Direct answer
For the Ubiquiti UniFi Dream Machine Pro, resolver, filter, VPN and cache should be separated from a site or provider outage. First, test the same hostname and direct IP from two clients.
What this covers
- Ubiquiti UniFi Dream Machine Pro (UDM-Pro)
- UniFi network; Network application version, gateway ownership, VLANs, PoE and adoption state are part of every diagnosis.
- The specific fault this record addresses: cannot open websites because DNS fails
What it does not cover
- ×The same symptom on a different Ubiquiti product line, which has its own record and its own cited source
- ×An on-screen error code whose meaning has not been checked against this exact model's manual
- ×Live electrical, gas, sealed-system, internal battery-cell or structural repair — a technician boundary, not a self-service step
Differential
What actually causes this, and how to tell them apart
These are ordered by how often each one is the answer, not by how easy it is to try. The point of the middle column is that two causes producing the same headline symptom rarely produce the same detail — that detail is what tells you which one you have before you change anything.
- 1
The provider's DNS resolver is slow or failing
What separates it The link is up, some or all named sites fail or load slowly, but the connection test passes.
How to confirm Set a reliable public DNS on the router or the device and retest; if names resolve on the public resolver, the provider's was the problem.
- 2
A cached DNS entry is stale
What separates it One specific site fails or goes to the wrong place while others are fine, especially just after that site moved.
How to confirm Flush the DNS cache on the device and, if needed, restart the router so it re-queries; a stale cached record affects only the names it holds.
- 3
A content-filtering or security DNS service is blocking the name
What separates it Specific categories or sites fail to resolve, matching a filter or parental service that is enabled.
How to confirm Check whether a filtering DNS or parental/security service is intentionally blocking the name before treating it as a fault.
- 4
The device is set to a DNS server that is unreachable
What separates it One device fails to resolve while others on the same network are fine.
How to confirm Check that device's DNS settings; a manually-set DNS that is down or wrong breaks resolution for that device only.
Before you touch a setting
Record this first — changing settings destroys the evidence
Every item below stops existing the moment a reset, re-pair or settings change is made. Written down first, they are what separates the causes above; recovered afterwards, they are guesswork.
- Whether a numeric IP loads while the named site does not — the signature of a DNS fault.
- Whether all names fail or only specific ones, and on all devices or one.
- Which resolver is in use — provider, router, a public one, or a filtering service.
Confirm it is DNS by loading a numeric address versus a name
ReversibleA working IP with a failing name is DNS, not the connection.
Set a reliable public DNS on the router and retest
ReversibleResolves a slow or failing provider resolver.
Flush the device's DNS cache for a single stale or wrong entry
ReversibleFixes one misbehaving name without touching the rest.
Rule out a filtering/parental DNS service before calling it a fault
ReversibleA block may be intentional configuration.
Model-specific
What is true of this model and not of its siblings
Generic advice for the product line fails here. Each item below is a property of this specific model family that changes which of the steps above apply to you.
- Model scope
- UDM-Pro. UniFi network; Network application version, gateway ownership, VLANs, PoE and adoption state are part of every diagnosis.
- Type — rack GATEWAY/router, NO Wi-Fi
- The UDM Pro is a rack-mount UniFi gateway (router, firewall, controller, NVR) with NO built-in Wi-Fi radio — it does NOT broadcast a wireless network. So Wi-Fi symptoms (dead zones, wifi-drops) do not apply to it; you add separate UniFi access points for Wi-Fi. It handles routing, VLANs and the UniFi Network application.
- Needs separate access points
- Because it has no radio, 'no Wi-Fi' on a UDM Pro is expected — the Wi-Fi comes from UniFi APs you connect to it (often via a PoE switch). Troubleshoot Wi-Fi at the APs, not the gateway.
- UniFi controller/app
- Managed through the UniFi Network application (web/app), which is more advanced than consumer routers — VLANs, adoption, firmware and site settings live there.
- Symptom boundary
- This record covers Ubiquiti UniFi Dream Machine Pro when it cannot open websites because DNS fails. A different symptom on the same hardware, or this symptom on a different Ubiquiti product line, has its own record with its own causes and its own cited source.
Stop boundary
When this stops being a self-service repair
Continuing past any one of these costs more than the repair saves — in safety, in warranty, or in evidence a technician needs.
- !Do not point DNS at an unknown third-party server from an untrusted source — a malicious resolver can redirect your traffic. Use a reputable public resolver only.
Evidence ledger
Sources behind this answer
Visible sources support the visible claims. Home Product Support records the publisher, the fact used and the review date; community reports can suggest an issue but do not become a published fact on their own.
Where the manufacturer's article stops. Ubiquiti Help Center publishes this as "UniFi - DNS Troubleshooting Guide". Ubiquiti's own device-agnostic DNS troubleshooting article. Verified reachable and content-matched via the Browser tool 2026-08-28. What that article does not carry is the model boundary — it is written for a product line, and UDM-Pro is the scope applied here. Where a control label, terminal, indicator pattern or reset sequence differs on your unit, the manual for that exact model is the authority, not this page and not the article.
Exact questions
Common follow-ups
My UniFi Dream Machine Pro isn't broadcasting Wi-Fi.+
That is expected — the UDM Pro has no built-in Wi-Fi radio, so it never broadcasts a wireless network on its own. It is a rack gateway/router; Wi-Fi comes from separate UniFi access points (like a U6/U7 Pro) that you connect, usually through a PoE switch, and adopt in the UniFi Network application. So to add or fix Wi-Fi, work with the access points; the Dream Machine Pro handles routing, not the radio.
Some websites won't load but my connection seems fine.+
That is the classic sign of a DNS problem — the connection works but the name-to-address lookup is failing. Confirm it by loading a numeric IP address, which will work while the site name does not. Then set a reliable public DNS server on the router and retest; if names resolve on the public one, your provider's resolver was the issue. For a single stale site, flushing the device's DNS cache is usually enough.
Does this answer apply to every Ubiquiti model?+
No. It is scoped to UDM-Pro. UniFi network; Network application version, gateway ownership, VLANs, PoE and adoption state are part of every diagnosis.
What should I record before troubleshooting DNS or site not found?+
Record the complete model identifier, exact message or indicator, software/firmware where visible, the operating stage and what still works.
Why is a factory reset not the first step?+
A reset can erase accounts, networks, maps, schedules or preferences without distinguishing DNS, site not found. The ordered checks preserve that evidence.
When should I stop and use qualified service?+
Do not bypass managed security DNS without authorization.
Answer for the exact device and software version shown above.