Mullvad Public DNS Migration and VPN DNS Setup

Mullvad's public encrypted DNS service is scheduled to close on November 2, 2026. Manually configured public resolvers need replacing before that date. Mullvad VPN's internal DNS is separate and is not closing. Mullvad Browser's default and included ad-blocking DNS settings will migrate automatically to Quad9; custom settings will not.

Source: Mullvad's September 3 announcement, retrieved September 21, 2026. The migration guidance below is documentation-checked, not a local installation test.

Do I need to change my DNS settings?

Public DNS migration: action depends on where the resolver is configured
Public DNS migration: action depends on where the resolver is configured
ConfigurationAction before November 2, 2026
Mullvad VPN with default internal DNSNo resolver migration is needed inside the tunnel. Keep Custom DNS off for the VPN baseline below. Check any separate DNS settings used when disconnected.
Mullvad Browser with default or included ad-blocking DoHMullvad says these settings will migrate automatically to Quad9. Do not assume a manually entered hostname will migrate.
Mullvad Browser with custom Mullvad DoHReturn the DNS provider to the browser default, as Mullvad instructs, or deliberately configure a replacement.
Other browsers with custom Mullvad secure DNSReplace the custom DoH service using the replacement resolver’s browser instructions. A browser setting does not update operating-system DNS.
macOS or iOS with an installed Mullvad DNS profileRemove the old profile and install a replacement from the official Quad9 guide. See the profile steps and expiry warning below.
Android 9+ Private DNS without a VPNReplace the Mullvad hostname with dns.quad9.net, save, and check the resolver. See step 8.
Windows, Linux, routers, or other manual DoH/DoT clientsReplace the configured public Mullvad resolver, including any IPv4/IPv6 addresses and encrypted-DNS template. Follow the matching Quad9 platform guide; changing one device does not change the router.
VPN custom DNS or Apple Private RelayInspect the active resolver path separately. Most VPN clients and Private Relay do not use Apple DNS profiles; installing a profile does not prove those queries migrated.

The closure covers the public DoH and DoT service, not just its unfiltered option: dns.mullvad.net, adblock.dns.mullvad.net, base.dns.mullvad.net, extended.dns.mullvad.net, family.dns.mullvad.net, and all.dns.mullvad.net. Mullvad's public DNS documentation lists these variants and the closure date (retrieved September 21, 2026). Do not treat another public Mullvad hostname as a long-term replacement.

Replace a Mullvad DNS profile on Mac or iPhone

  1. Remove the old Mullvad profile. On macOS 15 or newer, use System Settings → General → Device Management; on macOS 13/14, Privacy & Security → Profiles. On iOS, use Settings → General → VPN & Device Management. These paths are documented in Mullvad's public DNS guide.
  2. In Safari, open Quad9's macOS Big Sur and later guide or iOS 14 and later guide. Download its recommended HTTPS (.9) profile for DNSSEC and threat blocking, not a copy from an unrelated site.
  3. On Mac, open the downloaded profile, then System Settings → Profile Downloaded and install it. On iOS, open Settings → Profile Downloaded and install it. Review the profile and approve the operating-system prompts.
  4. Visit on.quad9.net to check the resolver used by that browser. Check browser secure-DNS overrides separately. This result is not proof that every application uses the profile.

Quad9's profiles currently expire on January 19, 2027 and automatically disable at expiry. Set a reminder to obtain a new official profile before then. Quad9 recommends DoH for most users: blocked DoT does not fall back to unencrypted DNS, so a restrictive network can stop resolution. Most VPN clients, iCloud Private Relay, and Little Snitch may bypass the profile. The App Store, dig, and nslookup do not use Apple's encrypted DNS profile and cannot validate that path.

Quad9's Mac and iOS instructions were retrieved September 21, 2026. Its threat-blocking profile is not a like-for-like replacement for Mullvad's ad, tracker, family, or social-media filters. For other platforms, use the official Quad9 setup guides. Compare the public Mullvad DNS service and Quad9 separately from the VPN configuration below.

Mullvad VPN with internal DNS

At a glance

One tunnel, one resolver path, no browser exception. The leak-resistant Mullvad baseline uses in-tunnel DNS, blocks browser resolver exceptions, and treats encrypted DNS without VPN as a separate IP-exposed mode.

