• Skip to primary navigation
  • Skip to main content
  • Skip to footer

Cisco Umbrella

Enterprise network security

  • Contact Sales
  • Login
    • Umbrella Login
    • Cloudlock Login
  • Search
Search
  • Why Us
    • Why Cisco Umbrella
      • Why Try Umbrella
      • Why DNS Security
      • Why Umbrella SASE
      • Our Customers
      • Customer Stories
      • Why Cisco Security
    • Fast Reliable Cloud
      • Global Cloud Architecture
      • Cloud Network Status
      • Global Cloud Network Activity
    • Unmatched Intelligence
      • A New Approach to Cybersecurity
      • Interactive Intelligence
      • Cyber Attack Prevention
      • Umbrella and Cisco Talos Threat Intelligence
    • Extensive Integrations
      • IT Security Integrations
      • Hardware Integrations
      • Meraki Integration
      • Cisco Security for Chromebook
  • Products
    • Cisco Umbrella Products
      • Cisco Umbrella Cloud Security Service
      • Recursive DNS Services
      • Cisco Umbrella SIG
      • Umbrella Investigate
      • What’s New
    • Product Packages
      • Cisco Umbrella and Cisco Secure Access Packages
      • – DNS Security Essentials Package
      • – DNS Security Advantage Package
      • – SIG Essentials Package
      • – SIG Advantage Package
      • Umbrella Support Packages
      • Cisco Umbrella for Government Packages
    • Functionality
      • DNS-Layer Security
      • Secure Web Gateway
      • Cloud Access Security Broker (CASB)
      • Cloud Data Loss Prevention (DLP)
      • Cloud-Delivered Firewall
      • Cloud Malware Protection
      • Remote Browser Isolation (RBI)
    • Man on a laptop with headphones on. He is attending a Cisco Umbrella Live Demo
  • Solutions
    • SASE & SSE Solutions
      • Your SSE journey with Cisco
      • Cisco Umbrella SASE
      • Secure Access Service Edge (SASE)
      • What is SASE
    • Functionality Solutions
      • Web Content Filtering
      • Secure Direct Internet Access
      • Shadow IT Discovery & App Blocking
      • Fast Incident Response
      • Unified Threat Management
      • Protect Mobile Users
      • Securing Remote and Roaming Users
      • Umbrella and Duo Layered Protection
    • Network Solutions
      • Guest Wi-Fi Security
      • SD-WAN Security
      • Off-Network Endpoint Security
    • Industry Solutions
      • Government and Public Sector Cybersecurity
      • Financial Services Security
        • – FTC Safeguards Rule Compliance 2023
      • Cybersecurity for Manufacturing
      • Higher Education Security
      • K-12 Schools Security
      • Healthcare, Retail and Hospitality Security
      • Enterprise Cloud Security
      • Small Business Cybersecurity
  • Resources
    • Content Library
      • Top Resources
      • Research Reports
      • Case Studies
      • Videos
      • Datasheets
      • eBooks
      • Solution Briefs
      • Cybersecurity Webinars
    • International Documents
      • Deutsch/German
      • Español/Spanish
      • Français/French
      • Italiano/Italian
      • 日本語/Japanese
    • Security Definitions
      • What is DNS Security
      • What is a Secure Web Gateway
      • What is a Cloud Access Security Broker (CASB)
      • What is Security Service Edge (SSE)
      • What is Secure Access Service Edge (SASE)
      • Cyber Threat Categories and Definitions
    • For Customers
      • Support
      • Customer Success Webinars
      • Free Trial Quick Start Guide
      • Free Trial Help and Tips
  • Trends & Threats
    • Market Trends
      • Generative AI Cybersecurity Risks and Rewards
      • Hybrid Workforce
      • Rise of Remote Workers
      • Secure Internet Gateway (SIG)
    • Security Threats
      • How to Stop Phishing Attacks
      • Malware Detection and Protection
      • Ransomware is on the Rise
      • Cryptomining Malware Protection
      • Cybersecurity Threat Landscape
      • Global Cyber Threat Intelligence
    •  
    • Woman connecting confidently to any device anywhere
  • Partners
    • Channel Partners
      • Partner Program
      • Become a Partner
    • Service Providers
      • Secure Connectivity
      • Managed Security for MSSPs
      • Managed IT for MSPs
    •  
    • Person looking down at laptop. They are connecting and working securely
  • Blog
    • News & Product Posts
      • Latest Posts
      • Products & Services
      • Customer Focus
      • Feature Spotlight
    • Cybersecurity Posts
      • Security
      • Threats
      • Cybersecurity Threat Spotlight
      • Research
    •  
    • Register for a webinar - with illustration of connecting securely to the cloud
  • Contact Us
  • Umbrella Login
  • Cloudlock Login
  • Free Trial
Clearing search keywords

DNS-layer security starts with recursive DNS services

Curious about those numbers in our website footer? Find out how fast you can secure your network from threats.

Start a free trial
Recursive DNS Icon

Recursive DNS Services

Umbrella DNS is the simplest way to protect your users everywhere in minutes. Sign up for our basic DNS monitoring services for free — no strings attached.

Protection icon

Additional security

Interested in extensive security protection? Sign up for a variety of Umbrella packages and get features including web filtering, threat intelligence, and added security.

