Pular para o conteúdo principal

DNS speed test

Benchmark public DNS resolvers directly from your browser to compare latency and optimize connection speeds.

Benchmark public DNS resolvers

Times are measured from your browser to each resolver's DNS-over-HTTPS endpoint, so they reflect your real path to that resolver. A resolver may show as blocked if its endpoint does not allow cross-origin browser requests, not because it is slow.

Enterprise WiFi & Captive Portal DNS

Eliminate captive portal load stalls and DNS sign-in drops

Slow DNS resolutions and missing walled-garden allow-lists account for over 40% of captive portal redirect failures. Purple provides cloud-managed RADIUS, pre-validated DNS rules, and automated portal allow-lists for Meraki, Aruba, Ruckus, and UniFi networks.

Key takeaways for network engineers

  • Direct browser measurement: Tests execute over DNS-over-HTTPS (RFC 8484) to capture the actual round-trip delay from your current network connection.
  • Captive portal performance: DNS delays exceeding 100 ms double splash page load times, triggering mobile OS browser timeouts on guest WiFi networks.
  • Resolver selection: Cloudflare (1.1.1.1) and Google (8.8.8.8) consistently yield sub-20 ms median response times in major metropolitan areas.

Why DNS resolver speed matters for enterprise & guest WiFi

Every network request - from loading a web page to initiating a captive portal login - begins with a Domain Name System (DNS) query. Before a mobile device or laptop can negotiate a TCP connection or TLS handshake, it must resolve the target hostname into an IP address. When public DNS resolvers respond slowly, users experience noticeable latency on every new domain connection.

On high-density venue and guest WiFi networks, DNS performance is even more critical. Upon connecting to an open SSID, modern operating systems (iOS CNA, Android Captive Portal Handler, Windows NCSI) issue HTTP probe requests to detect internet connectivity. If the local DNS server or upstream resolver stalls during this lookup, the captive portal splash screen fails to open automatically, causing guest sign-in abandonments.

Public DNS resolver benchmark comparison

The table below summarizes the primary technical attributes and typical global latency profiles for major public DNS providers:

ResolverPrimary IPDoH EndpointFilter TypeTarget LatencyBest Use Case
Cloudflare1.1.1.1cloudflare-dns.comUnfiltered / Speed10 - 18 msHigh-throughput browsing & guest portals
Google Public DNS8.8.8.8dns.googleGlobal Anycast12 - 22 msHigh-reliability primary or secondary fallback
NextDNSCustomdns.nextdns.ioCustom Security & Privacy15 - 30 msPolicy-driven content filtering
AdGuard DNS94.140.14.14dns.adguard-dns.comAd & Tracker Blocking20 - 35 msNetwork-wide advertisement blocking

How browser DNS speed measurement works

Traditional command-line tools like dig or nslookup send raw UDP or TCP packets directly to port 53. Because web browsers run within a sandboxed environment without direct socket access, browser-based DNS speed testing utilizes DNS-over-HTTPS (RFC 8484).

The benchmark tool issues a warm-up HTTPS request to populate local DNS cache and establish the TLS session. It then performs four consecutive fetch cycles using performance.now() high-resolution timestamps to calculate the median response time. Resolvers that do not configure Cross-Origin Resource Sharing (CORS) headers for browser requests are identified as CORS-restricted.

Troubleshooting DNS & captive portal sign-in failures

When configuring enterprise wireless infrastructure (Cisco Meraki, HPE Aruba, Ruckus, or Ubiquiti UniFi), misconfigured DNS settings frequently lead to connection drops. Ensure your network setup addresses these key factors:

  • Pre-authentication DNS access: Guest devices must be granted unauthenticated DNS resolution to port 53 (or DoH endpoints) before completing captive portal registration.
  • Walled garden domain resolution: OAuth social sign-ins (Google, Apple, Facebook) require explicit FQDN allow-lists in the wireless controller. If the DNS server fails to resolve these domains, authentication halts.
  • Encrypted DNS interference: Apple Private Relay and Android Private DNS (DoT/DoH) can intercept DNS queries on guest SSIDs, bypassing local filter policies.

Frequently asked questions about DNS speed

How does this browser DNS speed test measure resolver latency?

The tool uses DNS-over-HTTPS (DoH) endpoints to execute real-time fetch requests from your browser to Cloudflare (1.1.1.1), Google (8.8.8.8), NextDNS, and AdGuard, calculating the median round-trip time in milliseconds.

Why does DNS resolver latency impact guest WiFi networks and captive portals?

Every new HTTPS connection starts with a DNS lookup. Slow DNS resolution adds delay to captive portal splash page redirects, leading to sign-in timeouts and degraded user experience on high-density guest networks.

Which public DNS resolver is fastest for WiFi networks?

Cloudflare (1.1.1.1) and Google (8.8.8.8) typically provide the lowest global latency (under 15-20 ms in urban locations). However, actual performance depends on your local ISP routing and proximity to the nearest resolver node.

How does Purple optimize DNS for captive portal deployments?

Purple provides pre-validated DNS allow-lists, walled garden rules, and cloud RADIUS integration for Cisco Meraki, HPE Aruba, Ruckus, and Ubiquiti UniFi networks to eliminate portal load delays and prevent sign-in drops.

DNS issues breaking guest sign-in?

Captive portal redirection failures frequently trace back to DNS stalls and missing walled-garden domain rules. Purple delivers cloud-managed RADIUS and pre-tested DNS configurations for Cisco Meraki, HPE Aruba, Ruckus, and Ubiquiti UniFi.

Book a 20-min demo
Free Desktop App

Netforge Network Multi-Tool

Run offline network health checks, path analysis, and latency diagnostic scans directly from your desktop.

Download Multi-Tool