Traffic and DNS path from a device through the operating-system resolver and Mullvad VPN tunnel to Mullvad DNS, with browser DNS-over-HTTPS blocked and DNS-only mode shown separately as IP-exposed.
One tunnel, one resolver path, no browser exceptionCunicula
Data behind this diagram
Mullvad DNS leak-proof baseline
Mullvad DNS leak-proof baseline
SettingRequired stateVerify method
Auto-connectOnReboot and confirm automatic tunnel
Lockdown modeOnDisconnect; a fresh page must fail
Split tunnelingNo applicationsInspect split-tunnel list
Custom DNSOffMullvad Check reports no DNS leak
Browser secure DNSOff for this VPN profileCheck each browser; rerun Mullvad Check
DNS-only modeSeparate mode; IP exposedResolver reaches Mullvad DNS while public IP remains ISP address

This procedure configures the Mullvad desktop app so ordinary traffic and DNS use one VPN tunnel, then proves that the computer stops networking when that tunnel is unavailable. It uses Mullvad VPN with its default internal DNS, not the retiring public DNS service. It is for a reader on Windows, macOS, or Linux who wants one reproducible leak-resistant state, not a chain of custom resolvers and browser exceptions.

FOR
Desktop
Mullvad app 2026.3
Mullvad release
THREAT
ISP + DNS path
One enforced tunnel
Mullvad docs
TIME
20-35 min
Cunicula estimate
Cunicula procedure
COST
€5 / month
Flat price
Mullvad pricing

COST SOURCES: Mullvad pricing (retrieved 10 August 2026).

Before you start

  • Windows 11, macOS 14 or later, or a supported current Linux distribution with administrator access.
  • Mullvad desktop app 2026.3. The menu paths below are written for that desktop release.
  • A separate device that can reach Mullvad help if Lockdown mode blocks this computer during troubleshooting.
  • Five euros for 30 days, plus any exchange or payment fee charged by the method you choose.

Mullvad publishes one flat price of €5 for 30 days. It allows up to five devices per account. Cash and cryptocurrency can reduce conventional billing data; card, app-store, and bank methods create their normal payment records. The VPN provider still knows the account number and active tunnel connection.

STOP CONDITION: do not add a custom DNS server, split-tunneled browser, proxy extension, or second VPN during this procedure. Each exception creates another route that must be tested separately.

1. Create and fund a Mullvad account

Open the Mullvad VPN provider page and continue to the official site. Select Generate account number. Store the 16-digit number in a password manager as a secret; the account has no username and the number grants access. Add 30 days with the payment method that fits your billing threat. Do not add a name to the password-manager title.

Sign out of the website, sign back in with the stored number, and confirm the paid-until date. This test happens before installation so a copied digit error does not become a later connection diagnosis.

VERIFY: The account page shows at least 30 days remaining, the stored account number matches character for character, and no screenshot or shared note contains it.

SOURCES: Mullvad price and payment methods (retrieved 10 August 2026); Mullvad app account workflow (retrieved 10 August 2026).

2. Install the signed desktop app

Download the 2026.3 installer for the current operating system from Mullvad. When the page supplies a signature file, follow Mullvad's linked verification procedure before running it. Install with administrator approval, open the app, enter the account number, and allow the operating system's VPN permission prompt.

If About reports an older build, update before continuing. If it reports a later stable desktop build and the named settings have moved, use that release's official help rather than selecting a similar-looking control by guesswork.

VERIFY: About identifies Mullvad VPN 2026.3, the app logs in with the stored account, and the operating system shows Mullvad as the installed VPN provider.

SOURCES: Mullvad desktop download (retrieved 10 August 2026); Mullvad VPN desktop 2026.3 release (retrieved 10 August 2026).

3. Set the leak-resistant baseline

In Mullvad VPN 2026.3 set Settings → VPN settings → Auto-connect: On and Lockdown mode: On. Under general settings set Launch app on start: On. Keep Local network sharing: Off unless a documented printer or device requirement justifies and tests it. Open Split tunneling and remove every application.

Under VPN settings → DNS settings, turn all DNS content blockers Off for the baseline and set Custom DNS: Off. This makes the app use Mullvad's resolver through the tunnel. Filtering can be added only after the unfiltered path passes, because a custom resolver can sit outside the VPN path and create a leak.

VERIFY: VPN settings shows Auto-connect On, Launch app on start On, Lockdown mode On, Local network sharing Off, Split tunneling with zero apps, and DNS content blockers and Custom DNS both Off.

SOURCES: Mullvad VPN app settings (retrieved 10 August 2026); Mullvad DNS leak prevention (retrieved 10 August 2026).

4. Remove browser DNS exceptions

A browser's DNS-over-HTTPS feature can send queries to a resolver other than Mullvad. In the current Firefox desktop panel documented on 10 August 2026, open Settings → Privacy & Security → DNS over HTTPS and select Off. In current Chromium-based browsers, open the privacy and security settings, locate Use secure DNS, and turn it Off for this VPN profile.

Disable browser VPN and proxy extensions. Close every browser completely and reopen it so existing connections cannot be mistaken for traffic from the new state. This step does not claim encrypted DNS is bad: it removes a second resolver choice because DNS is already encrypted inside the VPN tunnel.

VERIFY: Every installed browser either uses the operating-system resolver or has secure DNS explicitly disabled for this profile; no VPN or proxy extension is enabled.

