Mullvad VPN and DNS Leak-Proof Setup
One tunnel, one resolver path, no browser exception. The leak-resistant Mullvad baseline uses in-tunnel DNS, blocks browser resolver exceptions, and treats encrypted DNS without VPN as a separate IP-exposed mode.
Data behind this diagram
| Setting | Required state | Verify method |
|---|---|---|
| Auto-connect | On | Reboot and confirm automatic tunnel |
| Lockdown mode | On | Disconnect; a fresh page must fail |
| Split tunneling | No applications | Inspect split-tunnel list |
| Custom DNS | Off | Mullvad Check reports no DNS leak |
| Browser secure DNS | Off for this VPN profile | Check each browser; rerun Mullvad Check |
| DNS-only mode | Separate mode; IP exposed | Resolver reaches Mullvad DNS while public IP remains ISP address |
This procedure configures the Mullvad desktop app so ordinary traffic and DNS use one VPN tunnel, then proves that the computer stops networking when that tunnel is unavailable. It uses Mullvad VPN with its default in-tunnel Mullvad DNS. It is for a reader on Windows, macOS, or Linux who wants one reproducible leak-resistant state, not a chain of custom resolvers and browser exceptions.
- FOR
- Desktop
- Mullvad release
- THREAT
- ISP + DNS path
- Mullvad docs
- TIME
- 20-35 min
- Cunicula procedure
- COST
- €5 / month
- Mullvad pricing
COST SOURCES: Mullvad pricing (retrieved 10 August 2026).
Before you start
- Windows 11, macOS 14 or later, or a supported current Linux distribution with administrator access.
- Mullvad desktop app 2026.3. The menu paths below are written for that desktop release.
- A separate device that can reach Mullvad help if Lockdown mode blocks this computer during troubleshooting.
- Five euros for 30 days, plus any exchange or payment fee charged by the method you choose.
Mullvad publishes one flat price of €5 for 30 days. It allows up to five devices per account. Cash and cryptocurrency can reduce conventional billing data; card, app-store, and bank methods create their normal payment records. The VPN provider still knows the account number and active tunnel connection.
STOP CONDITION: do not add a custom DNS server, split-tunneled browser, proxy extension, or second VPN during this procedure. Each exception creates another route that must be tested separately.
1. Create and fund a Mullvad account
Open the Mullvad VPN provider page and continue to the official site. Select Generate account number. Store the 16-digit number in a password manager as a secret; the account has no username and the number grants access. Add 30 days with the payment method that fits your billing threat. Do not add a name to the password-manager title.
Sign out of the website, sign back in with the stored number, and confirm the paid-until date. This test happens before installation so a copied digit error does not become a later connection diagnosis.
VERIFY: The account page shows at least 30 days remaining, the stored account number matches character for character, and no screenshot or shared note contains it.
SOURCES: Mullvad price and payment methods (retrieved 10 August 2026); Mullvad app account workflow (retrieved 10 August 2026).
2. Install the signed desktop app
Download the 2026.3 installer for the current operating system from Mullvad. When the page supplies a signature file, follow Mullvad's linked verification procedure before running it. Install with administrator approval, open the app, enter the account number, and allow the operating system's VPN permission prompt.
If About reports an older build, update before continuing. If it reports a later stable desktop build and the named settings have moved, use that release's official help rather than selecting a similar-looking control by guesswork.
VERIFY: About identifies Mullvad VPN 2026.3, the app logs in with the stored account, and the operating system shows Mullvad as the installed VPN provider.
SOURCES: Mullvad desktop download (retrieved 10 August 2026); Mullvad VPN desktop 2026.3 release (retrieved 10 August 2026).
3. Set the leak-resistant baseline
In Mullvad VPN 2026.3 set Settings → VPN settings → Auto-connect: On and Lockdown mode: On. Under general settings set Launch app on start: On. Keep Local network sharing: Off unless a documented printer or device requirement justifies and tests it. Open Split tunneling and remove every application.
Under VPN settings → DNS settings, turn all DNS content blockers Off for the baseline and set Custom DNS: Off. This makes the app use Mullvad's resolver through the tunnel. Filtering can be added only after the unfiltered path passes, because a custom resolver can sit outside the VPN path and create a leak.
VERIFY: VPN settings shows Auto-connect On, Launch app on start On, Lockdown mode On, Local network sharing Off, Split tunneling with zero apps, and DNS content blockers and Custom DNS both Off.
SOURCES: Mullvad VPN app settings (retrieved 10 August 2026); Mullvad DNS leak prevention (retrieved 10 August 2026).
4. Remove browser DNS exceptions
A browser's DNS-over-HTTPS feature can send queries to a resolver other than Mullvad. In the current Firefox desktop panel documented on 10 August 2026, open Settings → Privacy & Security → DNS over HTTPS and select Off. In current Chromium-based browsers, open the privacy and security settings, locate Use secure DNS, and turn it Off for this VPN profile.
Disable browser VPN and proxy extensions. Close every browser completely and reopen it so existing connections cannot be mistaken for traffic from the new state. This step does not claim encrypted DNS is bad: it removes a second resolver choice because DNS is already encrypted inside the VPN tunnel.
VERIFY: Every installed browser either uses the operating-system resolver or has secure DNS explicitly disabled for this profile; no VPN or proxy extension is enabled.
