Mullvad Encrypted DNS Is Shutting Down: 4 Best Alternatives

Mullvad is shutting down its free public encrypted DNS servers on November 2, 2026. If you manually configured a Mullvad DNS-over-HTTPS endpoint, replace it before that date. For most people, Quad9 is the closest alternative; Cloudflare is simpler for general encrypted DNS, NextDNS is better for custom filtering, and AdGuard DNS is strongest when blocking ads and trackers is the priority.
Mullvad announced the change on September 3, 2026. The company will fund the nonprofit Quad9 Foundation instead of continuing to operate a separate public resolver. Mullvad VPN subscribers normally do not need to change anything, because the VPN already encrypts their traffic and uses Mullvad's internal DNS.
Who needs to change their DNS settings?
| Your setup | Do you need to act? | What to do |
|---|---|---|
| Mullvad VPN app with default DNS | No | Keep using the VPN normally; its internal DNS is not the public service being retired. |
| Mullvad Browser with default DoH or included ad-blocking setting | Usually no | Mullvad says these users will be migrated automatically to Quad9. |
| Mullvad Browser with custom DoH | Yes | Choose and enter a replacement provider manually. |
| Mullvad DoH configured in a browser, operating system, router, or DNS client | Yes | Replace the endpoint before November 2. |
| Mullvad DNS profile installed on iPhone, iPad, or Mac | Yes | Remove the old profile and install a supported replacement profile. |
The distinction matters: Mullvad is retiring its public encrypted resolver, not the internal DNS used while connected to Mullvad VPN. Changing system DNS while a VPN is active may also have no effect if the VPN overrides that setting.
Why is Mullvad closing its public encrypted DNS?
In its official announcement, Mullvad said it has run free public DNS-over-HTTPS servers since 2022. The service protected DNS queries outside the VPN and was the default for Mullvad Browser when the browser was not connected through Mullvad VPN.
Mullvad concluded that operating a privacy-focused public resolver is specialized work and that supporting Quad9 would be more effective than duplicating it. This is a planned migration rather than a reported breach or DNS failure.
Best Mullvad encrypted DNS alternatives
1. Quad9: best direct replacement for most users
Choose Quad9 if you want a free, privacy-focused resolver that also blocks known malicious domains. It is Mullvad's recommended destination and the default migration target for standard Mullvad Browser configurations.
Quad9 is a Swiss-based nonprofit. Its recommended service enables threat blocking and DNSSEC validation. According to Quad9's service documentation, the main addresses are:
- IPv4:
9.9.9.9and149.112.112.112 - IPv6:
2620:fe::feand2620:fe::9 - DNS over HTTPS:
https://dns.quad9.net/dns-query - DNS over TLS hostname:
dns.quad9.net
Quad9 is the easiest recommendation for former Mullvad DNS users because it preserves the core idea: free encrypted resolution with a privacy and security focus. Its standard endpoint blocks domains associated with threats, so a rare false positive is possible. Quad9 also offers a non-blocking endpoint for users who want privacy-first resolution without threat filtering.
2. Cloudflare 1.1.1.1: best simple option for broad device support
Choose Cloudflare if you want straightforward encrypted DNS with extensive setup documentation and wide platform support. Its standard resolver does not try to be an ad blocker, while the 1.1.1.1 for Families variants can block malware or malware plus adult content.
- Standard IPv4:
1.1.1.1and1.0.0.1 - Standard DoH:
https://cloudflare-dns.com/dns-query - DoT hostname:
one.one.one.one - Malware-filtering DoH:
https://security.cloudflare-dns.com/dns-query
Cloudflare's current DoH documentation explains that queries travel inside HTTPS on port 443. For Windows users, our step-by-step guide shows how to enable DNS over HTTPS in Windows 11 with Cloudflare, including how to prevent unencrypted fallback.
3. NextDNS: best for custom blocklists and per-device policies
Choose NextDNS if you want to control categories, blocklists, allowlists, analytics, and device-specific rules. Unlike a fixed public resolver, it gives each account a configuration tied to a personal endpoint.
NextDNS currently lists a free tier with 300,000 queries per month and access to its features. Its Pro plan lists unlimited queries for €1.99 per month or €19.90 per year. Check the live NextDNS pricing page before subscribing because prices and limits can change.
The extra control also creates extra responsibility. Review logging and retention settings, protect the configuration ID, and test allowlists before deploying a strict policy across a household or company.
4. AdGuard DNS: best for DNS-level ad and tracker blocking
Choose AdGuard DNS if blocking ads and tracking domains across many apps is more important than using a neutral resolver. The public service supports DNS over HTTPS, DNS over TLS, and DNS over QUIC, with filtering and non-filtering choices.
