Mullvad VPN and DNS Leak-Proof Setup

At a glance

One tunnel, one resolver path, no browser exception. The leak-resistant Mullvad baseline uses in-tunnel DNS, blocks browser resolver exceptions, and treats encrypted DNS without VPN as a separate IP-exposed mode.

Traffic and DNS path from a device through the operating-system resolver and Mullvad VPN tunnel to Mullvad DNS, with browser DNS-over-HTTPS blocked and DNS-only mode shown separately as IP-exposed.
One tunnel, one resolver path, no browser exceptionCunicula
Data behind this diagram
Mullvad DNS leak-proof baseline
Mullvad DNS leak-proof baseline
SettingRequired stateVerify method
Auto-connectOnReboot and confirm automatic tunnel
Lockdown modeOnDisconnect; a fresh page must fail
Split tunnelingNo applicationsInspect split-tunnel list
Custom DNSOffMullvad Check reports no DNS leak
Browser secure DNSOff for this VPN profileCheck each browser; rerun Mullvad Check
DNS-only modeSeparate mode; IP exposedResolver reaches Mullvad DNS while public IP remains ISP address

This procedure configures the Mullvad desktop app so ordinary traffic and DNS use one VPN tunnel, then proves that the computer stops networking when that tunnel is unavailable. It uses Mullvad VPN with its default in-tunnel Mullvad DNS. It is for a reader on Windows, macOS, or Linux who wants one reproducible leak-resistant state, not a chain of custom resolvers and browser exceptions.

FOR
Desktop
Mullvad app 2026.3
Mullvad release
THREAT
ISP + DNS path
One enforced tunnel
Mullvad docs
TIME
20-35 min
Cunicula estimate
Cunicula procedure
COST
€5 / month
Flat price
Mullvad pricing

COST SOURCES: Mullvad pricing (retrieved 10 August 2026).

Before you start

  • Windows 11, macOS 14 or later, or a supported current Linux distribution with administrator access.
  • Mullvad desktop app 2026.3. The menu paths below are written for that desktop release.
  • A separate device that can reach Mullvad help if Lockdown mode blocks this computer during troubleshooting.
  • Five euros for 30 days, plus any exchange or payment fee charged by the method you choose.

Mullvad publishes one flat price of €5 for 30 days. It allows up to five devices per account. Cash and cryptocurrency can reduce conventional billing data; card, app-store, and bank methods create their normal payment records. The VPN provider still knows the account number and active tunnel connection.

STOP CONDITION: do not add a custom DNS server, split-tunneled browser, proxy extension, or second VPN during this procedure. Each exception creates another route that must be tested separately.

1. Create and fund a Mullvad account

Open the Mullvad VPN provider page and continue to the official site. Select Generate account number. Store the 16-digit number in a password manager as a secret; the account has no username and the number grants access. Add 30 days with the payment method that fits your billing threat. Do not add a name to the password-manager title.

Sign out of the website, sign back in with the stored number, and confirm the paid-until date. This test happens before installation so a copied digit error does not become a later connection diagnosis.

VERIFY: The account page shows at least 30 days remaining, the stored account number matches character for character, and no screenshot or shared note contains it.

SOURCES: Mullvad price and payment methods (retrieved 10 August 2026); Mullvad app account workflow (retrieved 10 August 2026).

2. Install the signed desktop app

Download the 2026.3 installer for the current operating system from Mullvad. When the page supplies a signature file, follow Mullvad's linked verification procedure before running it. Install with administrator approval, open the app, enter the account number, and allow the operating system's VPN permission prompt.

If About reports an older build, update before continuing. If it reports a later stable desktop build and the named settings have moved, use that release's official help rather than selecting a similar-looking control by guesswork.

VERIFY: About identifies Mullvad VPN 2026.3, the app logs in with the stored account, and the operating system shows Mullvad as the installed VPN provider.

SOURCES: Mullvad desktop download (retrieved 10 August 2026); Mullvad VPN desktop 2026.3 release (retrieved 10 August 2026).

3. Set the leak-resistant baseline

In Mullvad VPN 2026.3 set Settings → VPN settings → Auto-connect: On and Lockdown mode: On. Under general settings set Launch app on start: On. Keep Local network sharing: Off unless a documented printer or device requirement justifies and tests it. Open Split tunneling and remove every application.

Under VPN settings → DNS settings, turn all DNS content blockers Off for the baseline and set Custom DNS: Off. This makes the app use Mullvad's resolver through the tunnel. Filtering can be added only after the unfiltered path passes, because a custom resolver can sit outside the VPN path and create a leak.

VERIFY: VPN settings shows Auto-connect On, Launch app on start On, Lockdown mode On, Local network sharing Off, Split tunneling with zero apps, and DNS content blockers and Custom DNS both Off.

SOURCES: Mullvad VPN app settings (retrieved 10 August 2026); Mullvad DNS leak prevention (retrieved 10 August 2026).

4. Remove browser DNS exceptions

A browser's DNS-over-HTTPS feature can send queries to a resolver other than Mullvad. In the current Firefox desktop panel documented on 10 August 2026, open Settings → Privacy & Security → DNS over HTTPS and select Off. In current Chromium-based browsers, open the privacy and security settings, locate Use secure DNS, and turn it Off for this VPN profile.

