNS Client Subnet to authoritative servers, which Quad9 describes as a privacy tradeoff for CDN steering. Unsecured (9.9.9.10): DNSSEC without malware blocking, labeled for experts. Mixing secured and unsecured addresses in one stub is discouraged.

The addresses page states DNSSEC validation is enabled on all resolver addresses. For signed zones, Quad9 will not return an answer if cryptographic validation fails. This protects against spoofed responses. It does not replace endpoint security and can surface as lookup failures when a domain's DNSSEC is broken.

In één oogopslag

HQ / entity
Zurich, Switzerland. Swiss foundation Quad9, c/o SWITCH, Werdstrasse 2, 8004 Zurich
Service online
FAQ: August 2016. Public announcement framed as 2017. HQ moved from California to Zurich February 2021
Recommended addresses
9.9.9.9, 149.112.112.112, 2620:fe::fe, 2620:fe::9; DoH/DoT dns.quad9.net
Other profiles
9.9.9.11 (blocking + ECS), 9.9.9.10 (no blocking)
Commercial model
Free public service. Grants, donations, and in-kind transit/space. No signup
Footprint (vendor)
Homepage: 230+ clusters in 110+ countries, 25+ threat feeds, 670M+ average daily blocks
Independent audit
No public no-logs audit, ISO 27001, or SOC 2 found

Best fit when

  • Replacing ISP DNS on routers, endpoints, or Android Private DNS without creating accounts
  • Wanting default malware and phishing blocking plus DNSSEC, with an unsecured 9.9.9.10 opt-out
  • Treating recursive DNS as a jurisdiction choice and preferring a Swiss foundation over a US ad or CDN company
  • Needing encrypted DNS (DoT, DoH, or DNSCrypt) to the same anycast platform
  • Covering IoT and unmanaged devices by setting the resolver on the local gateway

Poor fit when

  • Requirement for a contractual DPA, SSO, or organization-wide query reporting
  • Policy that every DNS query must be processed in a named EU region
  • Need for parental controls, category filtering, or custom block/allow lists as a product
  • Security policy that requires an independent no-logs audit, ISO 27001, or SOC 2 from the resolver operator

Consider instead when

  • When: You need a contractual DPA and query processing pinned to named EU sites

    Consider: Self-hosted Unbound, Knot Resolver, or a contracted EU recursive DNS operator (including DNS4EU if it meets the brief)

    Quad9 is a global anycast public service with no signup and no published region pin.

  • When: You want a US-operated consumer anycast resolver and companion apps

    Consider: Cloudflare 1.1.1.1 (and WARP) or Google Public DNS

    Different legal entity, different default blocking, and a US parent path.

  • When: The actual requirement is a full-tunnel VPN rather than recursive DNS

    Consider: Mullvad or Proton VPN

    Those products are in the catalog as VPNs. They are not public recursive DNS peers.

  • When: You want a Swiss public resolver with a narrower, local-community mission and no global threat-feed blend

    Consider: Digitale Gesellschaft DNS (Switzerland)

    Named on Quad9's own homepage testimonials as a Swiss resolver operator.

Jurisdictie & eigendom

Juridische entiteit
Swiss foundation Quad9, c/o SWITCH, Werdstrasse 2, 8004 Zurich
VS-moeder / zeggenschap
Geen bekende VS-moeder
CLOUD Act-blootstelling (indicatief)
Medium
Hosting / residentie
Quad9-operated global anycast (homepage: 230+ clusters in 110+ countries). In-kind space/power/transit named in 2025: PCH, EdgeUno, i3D, Path Network, Equinix. Client IPs claimed to stay in the receiving PoP except under the anomalous-conditions policy. Website/support subprocessors: Zendesk (US) and Mailchimp (US). No public backup/DR host list.

No known US parent. IBM, Packet Clearing House, and the Global Cyber Alliance are named founding sponsors that remain active in operations or advisement. Query processing is global, not EU-only. Indicative only, not legal advice.

  • Independent security / no-logs auditNot found
  • ISO 27001Not found
  • SOC 2 / SOC 3Not found
  • GDPR / EU data protectionVendor claimed
  • +4

Considerations & known limitations

  • MediumQueries are not pinned to the EU

    Anycast sends each client to a nearby cluster in a 110+ country network. A European user will often land in Europe, but Quad9 does not publish a region lock. Treat this as a public global resolver, not EU-hosted SaaS.

  • MediumNo public independent no-logs audit

    The no-IP-storage design is detailed and first-party. Without an external audit, a security policy that requires attested no-logs cannot be closed from public materials.

  • MediumThreat feeds can block legitimate names

    Feeds are large and not individually human-reviewed. Remediation is best-effort and may require an allow-list. Use 9.9.9.10 if blocking risk is unacceptable.

  • LowWebsite and support use US SaaS

    Zendesk and Mailchimp (US) process support and newsletter data, not resolver queries. Support may be answered from the United States, Canada, Nepal, or South Africa.

  • LowCourt-ordered blocking remains a live risk

    Policy rejects censorship lists, but Quad9 has litigated copyright-related blocking in Germany. Global resolvers can still be dragged into national courts.

Open questions for due diligence

  • Will Quad9 sign a B2B DPA or provide a named subprocessor list for the resolver platform (beyond in-kind PoP partners)?
  • Is there an independent no-logs or security audit available under NDA?
  • Can an organization pin or prefer EU/Swiss points of presence?
  • What control, if any, do founding sponsors (including IBM) retain over operations beyond the published 'advisement' language?

Veelgestelde Vragen

The service privacy policy says no. Reply-to IPs are treated as personal data, held only in volatile memory to send the answer, then dropped. Quad9 does not create accounts. It may keep integer counters and first/last-seen labels without a user identifier. Threat-intelligence partners receive stripped telemetry only for domains they themselves listed as malicious (timestamp, counts, optional coarse dimensions, no client IP). The anomalous-conditions policy is the documented exception when Quad9 believes traffic is attacking the platform.

Yes. The 9.9.9.10 / 149.112.112.10 family (and matching IPv6, DoT, and DoH hostnames on dns10.quad9.net) is the unsecured profile: DNSSEC validation, no security block list. Quad9 labels it for experts and warns against mixing it with 9.9.9.9 in the same stub configuration.

No public B2B data processing agreement or region-pin control was found. There is no signup or contract path. Queries go to the nearest anycast cluster in a global network the homepage describes as 230+ clusters in over 110 countries. For EU and EEA users, Quad9 says it is subject to the GDPR and names a European data protection representative in Hamburg. If you need a contractual DPA and a named EU-only processing region, plan on a self-hosted resolver or a contracted EU DNS operator instead.

Blocked names typically return NXDOMAIN, with Extended DNS Error codes 15/16/17 where appropriate. Quad9 publishes a domain-status lookup that attributes each block to the contributing threat analyst. False positives can be filed via the website form or support@quad9.net. The policy is best-effort manual review; if the feed owner does not remediate, Quad9 says it can add an allow-list override.

The data policy says Quad9 does not accept government censorship lists and will not implement mandatory user attribution. The FAQ says there are no plans for content filtering and that misspelled names are not redirected. Blocking is limited to domains Quad9 treats as malware, phishing, exploit, or fraud. Quad9 has been a party to copyright-related court actions in Germany (Sony). Treat court-ordered blocks as a live legal risk, not as a parental-control feature.