Skip to content
CUNICULA

Mullvad DNS

Free public encrypted DNS with DoH and DoT endpoints plus optional ad, tracker and malware blocking.

mullvad.net

Free public encrypted DNS with DoH and DoT endpoints plus optional ad, tracker and malware blocking.

Common useDNSDNSOperator dataHosted
Identity checksZero KYCNo document check recorded · identity exposure level 0/4
Evidence and riskVerified evidenceStandardMaterial claims checked against current sources.; no material risk recorded in them.
Last reviewedReviewed 22 Jun 2026KYC checked 22 Jun 2026 · verified jurisdiction · Source → official siteHow to cite this pageSource coverageVerified evidenceRecorded riskStandard
Evidence and facts

Evidence and facts

CUNICULA SCORE 4.0
45/100Limited evidencePrivacy 12/25 · Control 0/20 · Transparency 0/20 · Security 25/25 · Accountability 8/10 · Cap 69 · Method
JURISDICTIONSE
NOTEEncrypted DNS protects queries in transit but does not make the resolver blind to live requests. Mullvad states it logs no DNS requests or IP addresses. Anycast routing can send queries to a distant server, causing slowness or timeouts, and DNS blocking cannot block all ads or trackers.
AUDITED BYCure53
OPERATOR DATAHosted operator recorded
SOURCE COVERAGE
Verified evidenceINDEPENDENT AUDIT1/8Reviewed 22 Jun 2026 · Source → official site
LAST CHECKED2026-06-24
LAST UPDATED2026-06-22

Specs

DOCUMENT CHECKNone recorded
IDENTITY EXPOSURELevel 0/4
KYC TRIGGERSNo account, payment or identity verification required for public Mullvad DNS endpoints.
FEEFree
CATEGORIESDNS
FEATURESDNS over HTTPS, DNS over TLS, No logging, Ad blocking, Tracker blocking, Malware blocking, Swedish jurisdiction
TORNot listed
REGIONSGlobal availability
Review analysis, source material, related services, and history

Analysis

OVERVIEW

A free public encrypted resolver from an audited VPN operator: DoH and DoT endpoints, optional blocking tiers, no account, and a stated no-logging policy for queries.

LIMITS

Using one operator for both VPN and DNS concentrates the view of traffic and lookups in a single party, and the no-logging statement for the free resolver is policy rather than audited infrastructure.

USEFUL FOR

Replacing an ISP resolver without creating an account or configuration profile anywhere.

Sources · reviewed 2026-07-16

Corporate identity

Registry-sourced, not audited. The facts below come from cited web research rather than a direct registry query. Each claim links its own source.

LEGAL ENTITY
Mullvad VPN ABsource ↗
REGISTRATION NO.
559238-4001source ↗
INCORPORATED IN
Swedensource ↗
REGISTERED ADDRESS
Box 53049, 400 14 Gothenburg, Swedensource ↗
PARENT ENTITY
Amagicom ABsource ↗
Registry research · reviewed 2026-08-08

Ownership chain

Who owns the operator, read from the public register. Each step says what kind of evidence it rests on: a registry record can be checked, a company statement cannot.

  1. OPERATORMullvad VPN AB559238-4001 · Sweden
  2. SHAREHOLDERAmagicom AB556783-9807 · SwedenREGISTRY DATA

    The registry record for Mullvad VPN AB names Amagicom AB, organisation number 556783-9807, as its parent company.

    Bolagsverket company data for 559238-4001, via allabolag

The chain stops here because the register stops, not because the top was reached. Swiss and Swedish companies do not publish their shareholders, and a Czech joint-stock company does not list its own. Nothing above the last step should be assumed either way.

SAME OPERATOR

Mullvad VPN AB also runs one other service shown here. Comparing them compares products, not independent companies.

We wrote about this

Frequently Asked Questions

Is identity verification required?

No identity verification is recorded for typical use. No account, payment or identity verification required for public Mullvad DNS endpoints.

Which payment methods are accepted?

Please check the provider site for accepted payment methods.

Where is it available?

Recorded availability: GLOBAL.

Is the operator based in a Five Eyes country?

No. The recorded jurisdiction is SE, which is not a Five Eyes country. This is jurisdiction context and does not by itself establish that a service is safer or less safe.

How are identity, operator, and evidence fields reported?

Identity exposure is level 0 of 4. A hosted operator is recorded. Jurisdiction is shown as context, not a safety verdict. Source coverage is verified evidence, last reviewed 2026-06-22, and recorded risk is standard.

Related Services

Compare

Sources and history

Terms and privacy policy

No changes to the document we watch since we started checking on 9 Aug 2026. Last checked 9 Aug 2026.

Evidence basis: Claims on this page are linked to published sources for comparison, not certification, audit, endorsement, or recommendation; read the methodology and coverage map before relying on an entry.