Disable browser VPN and proxy extensions. Close every browser completely and reopen it so existing connections cannot be mistaken for traffic from the new state. This step does not claim encrypted DNS is bad: it removes a second resolver choice because DNS is already encrypted inside the VPN tunnel.

VERIFY: Every installed browser either uses the operating-system resolver or has secure DNS explicitly disabled for this profile; no VPN or proxy extension is enabled.

SOURCE: Mullvad browser DNS leak guidance (retrieved 10 August 2026).

5. Connect and run Mullvad Check

In the app choose a nearby country and city, connect, and wait for the green secure state. Open mullvad.net/check in each browser you use. Record the VPN connection, DNS, and WebRTC results. The expected result is a Mullvad VPN address with no DNS or WebRTC leak.

If DNS fails, close the browser, confirm Custom DNS remains off, confirm browser secure DNS remains off, and retest once. If WebRTC fails, remove browser proxy or VPN extensions and retest. Do not install an unreviewed “leak blocker” extension. If the check still fails after the one repair, disconnect and use Mullvad support with the test results.

VERIFY: Mullvad Check reports a Mullvad VPN connection and no DNS or WebRTC leak. Save the exit IP, server location, time, and three pass states.

SOURCES: Mullvad connection check (retrieved 10 August 2026); Mullvad leak-test interpretation (retrieved 10 August 2026).

6. Prove the kill switch

Leave Lockdown mode on. Manually disconnect inside Mullvad. Open a new private browser window and load a site you did not visit during the connected test. It must fail. Reconnect the VPN, reload the same page, and rerun Mullvad Check. This proves both directions: blocked without the tunnel and usable through it.

The built-in kill switch protects during an interrupted VPN connection. Lockdown mode extends blocking to intentional disconnects and before the next connection. If ordinary browsing succeeds while disconnected, treat the configuration as failed and do not use the machine for the protected activity.

VERIFY: With Lockdown mode on and the VPN manually disconnected, a new private browser window cannot load a fresh site; after reconnecting, that same site loads and Mullvad Check passes again.

SOURCE: Mullvad kill switch and Lockdown mode (retrieved 10 August 2026).

7. Prove startup behavior

Reboot the computer. Do not manually open Mullvad. As soon as the desktop appears, try to load a new page. Lockdown mode should block it until the app launches and auto-connect succeeds. Open Mullvad, confirm the secure state, then rerun the connection, DNS, and WebRTC checks.

Record the operating system, Mullvad version, server, and time. A configuration that passes only without a reboot is not complete. If auto-connect fails, keep Lockdown mode on, open Mullvad manually, and repair the startup setting before resuming protected activity.

VERIFY: After reboot, no page loads before the app establishes the tunnel, Mullvad connects without manual intervention, and Mullvad Check passes with a newly recorded exit IP.

SOURCE: Mullvad startup and auto-connect settings (retrieved 10 August 2026).

8. Configure DNS-only mode only when the VPN is intentionally absent

This is an optional, separate mode, not a fallback inside the VPN configuration. If a device cannot run Mullvad VPN and you knowingly accept exposing its IP, use the official encrypted DNS hostname base.dns.mullvad.net. On Android 9 or later, open Settings → Network & internet → Private DNS → Private DNS provider hostname, enter that exact hostname, and save. Do not enter a URL or IP address in that Android field.

DNS-only mode encrypts resolver traffic but does not hide the destination IP connections or replace a VPN. Label the device record DNS ONLY, IP EXPOSED. Do not combine this hostname with Custom DNS inside the Mullvad VPN app; in-tunnel default DNS remains the tested VPN configuration.

VERIFY: In DNS-only mode, the operating system reports base.dns.mullvad.net as private DNS and a resolver test reaches Mullvad DNS, while your recorded public IP remains the ISP address.

SOURCE: Mullvad encrypted public DNS hostnames (retrieved 10 August 2026).

What this setup does not protect

  • Mullvad replaces the ISP-visible destination path with a VPN provider path. It does not make browser logins, cookies, device identifiers, or activity anonymous.
  • The destination still sees the Mullvad exit IP and application traffic not protected by end-to-end encryption can still be read at its endpoints.
  • Split tunneling, local network sharing, custom DNS, browser secure DNS, virtual machines, containers, and other users can create paths outside the tested baseline.
  • DNS-only mode hides resolver queries from the local network but exposes the device IP and destination connections. It is not equivalent to the VPN mode.
  • Endpoint malware, operating-system VPN bugs, and traffic-correlation adversaries remain outside this setup's guarantee.
  • Access to one Mullvad account number controls all devices on that account. Protect it like a password.

LIMITATION SOURCES: Mullvad DNS leak guidance (retrieved 10 August 2026); Mullvad encrypted public DNS (retrieved 10 August 2026); Mullvad app limits and controls (retrieved 10 August 2026).

Maintenance

Rerun Mullvad Check after every app, browser, operating-system, resolver, split-tunnel, or network-sharing change. Repeat the disconnect and reboot tests monthly. If you deliberately enable a DNS blocker, custom resolver, local-network rule, or split-tunneled application, give that exception its own written threat, expected route, and pass/fail test.

Sources