Mullvad VPN Setup Guide

At a glance

Four privacy VPNs, seven operating facts. Privacy VPN comparison from the article, with the April 2023 Mullvad search-warrant outcome retained as historical evidence rather than a provider claim.

Comparison of Mullvad, IVPN, LNVPN, and Proton VPN by email requirement, Monero payment, audit, open-source apps, logs policy, and price.
Four privacy VPNs, seven operating factsCunicula
Data behind this diagram
Privacy VPN provider comparison
Privacy VPN provider comparison
ProviderNo emailXMR paymentAuditOpen sourceLogs policyPrice per month
MullvadYesYesCure53YesNo logs€5
IVPNYesYesCure53YesNo logs$6
LNVPNNo accountNo; Lightning onlyNoNoNo logsPer minute
Proton VPNNo; email requiredYesSEC ConsultYesNo logs$4–10

Most VPNs want an email and a credit card. Mullvad wants neither. You get a 16-digit number, add time, and connect. That design matters more than marketing copy. It cuts away a whole layer of identity leakage.

Confirmed
email, name, or account required (Mullvad)
0
Random 16-digit account number only, no signup form
Mullvad monthly price, XMR and BTC accepted
€5
Cash by mail also accepted in some regions
Mullvad server countries (WireGuard only)
50
587 servers across 91 cities, per Mullvad’s live server list

Mullvad knows less

Most VPN providers, including the loud ones with "no-logs" slogans, still know your email and process a payment tied to you. If records exist, records can be demanded. With Mullvad:

  • No email address attaches to the account.
  • No name, phone number, or billing address.
  • You can pay without linking payment to identity. Cash by mail still exists.
  • The account number is random and says nothing about who you are.
  • Mullvad has passed independent audits (Cure53, Assured) and has a public record of having little to hand over.

In April 2023, Swedish police raided Mullvad's office and left with nothing useful. That is what a no-logs claim looks like when reality knocks.

Step 1: Generate the number

1

Create an account without credentials

Go to mullvad.net and see the provider page if you want more detail. Click Generate account number. That is the signup flow. No form. No email. No CAPTCHA. You get a 16-digit code like 1234 5678 9012 3456.

Save it. That number is the account. Lose it and it is gone. There is no recovery path. That is deliberate.

Step 2: Pay without a paper trail

2

Fund the account anonymously

Mullvad costs €5 per month. Their pricing page shows several payment methods. From most private to least:

  • Monero (XMR): the best choice. Open the account page, enter the number, choose "Add time" → Cryptocurrency → Monero, then send the exact amount to the XMR address shown.
  • Bitcoin via Lightning: faster and a bit cleaner than on-chain BTC. Use a non-custodial Lightning wallet.
  • Bitcoin on-chain: Mullvad gives you a fresh BTC address per payment, but the chain is public. If the BTC came from a KYC exchange, that trail still exists. CoinJoin first if you need it.
  • Cash by mail: slow, old, still real. Put cash and your account number in the envelope and follow Mullvad's instructions.

Step 3: Install the app

3

Download and sign in

Download the app from mullvad.net/download for Windows, macOS, Linux, iOS, or Android. If you avoid Google Play, grab the Android APK directly from Mullvad.

Open the app and enter the 16-digit account number. It connects with the number alone. No password. No 2FA.

Step 4: Connect and tighten settings

4

Pick a server location

The default settings work fine for most people. A few things deserve attention:

  • Avoid Five Eyes countries if your threat model includes government surveillance. Pick Switzerland, Iceland, or Germany instead of the US, UK, Canada, Australia, or New Zealand.
  • Kill switch: on by default. Keep it on.
  • DNS leak protection: Mullvad routes DNS through its own servers. You can also turn on its ad and tracker blocking DNS.
  • Split tunneling: useful on desktop and Android, but easy to misconfigure. Leak one app and you punch a hole in the setup.

Android VPN lockdown has a system-level leak

Android's Block connections without VPN setting can still let an installed app reveal the device's real network address. Research published in 2026 used Android's public NAT-T keepalive interface. Android sent a fixed UDP packet outside the VPN tunnel while Always-on VPN and lockdown were active. This is an Android system issue, not a failure inside Mullvad's encrypted tunnel.

The strongest result is a controlled packet capture from a Pixel 8 Pro running Android 16 over Wi-Fi. The access point recorded one-byte UDP packets every ten seconds to an address chosen by the app. The destination could see the non-VPN source IP and packet timing. The method did not carry browsing history, messages, DNS requests, or arbitrary app data. Read the research paper for the test matrix and limits.

A Samsung SM-F966B kept one physical Wi-Fi keepalive slot active for more than 24 hours. A Nothing A059 reached the active callback for the same public path. Those two tests did not include an external packet capture. Cellular packet emission was not measured on any device. The paper argues that the shared Android 12 and later code and firmware evidence support wider exposure, but direct runtime testing covered three Android 16 models.

The app did not need root, ADB, a hidden API, or the privileged packet-offload permission. Android passed the keepalive to Wi-Fi hardware without first applying the calling app's VPN-lockdown policy. The hardware could then send the packet without another normal app socket write.

