Every website you visit starts with a DNS lookup. Most DNS systems do nothing to protect you in that moment. Quad9 does — blocking millions of malicious sites every day, before your device ever connects to them. Before you reach any website, your device asks for directions. Type an address, click a link, open an app — your device sends a request to a DNS resolver (Domain Name System) to find that site’s actual location. Only then can it connect. This happens every time, on every device, invisibly. And for most people, it runs through their internet provider’s default system — one with little to no security checks and often a financial incentive to track where you go. That gap between clicking a link and connecting to a website is where a significant portion of cyberattacks begin. Malware, ransomware, and phishing sites all depend on your device completing that lookup unchecked. When your device sends a DNS lookup through Quad9, every request is checked in real time against threat data from 30+ of the world’s leading cybersecurity organizations. If the site is known to host malware, run a phishing operation, or distribute ransomware — Quad9 blocks the lookup. Your device never receives the address. The connection never happens. If the site is not known to be malicious, you connect normally. The whole process takes milliseconds. The result: An average of 670 million threats blocked every single day across Quad9’s global network. The result: An average of 670 million threats blocked every single day across Quad9’s global network. Every DNS query is a record of where you’ve been online — what you read, what you search, what you buy. Commercial DNS providers have a financial reason to collect and monetize that data. This happens every time, on every device, invisibly. Quad9 doesn’t. Your IP address is never logged in any Quad9 system. No personal data collected. Nothing to sell. This isn’t a promise that can be reversed by a leadership change or acquisition. Quad9 is operated by a Swiss nonprofit foundation, subject to Swiss data protection law — among the strongest in the world and comparable to GDPR. The organization was legally constituted to make privacy(jlt – link to privacy page) non-negotiable. Every DNS query is a record of where you’ve been online — what you read, what you search, what you buy. Commercial DNS providers have a financial reason to collect and monetize that data. Quad9 doesn’t. Your IP address is never logged in any Quad9 system. No personal data collected. Nothing to sell. This isn’t a promise that can be reversed by a leadership change or acquisition. Quad9 is operated by a Swiss nonprofit foundation, subject to Swiss data protection law — among the strongest in the world and comparable to GDPR. The organization was legally constituted to make privacy(jlt – link to privacy page) non-negotiable. No account. No software. No contract. Point your DNS settings to Quad9 for free, and protection is active immediately. 9.9.9.9 (IPv4) · 2620:fe::fe (IPv6) Set it on your router once, and every device on your network is protected automatically — including smart home devices that can’t run security software on their own. Other DNS services are backed by companies whose business models depend on your data. Their privacy commitments are policies that can change. Quad9’s is structural: a nonprofit charter, Swiss law, and no commercial motive. Your IP address is never logged in any Quad9 system. No query history, no personal data, nothing to sell. Quad9 is operated by a Swiss nonprofit foundation and subject to Swiss data protection law — a legal guarantee, not a policy that can change with leadership or ownership. Quad9 publishes a Transparency Report detailing how the service operates, how threat blocking decisions are made, and how requests from governments and law enforcement are handled. Open infrastructure, openly accounted for. Quad9 blocks only domains that present a genuine security threat — malware, phishing, ransomware, spyware, and exploits. It does not filter content, block ads, or interfere with legitimate sites. Threat data comes from a network of commercial and public intelligence partners, updated multiple times daily and near-real-time as new risks emerge. A study by the Global Cyber Alliance found that approximately 33% of cybersecurity breaches could be stopped by a DNS-based system like Quad9. Answers to common questions about how Quad9 works, how to set it up, what gets blocked and why, how privacy is protected, and what Quad9 logs — and doesn’t log. Covers DNSSEC, encrypted DNS protocols, uptime, and how to verify you’re using Quad9. If something isn’t working, this is the first place to look. Your digital life has a security gap.
Quad9 closes it.
The Gap in Your Digital Security
Quad9 adds the check.
How It Works
Here’s what that looks like:
What Quad9 Blocks
Most cyberattacks don’t require a targeted effort — they just require an unguarded connection.
Privacy That Isn’t Just a Policy
Built by the Security Community
Setup
In This Section
Privacy
Transparency
Threat Blocking
FAQs