SOURCE: Mullvad browser DNS leak guidance (retrieved 10 August 2026).

5. Connect and run Mullvad Check

In the app choose a nearby country and city, connect, and wait for the green secure state. Open mullvad.net/check in each browser you use. Record the VPN connection, DNS, and WebRTC results. The expected result is a Mullvad VPN address with no DNS or WebRTC leak.

If DNS fails, close the browser, confirm Custom DNS remains off, confirm browser secure DNS remains off, and retest once. If WebRTC fails, remove browser proxy or VPN extensions and retest. Do not install an unreviewed “leak blocker” extension. If the check still fails after the one repair, disconnect and use Mullvad support with the test results.

VERIFY: Mullvad Check reports a Mullvad VPN connection and no DNS or WebRTC leak. Save the exit IP, server location, time, and three pass states.

SOURCES: Mullvad connection check (retrieved 10 August 2026); Mullvad leak-test interpretation (retrieved 10 August 2026).

6. Prove the kill switch

Leave Lockdown mode on. Manually disconnect inside Mullvad. Open a new private browser window and load a site you did not visit during the connected test. It must fail. Reconnect the VPN, reload the same page, and rerun Mullvad Check. This proves both directions: blocked without the tunnel and usable through it.

The built-in kill switch protects during an interrupted VPN connection. Lockdown mode extends blocking to intentional disconnects and before the next connection. If ordinary browsing succeeds while disconnected, treat the configuration as failed and do not use the machine for the protected activity.

VERIFY: With Lockdown mode on and the VPN manually disconnected, a new private browser window cannot load a fresh site; after reconnecting, that same site loads and Mullvad Check passes again.

SOURCE: Mullvad kill switch and Lockdown mode (retrieved 10 August 2026).

7. Prove startup behavior

Reboot the computer. Do not manually open Mullvad. As soon as the desktop appears, try to load a new page. Lockdown mode should block it until the app launches and auto-connect succeeds. Open Mullvad, confirm the secure state, then rerun the connection, DNS, and WebRTC checks.

Record the operating system, Mullvad version, server, and time. A configuration that passes only without a reboot is not complete. If auto-connect fails, keep Lockdown mode on, open Mullvad manually, and repair the startup setting before resuming protected activity.

VERIFY: After reboot, no page loads before the app establishes the tunnel, Mullvad connects without manual intervention, and Mullvad Check passes with a newly recorded exit IP.

SOURCE: Mullvad startup and auto-connect settings (retrieved 10 August 2026).

8. Configure DNS-only mode only when the VPN is intentionally absent

This is an optional, separate mode, not a fallback inside the VPN configuration. Without a VPN, the device's public IP remains visible to destinations. On Android 9 or later, search Settings for Private DNS, select Private DNS provider hostname, enter dns.quad9.net, and save. Do not enter a URL or IP address in that field. Quad9 says this mode is not used with a VPN or an enabled Quad9 Connect app. Check on.quad9.net and any browser DNS override separately.

DNS-only mode encrypts resolver traffic but does not hide the destination IP connections or replace a VPN. Label the device record DNS ONLY, IP EXPOSED. Do not combine this hostname with Custom DNS inside the Mullvad VPN app; in-tunnel default DNS remains the VPN baseline to verify with the tests above.

VERIFY: In DNS-only mode, Android records dns.quad9.net as Private DNS and on.quad9.net reports Quad9 in the browser being checked. DNS-only mode does not change the public IP.

SOURCE: Quad9 Android 9+ encrypted DNS instructions (retrieved 21 September 2026).

What this setup does not protect

  • Mullvad replaces the ISP-visible destination path with a VPN provider path. It does not make browser logins, cookies, device identifiers, or activity anonymous.
  • The destination still sees the Mullvad exit IP and application traffic not protected by end-to-end encryption can still be read at its endpoints.
  • Split tunneling, local network sharing, custom DNS, browser secure DNS, virtual machines, containers, and other users can create paths outside the tested baseline.
  • DNS-only mode hides resolver queries from the local network but exposes the device IP and destination connections. It is not equivalent to the VPN mode.
  • Endpoint malware, operating-system VPN bugs, and traffic-correlation adversaries remain outside this setup's guarantee.
  • Access to one Mullvad account number controls all devices on that account. Protect it like a password.

LIMITATION SOURCES: Mullvad DNS leak guidance (retrieved 10 August 2026); Mullvad encrypted public DNS (retrieved 10 August 2026); Mullvad app limits and controls (retrieved 10 August 2026).

Maintenance

Rerun Mullvad Check after every app, browser, operating-system, resolver, split-tunnel, or network-sharing change. Repeat the disconnect and reboot tests monthly. If you deliberately enable a DNS blocker, custom resolver, local-network rule, or split-tunneled application, give that exception its own written threat, expected route, and pass/fail test.

Sources