DNS Configuration Guide

July 10, 2026 · View on GitHub

This guide covers DNS configuration on Ubuntu and macOS, explaining the differences between network management approaches and providing practical commands for each platform.

Ubuntu (NetworkManager)

Understanding NetworkManager's Approach

Ubuntu uses NetworkManager which operates on connection profiles rather than interfaces directly. This means:

  • DNS settings are tied to specific network connections (e.g., "Home WiFi", "Office WiFi")
  • Each Wi-Fi network can have different DNS settings
  • Settings persist automatically when reconnecting to the same network
  • wifiwand na ... is an exact replacement operation on Ubuntu
  • Setting IPv4-only DNS clears previously custom IPv6 DNS
  • Setting IPv6-only DNS clears previously custom IPv4 DNS

Key Commands

Check Current Configuration

# Show all devices and DNS settings
nmcli device show | grep -E "DEVICE|TYPE|CONNECTION|IP4.DNS"

# Show DNS for specific interface
nmcli device show wlp0s20f3 | grep DNS

# List active connections
nmcli connection show --active

Configure DNS Settings

# Set custom IPv4 DNS servers for a connection
sudo nmcli connection modify "Wi-Fi Connection Name" ipv4.dns "1.1.1.1 8.8.8.8"

# Ignore automatic IPv4 DNS from router/DHCP
sudo nmcli connection modify "Wi-Fi Connection Name" ipv4.ignore-auto-dns yes

# Apply changes by restarting the connection
sudo nmcli connection up "Wi-Fi Connection Name"

When you use wifiwand na ... on Ubuntu, the requested nameserver list becomes the full DNS configuration for that profile. Setting IPv4-only DNS clears any previously custom IPv6 DNS and resets ipv6.ignore-auto-dns to DHCP/router-provided DNS; setting IPv6-only DNS clears any previously custom IPv4 DNS and resets ipv4.ignore-auto-dns to DHCP/router-provided DNS. Use na clear to clear both families explicitly.

WifiWand Commands

wifiwand na is the cross-platform DNS command. Showing nameservers is read-only, but clear and server arguments mutate the active network DNS configuration.

# Show the active DNS servers
wifiwand na
wifiwand na get

# Clear custom DNS and return to automatic DNS where the platform supports it
wifiwand na clear

# Replace the active DNS configuration with these servers
wifiwand na 9.9.9.9 8.8.8.8

On Ubuntu, the set operation is an exact replacement for the active NetworkManager connection profile. On macOS, it changes the Wi-Fi network service DNS settings, which usually apply to every Wi-Fi network.

Example: Complete DNS Setup

# 1. Identify your connection
nmcli connection show --active

# 2. Configure DNS (replace "WFC_Globe" with your connection name)
sudo nmcli connection modify "WFC_Globe" ipv4.dns "1.1.1.1 8.8.8.8"
sudo nmcli connection modify "WFC_Globe" ipv4.ignore-auto-dns yes
sudo nmcli connection up "WFC_Globe"

# 3. Verify changes
nmcli device show wlp0s20f3 | grep DNS

Why Connection Names vs Interface Names?

NetworkManager uses connection profiles because:

  • One interface can connect to multiple networks (different Wi-Fi SSIDs)
  • Each network connection can have different configurations
  • Settings persist per connection, not per interface

Example:

  • Interface: wlp0s20f3 (the physical WiFi adapter)
  • Connections: Home_WiFi, Office_WiFi, Coffee_Shop (different network profiles)

macOS DNS Management

Understanding macOS Approach

macOS handles DNS at the network service level:

  • DNS settings apply to network services (Wi-Fi, Ethernet, etc.)
  • By default, all Wi-Fi networks share the same DNS settings
  • Uses "Locations" for different network configurations (advanced)

Key Commands

Check Current Configuration

# Show all DNS configuration
scutil --dns

# Show DNS servers for specific service
networksetup -getdnsservers Wi-Fi
networksetup -getdnsservers Ethernet

# List all network services
networksetup -listallnetworkservices

Configure DNS Settings

# Set DNS servers for Wi-Fi
sudo networksetup -setdnsservers Wi-Fi 1.1.1.1 8.8.8.8

# Set DNS servers for Ethernet
sudo networksetup -setdnsservers Ethernet 1.1.1.1 8.8.8.8

# Clear DNS servers (use automatic)
sudo networksetup -setdnsservers Wi-Fi "Empty"

Advanced: Using Locations

# Create a new location
networksetup -createlocation "Work" populate

# Switch to a location
networksetup -switchtolocation "Work"

# List all locations
networksetup -listlocations

Key Differences Between Ubuntu and macOS

AspectUbuntu (NetworkManager)macOS
ScopePer connection profilePer network service
GranularityEach Wi-Fi network can have different DNSAll Wi-Fi networks share same DNS by default
PersistencePermanent per connection - survives reboots & reconnectionsPermanent for service - survives reboots & network changes
ManagementConnection-basedService-based
FlexibilityHigh - each network independentLow - all networks use same DNS
Example"Home WiFi" uses 1.1.1.1, "Work WiFi" uses 8.8.8.8All Wi-Fi uses 1.1.1.1 unless using Locations

