Why is Mullvad Ending Its Public Encrypted DNS Service?
Operating a secure, privacy-focused public DNS-over-HTTPS (DoH) service at scale demands significant expertise and resources. Mullvad recognized that maintaining its DNS servers competes with specialized organizations like the Quad9 Foundation, which leads in providing encrypted DNS services that block malicious domains and enhance privacy.
To optimize resource use and reinforce community privacy infrastructure, Mullvad is ceasing its public DoH offerings and sponsoring Quad9 financially. This strategy allows it to focus on its core VPN services, which already encrypt DNS queries internally for users connected to Mullvad VPN.
How Does This Impact Mullvad VPN Users?
If you use Mullvad VPN, this DNS change has little to no impact on your encrypted traffic because the VPN handles DNS internally. However, if you rely on Mullvad’s public DoH servers while disconnected from the VPN—for example, when manually configured in your device or router—you will need to switch to Quad9 before November 2, 2026.
Failing to migrate will result in loss of DNS resolution from these servers after the shutdown date, potentially disrupting your internet connectivity outside the VPN.
Step-by-Step Guide to Switching from Mullvad DNS to Quad9
1. Identify Your Current DNS Setup
- Check if you use Mullvad DNS servers directly on your device, router, or via configuration profiles.
- If you use the Mullvad Browser with default DNS-over-HTTPS settings, the switch to Quad9 happens automatically.
2. For Mullvad Browser Users
- Ensure you have the latest browser update installed.
- If you customized Mullvad DoH variants, reset them to the default setting to enable automatic Quad9 migration.
3. For Users with Configuration Profiles (iOS/macOS)
- Remove current Mullvad DoH profiles as they will stop working after shutdown.
- Download and install Quad9's dedicated DNS profiles for your platform before November 2, 2026.
- Follow Quad9's official configuration guides carefully to avoid connectivity issues.
4. For Manual DNS Configurations on Routers or Other Devices
- Consult Quad9’s official DoH IP addresses and DNS server information.
- Manually replace Mullvad DNS server entries with Quad9’s in your device or router settings.
- Verify connectivity and DNS resolution after changes.
5. Test Your DNS Configuration
- Use online tools or command-line utilities to check your current DNS server and verify encryption (DoH).
- Confirm that DNS blockers or filters provided by Quad9 are active, such as malware and ad domain blocking.
Key Considerations and Common Pitfalls
- Do not delay migration until the last moment to troubleshoot any unexpected issues.
- Keep backups of your current DNS configurations before making changes.
- If DNS stops functioning after migration, double-check the server IP addresses and profiles for accuracy.
- Remember that VPN users do not need to manually change anything for DNS when connected to Mullvad VPN.
Practical Takeaway: What You Need to Do Now
To maintain uninterrupted, private, and secure DNS resolution outside of Mullvad VPN connections, plan your switch to Quad9 DNS services well before the November 2, 2026 deadline. Check your current DNS setup, update or replace Mullvad DNS configurations as needed, and follow Quad9’s official guides for smooth transition.
This change is designed to enhance overall DNS security and privacy by leveraging the expertise of a dedicated provider while allowing Mullvad to focus on VPN innovations.