Read the ebook

It’s all about DNS

To start, configure your recursive DNS to use Umbrella’s DNS servers. This directs traffic from your network to the Cisco Umbrella global network. When a request is made, Umbrella applies the selected security settings associated with the policies in your account.

Cisco Umbrella supports both IPv4 and IPv6 addresses.

Our IPv4 addresses are:
208.67.222.222
208.67.220.220

Our IPv6 addresses are:
2620:119:35::35
2620:119:53::53

How to point your recursive DNS to Cisco Umbrella

Point the DNS settings in your operating system or hardware firewall/router to Umbrella’s nameserver IP addresses, and turn off the automatic DNS servers provided by your ISP.

Some systems allow you to specify multiple DNS servers. We recommend you only use the Cisco Umbrella servers and do not include any other DNS servers in your list.

Note: We recommend only users with administrative access to the router, DNS server, or their own computer use these instructions, since you need admin access to complete the steps.

Setting up your recursive DNS

Step 1 – Find out where your public DNS server addresses are configured

Determine which device or server on your network maintains the addresses of your public DNS servers — most often, this will be a router or a DNS server.
Typically, the device that provides an internal non-routable IP address (DHCP) or the device that serves as your default gateway is also where you configure public DNS servers.

Step 2 – Log into the server or router where DNS is configured

Log into the device using administrator credentials. Once you’ve logged in, find the DNS settings for this device. If you’re unsure of where these settings are, check the documentation for your specific device, or try one of the following guides:

  • Router Configuration
  • Computer Configuration
  • Server Configuration

Step 3 – Change your DNS server addresses

Before you change your DNS settings to use Cisco Umbrella, be sure to record the current DNS server addresses or settings (for example, by writing them down on a piece of paper). It’s important that you keep these numbers for backup purposes — just in case you need to revert to them later.

Note: Some ISPs will hard-code their DNS servers into the equipment they provide. If you are using such a device, you will not be able to configure it to use Umbrella. Instead, you can configure each of your computers by installing the Umbrella roaming client, or by configuring the DNS server addresses on each computer. Instructions to configure a typical Windows or Mac computer can be found here.

The process for changing your DNS settings varies according to the operating system and version (Windows, Mac, or Linux) or the device (DNS server, router, or mobile device). This procedure might not apply for your OS, router, or device. For authoritative information, refer to your equipment vendor documentation.

To change your settings on a typical router:

  1. In your browser, enter the IP address to access the router’s user interface and enter your password.
  2. Find the area of configuration in which DNS server settings are specified and replace those addresses with the Cisco Umbrella IP addresses
  3. Save your changes and exit your router’s configuration interface.
  4. Flush your DNS cache.

You can use either the IPV4 or IPv6 DNS addresses as your primary and secondary DNS servers. However, you must use both numbers in the set, instead of using the same IP address twice for primary and secondary.
If your router requires a third or fourth DNS server setting, please use 208.67.220.222 and 208.67.222.220 (for IPv4) or 2620:119:35::35 and 2620:119:53::53 (for IPv6) as the third and fourth entries, respectively

Note: Don’t forget to confirm that your DNS is set to be static.

Important: when you make changes to DNS, you may have cached results that affect service. Flush your DNS cache to be sure that you’re receiving only the latest DNS results. For information on how to flush your DNS cache, see our guide here.

Step 4 – Test your new DNS settings

Now that you’ve configured your DNS settings, browse to http://welcome.umbrella.com. If you’ve successfully pointed your DNS to the Cisco Umbrella servers, you will see an Umbrella welcome page.

Note: Savvy users may try to modify their DNS settings to circumvent Umbrella. You can prevent this behavior with firewall rules. Learn more in our guide here.

Get help when you need it

If you have trouble reaching the Cisco Umbrella welcome page or getting web pages to load after following these steps, try the following steps to troubleshoot.

  1. From your browser, type in a fixed IP address in the address bar. If this works but you can’t reach the Umbrella welcome page, there is a problem with your DNS configuration. Recheck the steps above to make sure you have configured everything correctly. If this fails, go to step 2.
  2. Roll back the DNS changes you made and run the tests again (remember those addresses you wrote down on the piece of paper?) If the tests still don’t work, there is a problem with your network settings or your ISP.
  3. Contact our Support team for assistance.
Submit a support ticket

Explore at your pace

Not ready to try Umbrella just yet? Learn how you can protect your users from threats in our self-guided demo environment.

Note: Chrome or Firefox browser is required and you will be asked to install a third-party plug-in, WalkMe.

Start exploring

Follow Us

Facebook X LinkedIn Youtube

Footer Sections

What we make

  • Cloud Security Service
  • DNS-Layer Network Security
  • Secure Web Gateway
  • Security Packages

Who we are

  • Global Cloud Architecture
  • Cloud Network Status
  • Cloud Network Activity
  • OpenDNS is now Umbrella
  • Cisco Umbrella Blog

Learn more

  • Webinars
  • Careers
  • Support
  • Cisco Umbrella Live Demo
  • Contact Sales
Umbrella by Cisco
208.67.222.222+208.67.220.220
2620:119:35::35+2620:119:53::53
Sign up for a Free Trial
  • Cisco Online Privacy Statement
  • Terms of Service
  • Sitemap

© 2025 Cisco Umbrella