DNS Persistence Behavior

Both systems permanently modify DNS settings when you configure custom servers:

Ubuntu:

  • Custom DNS settings are saved to the specific connection profile
  • Settings persist across reboots and reconnections to that network
  • Each Wi-Fi network maintains independent DNS configuration
  • na applies DNS as an exact replacement for the active profile, not a partial merge
  • If you set only IPv4 servers, prior custom IPv6 DNS is cleared; if you set only IPv6 servers, prior custom IPv4 DNS is cleared
  • Other networks are unaffected

macOS:

  • Custom DNS settings apply to the entire Wi-Fi service
  • Settings persist across reboots and apply to ALL Wi-Fi networks
  • Cannot have different DNS per network (without using Locations)
  • All Wi-Fi connections use the same custom DNS

Practical Examples

Ubuntu Scenario:

# Connect to work network and set custom DNS
nmcli connection up "Work_WiFi"
sudo nmcli connection modify "Work_WiFi" ipv4.dns "8.8.8.8 1.1.1.1"
sudo nmcli connection modify "Work_WiFi" ipv4.ignore-auto-dns yes
sudo nmcli connection up "Work_WiFi"

# Switch to home network (keeps its own DNS settings)
nmcli connection up "Home_WiFi"  # Still uses router DNS (192.168.1.1)

# Switch back to work (automatically uses custom DNS)
nmcli connection up "Work_WiFi"  # Automatically uses 8.8.8.8, 1.1.1.1

macOS Scenario:

# Set custom DNS for all Wi-Fi networks
sudo networksetup -setdnsservers Wi-Fi 8.8.8.8 1.1.1.1

# All Wi-Fi networks now use custom DNS when you connect to them
wifiwand co "Work_WiFi" password    # Uses 8.8.8.8
wifiwand co "Home_WiFi" password    # Uses 8.8.8.8
wifiwand co "Coffee_Shop"           # Uses 8.8.8.8

Common DNS Servers

ProviderPrimarySecondaryPurpose
Cloudflare1.1.1.11.0.0.1Fast, privacy-focused
Google8.8.8.88.8.4.4Reliable, widely used
Quad99.9.9.9149.112.112.112Security-focused, blocks malicious domains
OpenDNS208.67.222.222208.67.220.220Content filtering options

Troubleshooting

Ubuntu

# Check if NetworkManager is running
systemctl status NetworkManager

# Restart NetworkManager
sudo systemctl restart NetworkManager

# Reset DNS cache
sudo resolvectl flush-caches

# Older Ubuntu releases may use the deprecated command name
sudo systemd-resolve --flush-caches

# Check DNS resolution
dig @1.1.1.1 example.com

Understanding systemd-resolved on Ubuntu

Ubuntu uses systemd-resolved which creates a local DNS stub resolver at 127.0.0.53. This is normal and expected:

# /etc/resolv.conf will show:
nameserver 127.0.0.53

# To see actual DNS servers being used:
resolvectl status

# Or check NetworkManager connection directly:
nmcli connection show "Your-WiFi-Name" | grep -i dns

Why this matters:

  • /etc/resolv.conf shows 127.0.0.53 (systemd-resolved stub)
  • The actual DNS servers are configured in NetworkManager
  • Applications use the stub, which forwards to the real DNS servers
  • This is why WiFiWand needed to read from NetworkManager, not /etc/resolv.conf

macOS

# Flush DNS cache
sudo dscacheutil -flushcache
sudo killall -HUP mDNSResponder

# Check DNS resolution
dig @1.1.1.1 example.com
nslookup example.com

Best Practices

  1. Use reliable DNS providers - Choose DNS servers with good uptime and privacy policies
  2. Test after changes - Verify DNS resolution works after configuration changes
  3. Document your settings - Keep track of which networks use which DNS servers
  4. Consider security - Use DNS providers that block malicious domains (like Quad9)
  5. Have fallbacks - Configure both primary and secondary DNS servers