-
Mullvad will close its free public encrypted DNS service on November 2, 2026, after running it since 2022.
-
The VPN company will send money and support to Quad9, a nonprofit group known for private DNS protection.
-
People who set up Mullvad’s public DNS by hand must switch soon, but most VPN users need to do nothing at all.
Mullvad has announced that it will shut down its public encrypted DNS service for good. The company built this free service back in 2022. It lets anyone use encrypted DNS lookups without paying a cent. Soon, that will change.
According to Mullvad’s official blog post, the company plans to close the service on November 2, 2026. Instead of running its own DNS servers, Mullvad will now put its money and effort behind Quad9. Quad9 is a nonprofit organization that also focuses on protecting people’s privacy online.
Mullvad shuts down its public DNS servers
Mullvad’s decision only affects one specific service. That service is called public DNS-over-HTTPS, or DoH for short. It does not affect the DNS system that Mullvad VPN uses internally. Mullvad explained that VPN customers already send their DNS requests through encrypted VPN tunnels. This means the standalone public DNS service adds little extra value for them.
The public DNS service mainly helped a different group of people. Mullvad Browser users who browse without turning on the VPN relied on it the most. Some other users also wanted the service. They wanted to stop their internet providers from seeing their DNS requests in plain text. Both groups will now need another option once the shutdown date arrives, based on details from Mullvad’s announcement.
Mullvad VPN itself is not closing. The company made that point clear. This shutdown only removes one piece of a much larger set of privacy tools that Mullvad offers.
The Reason Behind the Move to Quad9
Mullvad chose to stop building its own public DNS tool for a clear reason. The company called running a privacy-focused DNS resolver a highly specialized job. Instead of competing with existing experts, Mullvad decided to support one directly. Quad9 already runs a trusted, privacy-first DNS network. Mullvad will now fund that work rather than duplicate it.
Quad9 brings an extra benefit that Mullvad’s own service did not always match. Reports from CyberInsider note that Quad9 blocks domains linked to malware and other harmful activity. This gives users an added layer of safety, not just privacy. Mullvad framed the switch as a smarter use of resources. The company can support an established group instead of stretching its own team thin.
This move fits a pattern seen elsewhere in the privacy tech space. Smaller providers often team up rather than compete when the tools serve the same mission. Mullvad’s leadership appears to see Quad9 as a stronger long-term partner for DNS privacy than building competing infrastructure alone.
Migration deadline and user reactions
The clock is now ticking for a specific group of users. Anyone who manually typed Mullvad’s public DoH addresses into a device, router, or browser must act. They need to switch to a new DNS provider before November 2, 2026. After that date, Mullvad’s public DNS addresses will simply stop working.
Not everyone needs to take action, though. Mullvad Browser users who keep the default DNS settings will move automatically. This includes people using the browser’s built-in ad-blocking setup. Their systems will shift over to Quad9 without any extra steps.
However, users who changed their DNS settings by hand must update them manually. Existing Mullvad DNS profiles built for iOS and macOS devices will also stop working. Users on those devices need to install new Quad9 profiles instead, according to details shared in Mullvad’s blog post.
The announcement sparked plenty of discussion across online privacy communities. Many users expressed disappointment, especially those who used Mullvad’s DNS service without ever subscribing to the VPN. Some questioned why Mullvad would hand this responsibility to another provider instead of continuing on its own, as seen in a thread on Reddit.
Other users pushed back against that concern. Several commenters on the Privacy Guides forum pointed out that Quad9 has a strong reputation for privacy and malware protection. They viewed the switch as a reasonable trade rather than a loss.
Some also raised questions about Mullvad’s DNS blocklists, which many people relied on for extra filtering. Mullvad responded by confirming that its blocklists will keep working and will remain available to VPN customers going forward.
In January 2026, Google dismantled IPIDEA’s proxy network, which secretly turned over 9 million Android devices into data relays through embedded SDKs. Attackers later exploited the network to build a botnet of at least 2 million devices for DDoS attacks.
For now, the key date to remember is November 2, 2026. Anyone using Mullvad’s public DNS servers directly should start planning their move to Quad9 well before then. VPN customers, meanwhile, can continue using Mullvad as usual, since their DNS traffic already runs safely through the VPN’s encrypted tunnel.