SOURCE: Mullvad browser DNS leak guidance (retrieved 10 August 2026).
5. Connect and run Mullvad Check
In the app choose a nearby country and city, connect, and wait for the green secure state. Open mullvad.net/check in each browser you use. Record the VPN connection, DNS, and WebRTC results. The expected result is a Mullvad VPN address with no DNS or WebRTC leak.
If DNS fails, close the browser, confirm Custom DNS remains off, confirm browser secure DNS remains off, and retest once. If WebRTC fails, remove browser proxy or VPN extensions and retest. Do not install an unreviewed “leak blocker” extension. If the check still fails after the one repair, disconnect and use Mullvad support with the test results.
VERIFY: Mullvad Check reports a Mullvad VPN connection and no DNS or WebRTC leak. Save the exit IP, server location, time, and three pass states.
SOURCES: Mullvad connection check (retrieved 10 August 2026); Mullvad leak-test interpretation (retrieved 10 August 2026).
6. Prove the kill switch
Leave Lockdown mode on. Manually disconnect inside Mullvad. Open a new private browser window and load a site you did not visit during the connected test. It must fail. Reconnect the VPN, reload the same page, and rerun Mullvad Check. This proves both directions: blocked without the tunnel and usable through it.
The built-in kill switch protects during an interrupted VPN connection. Lockdown mode extends blocking to intentional disconnects and before the next connection. If ordinary browsing succeeds while disconnected, treat the configuration as failed and do not use the machine for the protected activity.
VERIFY: With Lockdown mode on and the VPN manually disconnected, a new private browser window cannot load a fresh site; after reconnecting, that same site loads and Mullvad Check passes again.
SOURCE: Mullvad kill switch and Lockdown mode (retrieved 10 August 2026).
7. Prove startup behavior
Reboot the computer. Do not manually open Mullvad. As soon as the desktop appears, try to load a new page. Lockdown mode should block it until the app launches and auto-connect succeeds. Open Mullvad, confirm the secure state, then rerun the connection, DNS, and WebRTC checks.
Record the operating system, Mullvad version, server, and time. A configuration that passes only without a reboot is not complete. If auto-connect fails, keep Lockdown mode on, open Mullvad manually, and repair the startup setting before resuming protected activity.
VERIFY: After reboot, no page loads before the app establishes the tunnel, Mullvad connects without manual intervention, and Mullvad Check passes with a newly recorded exit IP.
SOURCE: Mullvad startup and auto-connect settings (retrieved 10 August 2026).
8. Configure DNS-only mode only when the VPN is intentionally absent
This is an optional, separate mode, not a fallback inside the VPN configuration. If a device cannot run Mullvad VPN and you knowingly accept exposing its IP, use the official encrypted DNS hostname base.dns.mullvad.net. On Android 9 or later, open Settings → Network & internet → Private DNS → Private DNS provider hostname, enter that exact hostname, and save. Do not enter a URL or IP address in that Android field.
DNS-only mode encrypts resolver traffic but does not hide the destination IP connections or replace a VPN. Label the device record DNS ONLY, IP EXPOSED. Do not combine this hostname with Custom DNS inside the Mullvad VPN app; in-tunnel default DNS remains the tested VPN configuration.
VERIFY: In DNS-only mode, the operating system reports base.dns.mullvad.net as private DNS and a resolver test reaches Mullvad DNS, while your recorded public IP remains the ISP address.
SOURCE: Mullvad encrypted public DNS hostnames (retrieved 10 August 2026).
What this setup does not protect
- Mullvad replaces the ISP-visible destination path with a VPN provider path. It does not make browser logins, cookies, device identifiers, or activity anonymous.
- The destination still sees the Mullvad exit IP and application traffic not protected by end-to-end encryption can still be read at its endpoints.
- Split tunneling, local network sharing, custom DNS, browser secure DNS, virtual machines, containers, and other users can create paths outside the tested baseline.
- DNS-only mode hides resolver queries from the local network but exposes the device IP and destination connections. It is not equivalent to the VPN mode.
- Endpoint malware, operating-system VPN bugs, and traffic-correlation adversaries remain outside this setup's guarantee.
- Access to one Mullvad account number controls all devices on that account. Protect it like a password.
LIMITATION SOURCES: Mullvad DNS leak guidance (retrieved 10 August 2026); Mullvad encrypted public DNS (retrieved 10 August 2026); Mullvad app limits and controls (retrieved 10 August 2026).
Maintenance
Rerun Mullvad Check after every app, browser, operating-system, resolver, split-tunnel, or network-sharing change. Repeat the disconnect and reboot tests monthly. If you deliberately enable a DNS blocker, custom resolver, local-network rule, or split-tunneled application, give that exception its own written threat, expected route, and pass/fail test.
Sources
- Mullvad VPN desktop 2026.3 release, retrieved 2026-08-10
- Mullvad VPN official site · first-party source
- mullvad.net/check
- Mullvad connection check, retrieved 2026-08-10
- Mullvad desktop download, retrieved 2026-08-10
- Mullvad browser DNS leak guidance, retrieved 2026-08-10
- Mullvad encrypted public DNS hostnames, retrieved 2026-08-10
- Mullvad DNS official site · first-party source
- Mullvad startup and auto-connect settings, retrieved 2026-08-10
- Mullvad price and payment methods, retrieved 2026-08-10