How to Completely Disable ‘systemd-resolved’ (Local DNS Resolver) in Ubuntu Server

Modern versions of Ubuntu Server ship with a background daemon called systemd-resolved enabled by default. This service acts as a local DNS stub resolver. Instead of your applications querying a public DNS server (like Google’s 8.8.8.8) directly, every single application on your server routes its DNS queries to a local loopback address: 127.0.0.53. Systemd-resolved then intercepts the query, caches the result, and forwards it to the actual upstream DNS server.

While local DNS caching sounds beneficial, systemd-resolved is notoriously problematic for advanced networking setups. If you are deploying a custom DNS server (like Pi-hole, bind9, or CoreDNS), attempting to spin up Docker containers with strict networking rules, or configuring complex VPN tunnels (like WireGuard or OpenVPN), having systemd hijack port 53 on the local loopback interface will frequently cause catastrophic port conflicts and DNS leaks. To regain absolute, bare-metal control over your server’s DNS resolution, you must completely disable systemd-resolved and rely on a traditional static resolv.conf file.

Stopping and Disabling the Daemon via Systemctl

First, you must gracefully terminate the running process and ensure it never starts again upon reboot.

  1. Open a Terminal session (or connect to your server via SSH).
  2. Stop the daemon immediately:
    sudo systemctl stop systemd-resolved
  3. Permanently disable the service from launching at boot:
    sudo systemctl disable systemd-resolved

Restoring the Traditional Resolv.conf File

When systemd-resolved is active, it completely takes over the /etc/resolv.conf file, turning it into a symbolic link that points to its own internal configuration. With the daemon dead, you must destroy this symlink and manually define your DNS servers.

  1. Delete the systemd-hijacked symbolic link:
    sudo rm /etc/resolv.conf
  2. Create a brand new, static configuration file:
    sudo nano /etc/resolv.conf
  3. Inside this new file, manually define your trusted upstream DNS servers. For example, to use Cloudflare and Google, type the following:
    nameserver 1.1.1.1
    nameserver 8.8.8.8
  4. Save the file (Ctrl + O, then Enter) and exit the text editor (Ctrl + X).

Your Ubuntu server will now route DNS queries precisely the old-fashioned way. Applications will read the static resolv.conf file and query the defined IPs directly, completely bypassing the systemd middleman and leaving port 53 wide open for your custom routing solutions.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.