KEEP VPN LOCKDOWN ENABLED
The setting still blocked ordinary traffic in the published control tests. Disabling it removes that protection and does not close the separate keepalive path.

No released fix was confirmed on 21 September 2026

The researcher reported the issue to Google's Android Vulnerability Reward Program on 15 May 2026. The public paper says Google marked it as a duplicate of a private issue. The available record did not identify a fix, CVE, severity decision, or release date.

Mullvad's notice says Android needs to repair the system path. Mullvad declined to ship a proposed workaround that would fill the available keepalive slots because the workaround would itself send packets outside the tunnel and could lose a race to a malicious app.

GrapheneOS issue 8617 remained open at this review. A contributor said on 30 August 2026 that the project would fix it soon. That statement is not a released patch. Check the issue and current release notes before treating the fix as shipped.

What to do now

  • Remove apps you do not trust. The demonstrated path needs an installed app to request the keepalive.
  • Install Android and device updates. A platform repair will arrive through an operating-system update if Google or a downstream project ships one.
  • Force stop or uninstall a suspected app. Both actions stopped the active keepalive in the Pixel test.
  • Reboot to stop an active request. The Pixel keepalive did not survive reboot, but an app can request it again after launch.

Android documents the underlying socket keepalive API. The GrapheneOS setup guide covers app permissions, profiles, and release checks. Those controls reduce other exposure but do not prove this issue is fixed.

Router mode trades simplicity for coverage

If you want every device in a house behind the VPN, load Mullvad's WireGuard config onto the router. OpenWRT and DD-WRT both support WireGuard. Generate the config from the Mullvad account page and import it.

This protects devices that cannot run VPN apps, like smart TVs and some IoT junk. It also means every device shares one exit IP and one router becomes the failure point.

Alternatives worth a look

IVPN uses a similar model. It accepts XMR, uses account IDs instead of email, and offers multihop. It runs from Gibraltar and has a Cure53 audit. Slightly pricier. Still good.

LNVPN drops accounts completely. You pay over Lightning by the minute and receive a WireGuard config. No subscription. No stored balance. Good for occasional use.

Proton VPN gives you Swiss jurisdiction, open-source clients, and a free tier. It still needs an email because it rides on a Proton account. Less private by structure than Mullvad or IVPN, but still much better than mainstream VPN brands.

A VPN hides traffic from your ISP and blocks basic IP tracking. It does not make you anonymous. The VPN provider still sees your real IP and where your traffic goes. For anonymity, route traffic through Tor after the VPN, or use Tor Browser on its own. A VPN gives privacy. Tor gives anonymity.

Minimum setup includes a Mullvad number, XMR payment, the Mullvad app, and WireGuard.


Updated 21 September 2026. Android VPN-lockdown evidence was checked against the research paper, Mullvad notice, GrapheneOS issue, and Android API reference.

Information is provided for educational purposes. Always verify provider terms. Not financial advice. Commercial disclosure.

Sources

Frequently Asked Questions

Does Mullvad VPN require an email address?

No. Mullvad uses a random 16-digit account number instead of an email address. You visit mullvad.net/account, click "Generate account number," and get a number like 1234 5678 9012 3456. No email. No name. No password. Add credit to that number and use the app. If you lose the number, recovery does not exist. Write it down. That design means Mullvad cannot easily tie usage back to your identity because it never asked for one.

Can Android leak my real IP when VPN lockdown is enabled?

Yes, on tested Android 16 devices over Wi-Fi. A normal app can ask Android to send fixed NAT-T keepalive packets outside the VPN path. The receiving server can see the physical network IP address and packet timing. The controlled packet capture used a Pixel 8 Pro. No cellular packet emission was measured. Reviewed 21 September 2026.

How do I pay for Mullvad anonymously?

Mullvad accepts Monero, Bitcoin, Lightning, cash by post, and less private methods like bank transfer. Monero is the best option. Buy XMR through Haveno DEX with cash if you can, then send it to Mullvad. That keeps your payment separate from your VPN use. Credit and debit cards work, but they tie your identity to the account.

Has Mullvad ever been raided or handed over user data?

In April 2023, Swedish police executed a search warrant at Mullvad’s office. They left without customer data because Mullvad’s systems did not contain the information they sought. The account-number system and no-logging architecture leave little customer data to hand over.

What is Mullvad Multihop and should I use it?

Multihop routes traffic through two Mullvad servers in different countries before it exits to the internet. If one server gets compromised, an attacker still should not see both your source IP and destination at once. Mullvad builds Multihop on WireGuard. It is slower, usually by about 20 to 40 ms. Use it for sensitive research or if you connect from a high-surveillance location. For normal use, single-hop is fine.

Is Mullvad better than IVPN or Proton VPN?

All three respect privacy far more than most VPN brands. Mullvad stands out because it needs no email at all. IVPN lets you register without email but still uses an account ID. Proton requires email. Mullvad and IVPN are audited and open-source. Proton is Swiss, but it also complied with a court order to log an activist's IP in 2021. For anonymity, Mullvad comes first, then IVPN, then Proton. If you want email, calendar, and cloud storage in one bundle, Proton makes more sense.