Independent Reviews
Abstract encrypted VPN tunnel passing through protective network layers
VPN Privacy Published 6 Sept 2026 5 min read2 sources

Mullvad Is Closing Its Public Encrypted DNS Service

Mullvad will switch off the encrypted DNS servers it offers to the wider public on 2 November and sponsor the nonprofit Quad9 service instead. Most Mullvad VPN customers are unaffected, but manual DNS users need to change their settings.

By VPN Rocks Editorial Team

The short version

What you need to know

  • Mullvad says its public DNS-over-HTTPS service will stop on 2 November 2026 as it redirects resources to sponsor the nonprofit Quad9 Foundation.
  • Mullvad VPN subscribers normally use DNS inside the VPN tunnel and should not need to change anything. People who manually configured Mullvad DNS on a router, device or custom browser setting should migrate before the deadline.
  • Encrypted DNS protects the lookup between a device and its chosen resolver, but it does not tunnel all internet traffic or hide the public IP address from websites. A VPN and encrypted DNS solve overlapping but different network-privacy problems.

What is Mullvad shutting down?

Mullvad announced that it will retire the public encrypted DNS servers it has operated since 2022. The service lets people send DNS lookups over HTTPS even when they are not connected to Mullvad VPN. The shutdown is scheduled for 2 November 2026.

The provider says running a fast, privacy-focused public resolver is specialised work and that it will sponsor the nonprofit Quad9 Foundation rather than duplicate part of its infrastructure. This is a service migration, not an announcement that Mullvad VPN itself is closing.

Who needs to change settings before 2 November?

Most people connected through the Mullvad VPN app should see no change because the VPN already routes DNS through Mullvad's internal systems. Mullvad Browser users who kept its default encrypted-DNS configuration are expected to move automatically to Quad9.

Manual users need to act. TechRadar reports that custom Mullvad Browser variants, manually entered router or operating-system addresses, and Mullvad DNS profiles on iOS or macOS require attention. Existing Apple configuration profiles will stop working after the shutdown, so replace them using current instructions from the resolver you choose rather than copying an address from an unofficial guide.

Encrypted DNS and a VPN are not the same

DNS translates a name such as a website address into the network information needed to connect. DNS over HTTPS encrypts that lookup between your device and the selected resolver, which can reduce plain-text DNS visibility on a local network or at an internet provider.

It does not create a full-device tunnel. The DNS resolver can still receive the query, websites still see your connecting IP address, and other traffic is not automatically protected just because the lookup used HTTPS. A full-tunnel VPN encrypts supported traffic to the VPN provider and changes which public IP address destinations see, but the provider and any configured DNS resolver still require trust.

What you can do now

If you use the Mullvad VPN app with its normal DNS settings, confirm that you have not added a separate custom DNS profile and keep the app updated. If you configured Mullvad's public resolver independently, record where it is set, choose a replacement with a policy you understand and test name resolution after the change.

Do not wait until the old address fails silently. Check browsers, phones, computers and routers separately because a setting on one layer may override another. If filtering for malware, adverts or family use matters to you, verify that the replacement profile provides the exact feature rather than assuming every Quad9 or encrypted-DNS endpoint behaves identically.

VPN Rocks view

The useful lesson is to know which privacy layer you actually configured. An encrypted DNS profile can be worthwhile, but it is not a miniature VPN and it should not be marketed as one.

Mullvad's notice gives manual users time to migrate. Use that window to remove stale profiles, understand who will process DNS queries and test the final setup instead of making a last-minute address swap without checking the result.

Primary reading

Sources and further reading

We add plain-English context and practical advice. These links let you inspect the underlying reporting, research and official guidance directly.

Useful next steps