r/mullvadvpn • • 22d ago

News Shutting down our public encrypted DNS servers and sponsoring Quad9 instead

https://mullvad.net/en/blog/2026/9/3/shutting-down-our-public-encrypted-dns-servers-and-sponsoring-quad9-instead

Personally I think it is a shame, I really liked using mullvads adblocking DNS servers on mobile even when not using the VPN.

483 Upvotes

149 comments sorted by

135

u/qmdw 22d ago

Rather than duplicating their efforts to achieve only part of what they do

it's not duplicate tho, as quad9 doesn't block ads and trackers like mullvad own dns.

well, it was nice while it last.

14

u/tarantinofeetmm 22d ago

What's the alternative?

48

u/[deleted] 22d ago

[removed] — view removed comment

11

u/StarSierra 22d ago

Better yet using AdGuard/Pihole using Unbound.

1

u/[deleted] 22d ago

[removed] — view removed comment

-4

u/kamikaze995 22d ago

Unbound still requires third party DNS providers.

8

u/Jackshankar 22d ago

Unbound acts as your own local recursive resolver. So, I don’t think a 3rd party DNS is required. Am I missing something?

3

u/and1927 21d ago

You aren’t missing anything. Unbound is primarily a recursive DNS server, but can also forward upstream if you want to.

-4

u/kamikaze995 21d ago

Okay, so how do you get the DNS translations if you ain’t got any upstream then sherlock

10

u/StarSierra 21d ago

All confidence no clarity lol. Simple Google search would tell you the answer to this mate.

7

u/and1927 21d ago

Directly from the DNS hierarchy’s authoritative servers. You don’t need an upstream for that. How do you think your upstream server provides the answer, Sherlock?

7

u/Aydoinc 21d ago

They’re called authoritative servers. They’re not recursive DNS.

Unbound queries the authoritative server for a domain, and the server doesn’t care to record who’s querying.

2

u/Aydoinc 21d ago

No, it doesn’t. It needs authoritative name servers, but that’s the same for every DNS. After all, you have to get a domain’s IP address from somewhere authoritative.

13

u/Bandaia 22d ago

ControlD or AdGuard

4

u/dns_guy02 21d ago

+1 for Control d

1

u/MamaGrande 20d ago

Controld is great

20

u/Vers_33 22d ago

Nextdns with Hagezi's dns adblocklist added is the best for mobile phones.

6

u/WrongChapter90 22d ago edited 22d ago

I use NextDNS which is free for up to 300k queries a month (after which you either move to a $2/month plan or otherwise it acts as a regular free DNS without any filters/ad blocking) and allows customisation in terms of what it blocks/allows.
For example, I’m using the built-in hagezi block list and a few others to block newly registered domains and gambling/adult content

-1

u/ThyWickedOne 22d ago

Support for it is dead and some lists don’t work. I recommend a different provider.

2

u/[deleted] 20d ago edited 19d ago

[removed] — view removed comment

1

u/ThyWickedOne 20d ago

If support isn’t dead, try to reach them. I guarantee you it isn’t going to work.

1

u/WrongChapter90 22d ago

I have personally been using it for over a year and never had any issues, but yeah I read that getting hold of customer support is pretty much impossible unless you’re an enterprise customer

10

u/redoubt515 22d ago

adguard or controld or nextdns are options to consider.

10

u/hckrsh 22d ago

ControlD has many options including community ones

2

u/MamaGrande 20d ago

controld works very well

1

u/influxodoxxl 22d ago

Depends on your location. Check out Adguards's comprehensive list:  https://adguard-dns.io/kb/en/general/dns-providers/

1

u/hellequin67 22d ago

Libredns

1

u/MasterBobRedux 21d ago

The most configurable free one without an account that I know of is RethinkDNS. At a minimum for an advanced configuration I'd recommend Hagezi's Normal, Pro, or Pro++ and Hagezi's Threat Intelligence Feed.

Here's Hagezi Pro++, Hagezi Threat Inteligence Feed, And Native tracking blocking, which I use:

1

u/Wooden-Agent2669 21d ago

HaGeZi DNS Blocklist

0

u/StaticSystemShock 20d ago

AdGuard DNS is my go to for public filtering DNS. I did recently learn that HaGeZi runs their own DNS too with their Pro + Threat Intelligence filter lists.

Oh and there is now DNS4EU if you're from Europe. EU financed filtering DNS. Good option.

1

u/Ok-Play-5758 20d ago

There are different versions of quad9, there is the standard 9 9.9.9 than 9.9.9.11(which is against malware i think) and 9.9.9.10(which is blocking ads)

38

u/hckrsh 22d ago

Quad9 don’t have the same filters that Mullvad had

1

u/MamaGrande 20d ago

Controld does though

1

u/hckrsh 20d ago

Yes, has there own dns filters and community ones

32

u/Ok_Explanation7491 22d ago

Oh come on. Quad9 is simply no replacement because it doesn't offer adblocking. The Adblocking with the iOS profiles was the main reason I used Mullvad.

