What the hosts file is and why you'd edit it
Hosts is a plain text file the Windows resolver checks before it ever asks a DNS server: if a hostname is listed there, the IP on that line wins, and DNS is never queried for it. The file dates back to a time before DNS existed, and Windows still keeps it first in line — which is exactly what makes it useful. Entries are one per line: an IP address, a space or tab, then the hostname; anything after a # is a comment.
Today hosts earns its keep in four jobs: pointing development names at your own machine, blocking domains system-wide by sending them to a dead address, testing a site on a new server before DNS is switched, and rescuing yourself when DNS is broken but you know the IP. Community-maintained blocking lists extend the second job to thousands of ad and telemetry domains at once. None of this survives a careless edit, which is why the how matters more than the what.
- Local development — 127.0.0.1 myapp.test maps a name to your own machine
- System-wide blocking — 0.0.0.0 ads.example.com sends a domain into the void
- Migration testing — point example.com at the new server's IP before the real DNS switch
- Emergency access — reach a host when DNS is down but you know the address
- List blocking — paste a community hosts list to cut thousands of ad domains at once
Editing hosts correctly, step by step
Open the Start menu, type Notepad, right-click the result and choose “Run as administrator” — approve the UAC prompt. In Notepad, File → Open, paste C:\Windows\System32\drivers\etc\hosts into the address bar, and change the file filter from Text Documents (*.txt) to “All Files (*.*)”, otherwise hosts stays invisible. Add your lines after the existing content, keep the default comment block intact, then File → Save — the file must remain named hosts, with no extension.
One habit separates a working edit from a mystery: flushing the resolver cache. Windows caches lookups, so an old answer can keep winning for a while after your change. Open Terminal (Admin) — or press Win+R, run cmd — and execute ipconfig /flushdns; the reply “Successfully flushed the DNS Resolver Cache” means new lookups will honor your lines. Verify with ping example.com: if it answers from the IP you wrote, hosts is doing its job.
When hosts seems ignored — and how to reset it
Three culprits cover almost every “my edit does nothing” report. First, the DNS cache — fixed by the flush above. Second, the browser: Chrome and Edge can resolve names through their own secure DNS (DNS over HTTPS) and skip the operating system entirely, so a blocked domain still opens; turn off secure DNS in the browser's privacy settings and hosts rules apply again. Third, security software: some antivirus products guard hosts and silently revert changes, and Windows Security's Controlled folder access can block Notepad's save — check its notifications or Protection history before assuming Windows is broken.
Resetting hosts to stock is easy because the default file contains nothing but comments — the localhost lines are commented out with #. Delete your lines (or replace the whole file with the default comment block), save as administrator and flush again. Two warnings worth their bytes: if hosts contains entries you never wrote, especially ones pointing banks or social networks at odd addresses, treat it as a malware symptom and scan the machine; and if access stays denied even in an elevated Notepad, right-click hosts → Properties → Security and give Administrators full control — some lock-down tools tighten those permissions on purpose.
Questions and Answers
Why is access denied when saving the hosts file?
Because Notepad was opened without administrator rights — hosts is a protected system file. Close it, use Run as administrator from the Start menu, and save again. If it still fails, check Controlled folder access in Windows Security and the file's Security tab.
How do I block a website using the hosts file?
Add two lines — 0.0.0.0 example.com and 0.0.0.0 www.example.com — save, then run ipconfig /flushdns. The domain then resolves to a dead address in every app that uses Windows name resolution.
Why does my hosts entry not work in Chrome or Edge?
The browser's secure DNS (DNS over HTTPS) resolves names internally and bypasses the hosts file. Turn off secure DNS in the browser's privacy settings — or first check the entry with ping in a terminal to confirm hosts itself works.
Know what is included before you buy.
The one-time 30-minute trial covers core tools. PRO-labelled features stay locked until a paid license is activated.
Read next
Write to us: [email protected]