AdGuard DNS IP Ranges
AdGuard DNS is the public filtering resolver run by AdGuard Software Limited, the Cyprus company behind the AdGuard ad blocker, and AS212772 exists to carry those resolvers rather than to host anything for customers. The RIPE aut-num was created on 18 August 2020 under ORG-ASL47-RIPE, about eight minutes after the matching IPv6 allocation 2a10:50c0::/32 was recorded under netname CY-ADGUARD-20200818. The IPv4 behind the widely published 94.140.14.14 sits in inetnum 94.140.14.0/23, netname CY-ADGUARD-20081128, country CY, and the route object binding that space to this ASN was created on 7 September 2020.
- Provider
- AdGuard DNS
- Primary ASN
- AS212772
- Category
- DNS
- Headquarters
- Limassol, Cyprus
- Announced IPv4 prefixes
- 9
- Registry
- RIPE
Known IP ranges
These prefixes are currently announced to the global routing table by AS212772 (ADGUARD AdGuard Software Limited). Prefix sets change over time - use WHOIS Lookup for the authoritative record on any specific address.
45.156.136.0/22
176.103.128.0/22
46.243.228.0/22
92.255.56.0/24
92.255.84.0/24
185.113.29.0/24
185.113.28.0/24
94.140.14.0/24
94.140.15.0/24
2a10:50c0::/48
2a10:50c0:c000::/48
2a10:50c0:7001::/48 (IPv6)
What does an AdGuard DNS IP mean in a privacy test?
An AdGuard address in a leak test is the resolver that answered, and this network is unusual in telling you which resolver it was. 94.140.14.14 and 94.140.15.15 answer reverse lookups with dns.adguard-dns.com, the default filtering tier, while 94.140.14.140 and 94.140.14.141 answer with unfiltered.adguard-dns.com and 94.140.14.15 with family.adguard-dns.com, so the PTR names the tier the device was actually pointed at rather than the one you meant to set. AdGuard says in its own engineering blog that it uses anycast routing so that the nearest server responds, which means the country a lookup reports for one of these addresses describes where the prefix is announced, not where you are. It also states that it does not pass your real subnet to authoritative nameservers: it determines the AS number of your address and sends a random /24 announced by that AS in the EDNS Client Subnet field instead, so a leak test can name AdGuard while the nameservers behind it never learn your network. A device still querying 176.103.130.130 is on an address AdGuard announced it was retiring, and that address still resolves to dns.adguard-dns.com, so a name lookup alone will not reveal the stale configuration.
What AdGuard publishes about its own addresses
The list that matters is AdGuard's own resolver page at adguard-dns.io/en/public-dns.html, and it is organised by filtering behaviour rather than by prefix. The default server is 94.140.14.14 and 94.140.15.15 with IPv6 2a10:50c0::ad1:ff and 2a10:50c0::ad2:ff; Family Protection is 94.140.14.15 and 94.140.15.16 with 2a10:50c0::bad1:ff and 2a10:50c0::bad2:ff; the non-filtering server is 94.140.14.140 and 94.140.14.141 with 2a10:50c0::1:ff and 2a10:50c0::2:ff. The same three tiers are reachable as dns.adguard-dns.com, family.adguard-dns.com and unfiltered.adguard-dns.com over DNS-over-HTTPS, DNS-over-TLS and DNS-over-QUIC, and because every one of those addresses carries a reverse record naming its tier, a log line can be matched back to a row on that page without consulting a third-party database.
What AdGuard does not publish is a geolocation feed or an egress allowlist, and none of the allocations checked here carries a geofeed attribute. For the boundaries of the space the RIPE records are the source, and they show holdings assembled from separate allocations rather than one range: 92.255.56.0/24 is netname CY-ADGUARD-20071224, 94.140.14.0/23 is CY-ADGUARD-20081128, 46.243.228.0/22 is CY-ADGUARD-20101228, 185.113.28.0/22 is CY-ADGUARD-20150812, 45.156.136.0/22 is CY-ADGUARD-20190920, and the IPv6 allocation 2a10:50c0::/32 is CY-ADGUARD-20200818. One block sits apart from that pattern: 176.103.128.0/19 is netname CY-ADGUARD with status ASSIGNED PI and RIPE-NCC-END-MNT beside the company maintainer, where the others are ALLOCATED PA under RIPE-NCC-HM-MNT. All of them are held by ORG-ASL47-RIPE and maintained by mnt-cy-adguard-1.
Resolver addresses against the rest of AS212772
There is no tenant space on this network in the sense a hosting provider has tenants. Every allocation checked for this page is held by ORG-ASL47-RIPE itself rather than sub-allocated to a third party, which is the opposite of the pattern on a leasing ASN, where the netname on a block frequently names somebody other than the operator. The registered routing policy points the same way: the aut-num lists exactly five neighbours, AS199274, AS20473, AS9009, AS60068 and AS58010, each in the paired form from ASnnn accept ANY and to ASnnn announce AS212772, with nothing announced onward to downstream customers. The object's only remark is a NOC address at adguard.com.
Within that space the published resolver addresses are the small set inside 94.140.14.0/24 and 94.140.15.0/24 that answer reverse lookups with an adguard-dns.com name. Anything on AS212772 that does not is something else AdGuard runs, and the older blocks are separate from the resolver space: 45.156.136.0/22, 46.243.228.0/22, 92.255.56.0/24, and the announced 176.103.128.0/22 that sits inside the PI inetnum 176.103.128.0/19 and still carries the legacy 176.103.130.130. Two consequences follow for reading a log. The same resolver address seen from two places was almost certainly two different machines, because AdGuard states it routes these addresses by anycast. And an inbound connection originating from this space is unusual by design, since these addresses exist to be queried rather than to open sessions of their own.
Related tools
Frequently asked questions
Why does a DNS leak test show AdGuard?
Because AdGuard answered the query. AS212772 carries AdGuard's public resolvers, so its addresses appear as the server that resolved your lookup, not as the address websites see you arriving from. If you configured AdGuard DNS deliberately, that is the expected result.
Which AdGuard DNS server am I using?
Reverse DNS tells you. 94.140.14.14 and 94.140.15.15 answer to dns.adguard-dns.com, the default filtering resolver; 94.140.14.140 and 94.140.14.141 answer to unfiltered.adguard-dns.com; the Family Protection pair 94.140.14.15 and 94.140.15.16 answers to family.adguard-dns.com. The encrypted endpoints reuse those same three names over HTTPS, TLS and QUIC.
Do the old AdGuard DNS addresses still work?
AdGuard published a notice that every address it used before 2020 would be unavailable after 28 April. The legacy address 176.103.130.130 still resolves to dns.adguard-dns.com, so a name lookup on its own will not tell you the configuration is stale. If a device is still pointed at a pre-2020 address, move it to the current list on the public resolver page.
Does AdGuard DNS pass my IP address on to nameservers?
AdGuard states that it does not send your real client subnet. Instead it determines the AS number your query arrived from and looks up a random /24 announced by that AS in a map it built in advance, then sends that subnet in the EDNS Client Subnet field, which keeps geographically steered answers roughly right while withholding your own subnet.
Is an AdGuard DNS address ever my VPN exit?
It should not be. Every allocation on AS212772 is held by AdGuard's own RIPE organisation rather than sub-allocated to third parties, and the aut-num announces nothing to downstream customers, so there is no rented space here to run an exit on. An AdGuard address read as your browsing IP rather than as your resolver is a misreading of the test.