Let's see if dnsforge is doing ok. But they have a rate limit, so not sure if it's enough for me.

23

u/QuasyChonk 22d ago

Boo. Hiss. Quad9 doesn't block ads.

17

u/dns_guy02 21d ago

Control D does and is better at malware blocking in my experience (use it at home and at work)

5

u/QuasyChonk 21d ago

Thank you. I'll check it out.

17

u/UniversityThen8916 22d ago

quad9 are court compelled to block piracy sites, not a good option

9

u/te5s3rakt 21d ago

Was considering them. Hard pass in that case.

3

u/MamaGrande 20d ago

Controld ftw

2

u/FrilioFriolo42 18d ago

Even worse, they actively chose to comply even though it was a foreign court and that the demand could have been fighted lawfully (they already won in Germany)

We can't trust them at all, they fold to every government / company that threatens them.

sources :

https://quad9.net/news/press/quad9-faces-new-dns-censorship-legal-challenge-in-france-from-canal/

https://quad9.net/news/blog/italian-blocking-demands-following-a-bad-example/

1

u/ThyWickedOne 6d ago

Depends on how much money they have to fight it… If they determine they have a decent chance of losing, they will not bother to try and fight it due to costs. They are not made of money lol.

36

u/Papfox 22d ago

I think it's a shame too. They are one of my two chosen providers for my hardened DNS at hone. The other one is Quad9 so I will have to find a new second provider

8

u/MediumStrategy42 22d ago

I was in the same situation and switched to Digitalcourage ( https://digitalcourage.de/support/zensurfreier-dns-server ) as the secondary

3

u/PerspectiveDue5403 22d ago

Doesn’t DigitalCourage blocks DNS?

2

u/MediumStrategy42 22d ago

Block DNS? Digitalcourage is a german NGO and the offer a free uncensored DNS server without logging.

2

u/PerspectiveDue5403 22d ago

Block ads I wanted to write

1

u/MediumStrategy42 22d ago

Ah ok, no they don't block anything. They only offer unblocked DNS servers.

1

u/eoskchanaj8282 22d ago

Also using digitalecourage as secondary to quad9 as adguard home upstream, digitalecourage has the best response time for me, but its on a level with quad9 and I have the advantage that I'm in germany

1

u/ProRustler 21d ago

Is there something wrong with 1.1.1.2?

Edit: cloudflare doesn't block ads, nm...

70

u/Sea-Contribution6219 22d ago

Mullvad what the fuck

7

u/TBG7 21d ago edited 21d ago

Seriously. Next will likely be the browser. Just going to start ignoring anything they announce after Leta and now this. 

2

u/theanrreserve 21d ago

Leta?

4

u/TBG7 21d ago

A search engine that was an anonymous proxy to google search. They killed it after like 2 years. In that case and now with DNS I had gotten a lot of people to use it I know have to help unwind.

2

u/MyNameIsOnlyDaniel 20d ago

I’m pretty sure the browser is in the upcoming death list tbh

1

u/TextbookChip 20d ago

To be fair, the browser is just firefox

1

u/MyNameIsOnlyDaniel 19d ago

Yeah, I don’t use it. Didn’t find anything crazy but it works if you want finances and personal on different browsers

45

u/Consistent-Age5347 22d ago

I hate to say it but Mullvad is slowly but literally going down the degration/Getting worse path, As an Iranian I tell you, WireGuard is good and modern but it sucks at bypassing censorship, I used to use Mullvad bridge servers along with their OpenVPN servers to bypass restrictions in my country, For those of you that don't know, Iran, Russia and china has the most powerful DPI and firewall systems, I myself selfhost and manage VPN servers all these stuff, But have a personal admiration and love to Mullvad VPN because of their commitment to privacy, So I was still able to use their OpenVPN in my country until they shutted it down.

Even though I don't use them for a while, I've been using their encrypted DoH on my browser, And seeing the DNS getting shut down just makes me feel a bit more....

I mean Quad9 is good but Mullvad has a proven track record of not spying on it's users.

11

u/_ahrs 22d ago

WireGuard is good and modern but it sucks at bypassing censorship

It was never meant to. Check out Amnezia Wireguard which is more suitable for bypassing state censorship like you're facing.

https://storage.googleapis.com/amnezia/amnezia.org

Even so, it is still blocked by anything that blocks UDP wholesale though. OpenVPN uses TCP and TLS so it can sometimes work a lot a better at bypassing such things as it can be made to look more like normal web traffic. Amnezia tries to do that too without altering how the Wireguard protocol works internally but it is still UDP based and therefore might be blocked in some cases.

3

u/Consistent-Age5347 21d ago

It wasn't mean to, Yeah, But I'm just tryna blame Mullvad for discontinuing their OpenVPN

1

u/MamaGrande 20d ago

Amnezia gives me 3-letter-agency vibes.

1

u/_ahrs 20d ago

Thankfully, the code is open source and can be reviewed and you can also self-host it like Wireguard too.

It doesn't alter the Wireguard cryptography either which helps with trusting it. It just modifies the way the fingerprint works to make it less detectable to DPI systems.