AdGuard's official overview says its filtering resolver can identify domains associated with ads, trackers, and scams. DNS-level filtering cannot remove every ad—especially content delivered from the same domain as the app or video—but it can reduce unwanted requests without installing a browser extension on every device.
Quick comparison
| Provider | Best for | Threat blocking | Custom rules | Cost |
|---|---|---|---|---|
| Quad9 | Closest Mullvad replacement | Yes on recommended endpoint | No personal dashboard | Free |
| Cloudflare 1.1.1.1 | Simple, widely supported encrypted DNS | Optional Families endpoint | No personal dashboard | Free |
| NextDNS | Custom policies, analytics, and device controls | Configurable | Yes | Free limited tier; paid unlimited tier |
| AdGuard DNS | Blocking ads and trackers across devices | Yes on filtering endpoints | With private plans/configurations | Free public service; paid options available |
How to migrate safely before November 2
1. Identify where Mullvad DNS is configured
Check the browser's secure DNS setting, the operating system's network adapter, mobile configuration profiles, router settings, and any DNS proxy such as dnscrypt-proxy or an encrypted DNS client. Changing only the browser will not fix a Mullvad endpoint configured at the router level.
2. Record the old configuration
Save a screenshot or note before editing. Record whether you used a base, ad-blocking, extended, family, or custom Mullvad endpoint. This helps you choose a replacement with similar filtering instead of accidentally switching to a completely unfiltered resolver.
3. Enter both primary and secondary addresses
When configuring IPv4 or IPv6 manually, use the matched pair supplied by the same provider. Do not mix Quad9 as the primary resolver with Cloudflare as the secondary if you expect consistent filtering and privacy behavior.
4. Keep encryption enabled
Changing the numeric DNS address alone does not guarantee encryption. On supported systems, explicitly enable DNS over HTTPS or DNS over TLS and select the correct provider template or hostname.
5. Test resolution and encryption
Visit the provider's test page or use its documented diagnostic query. Confirm that ordinary websites load, the expected resolver answers, and DoH or DoT is active. Test a provider-supplied blocked-domain example if you chose malware filtering.
6. Check VPN and public Wi-Fi behavior
VPN apps commonly override system DNS. A captive portal may also fail to appear while a strict encrypted DNS configuration is active. If a hotel or airport sign-in page will not open, temporarily return DNS to automatic, complete the portal login, then re-enable encrypted DNS.
Encrypted DNS hides domain lookups from the local network, but it does not turn an untrusted hotspot into a VPN. Review our guide on checking whether public Wi-Fi is safe. Android users who need all traffic to stop when a VPN disconnects can also enable Always-On VPN and block connections without the VPN.
Do Mullvad VPN users need Quad9?
Not for normal use inside Mullvad VPN. Mullvad states that its VPN traffic is already encrypted and that its internal DNS handles queries. Adding an external resolver can be unnecessary and, if configured incorrectly, may undermine the VPN's intended DNS path.
If you use Mullvad Browser without Mullvad VPN and kept its default or included ad-blocking DoH option, the browser should migrate automatically. If you selected a custom resolver, Mullvad will leave that custom choice untouched.
Which alternative should you choose?
- Choose Quad9 for the closest no-cost replacement and built-in malicious-domain blocking.
- Choose Cloudflare for a simple resolver with broad documentation and easy browser or Windows setup.
- Choose NextDNS when you need custom policies, logs, allowlists, and device-level controls.
- Choose AdGuard DNS when DNS-level ad and tracker filtering is your primary goal.
For most people manually using Mullvad's public encrypted DNS, Quad9 is the sensible default. Whatever provider you select, migrate before November 2, 2026 and verify that encryption—not merely DNS resolution—is working.
Frequently asked questions
When will Mullvad public DNS stop working?
Mullvad tells manually configured users to switch before November 2, 2026.
Is Mullvad VPN shutting down?
No. The announcement concerns Mullvad's free public encrypted DNS servers. Mullvad VPN and its internal DNS are separate.
Will Mullvad Browser switch automatically?
Yes for users keeping the default DoH setting or the included ad-blocking option, according to Mullvad. Custom DoH configurations will not be changed automatically.
What happens to Mullvad DNS profiles on iOS and macOS?
Mullvad says existing iOS and macOS profiles will stop working. Replace them with a current profile from Quad9 or another trusted provider.
Does encrypted DNS replace a VPN?
No. DoH and DoT encrypt DNS queries, but they do not hide all traffic, change your public IP address, or create a full-device encrypted tunnel.