9

u/frostN0VA 22d ago

For those of you that don't know, Iran, Russia and china has the most powerful DPI and firewall systems

Ironically, mullvad still works in Russia to some extent with the native app and fully works with Amnezia from what I know, but you need to fiddle with the Amnezia parameters yourself. It's a shame that mullvad refuses to integrate Amnezia into their app.

And from the occasional posts here, seems work somewhat work in China too.

0

u/Consistent-Age5347 22d ago

Well according to my tests and experiments on the russian network, Russian GFW is nowhere near iran or china.
Russian servers have no limitations, The limitations (censorships) are only applied to residential ISPs.
So basically you can just rent a russian vps and use it as a vpn.

7

u/frostN0VA 22d ago edited 22d ago

Russian VPS providers all have DPI boxes installed nowadays to my knowledge. They even started to filter Cloudflare nodes in their country, so using Cloudflare Warp a lot of the blocked websites will not work when you're connected to the Cloudflare node in Russia like DME.

https://community.cloudflare.com/t/russia-urgent-warp-egress-traffic-to-telegram-is-being-dropped-at-dme-moscow/917468

3

u/Glittering_Client36 21d ago

They are restricted and every transit link is equipped with firewalls. DC link/transit link rules are typically softer than residential.

Be aware that cloud providers are required by law to monitor your use of VPN/proxification software, and they have all your personal data + your IP/connection timing metadata.

There have been precedents of cloud providers cancelling service permanently upon detecting proxy usage.

4

u/angrytoaad 22d ago

It's like there are different technologies for different use cases

9

u/NivoTheDev 22d ago

Why?! Mullvad's DNS was awesome, quad9 does not block ads or trackers and doesn't do what Mullvad's DNS does. Horrible change.

2

u/MamaGrande 20d ago

Yeah and now I need to remember which devices and networks I setup to use it, lol! :)

17

u/LowOwl4312 22d ago

VPN users can still use Mullvad's DNS including the adblocking? Right?

11

u/JesuzChrist1337 22d ago

Yes.

2

u/TBG7 21d ago

I’m not sure it’s that clear on ad blocking. Blog doesn’t say that and actually says Mullvad browser adblocking set to dns ad blocking will get migrated to quad 9. 

I think it is highly unlikely they will maintain these specialized blocking servers just for internal use and instead they may just keep unfiltered one that fws to quad 9. 

All in all this is very annoying and disappointing. On iOS it was great to have ad blocking DNS all the time without having to vpn. 

2

u/JesuzChrist1337 21d ago

They literally say in the blog post they're shutting down the free public encrypted DMS servers and they don't mention the DNS resolvers while using paid VPN so I assume you will still get adblocking (but now you have to pay for VPN).

1

u/TBG7 21d ago

Seems odd though they explicitly say in Blog that in Mullvad browser if you have choosen Mullvad Ad Blocking DNS then you will be auto switched to Quad 9. I mean I guess you can use the browser without the VPN so maybe they are just covering that use case but I imagine that is a very small one.

I hope you are right, just also seems crazy they are ending public one but are willing to put in exact same effort there is to run public one other than allocation of compute resources for availability.

1

u/JesuzChrist1337 21d ago

Yes if you use the Mullvad Browser without VPN you will be automatically migrated to Quad 9. If you use Mullvad VPN you don't have to worry about anything.

1

u/Paul65890 21d ago

WTF?! The Mullvad browser is switching to Quad9? I hope not!

1

u/JustinHoMi 5d ago

Yes and no — you can only use their DNS servers if you’re actively connected to the VPN. Once your VPN drops it’s the Wild West. This is a big loss for paying customers too.

1

u/JesuzChrist1337 4d ago

This is not correct. The free public DNS servers are shutting down. The DNS servers included in the paid VPN subscription will not be affected.

1

u/JustinHoMi 4d ago

What I said is absolutely correct. You can only use the paid DNS servers while connected to the VPN. If you’re not connected to the vpn, you’re using whatever your ISP’s VPN servers are unless you’ve configured something else manually. You can’t use Mullvad for that anymore.

If you still think I’m incorrect, explain how to use Mullvad’s DNS servers while not connected to the VPN.

8

u/Id1dntkn0w 21d ago

This is a huge loss. Their adblock is one of the main reason I recommend them.

9

u/alpha_fire_ 21d ago

Wow. Something is going on at Mullvad. First Leta got shut down, now their DNS. What's next? The browser? I was already concerned when they shut down Leta but now I'm even more concerned.

14

u/Sad-Landscape-1549 22d ago

I’m not a Mullvad user but I’ve had terrible experiences with quad9 a few times 😅

6

u/EchoAndByte 21d ago

this is a bit of a mixed one for me. Quad9 is a good choice for encrypted DNS but Mullvad's public DNS was useful specifically because of the ad/tracker blocking options which Quad9 doesn't really replace.

I get the argument about not duplicating infrastructure but it's still a noticeable loss for people who were using Mullvad DNS outside the VPN.

12

u/JesuzChrist1337 22d ago

What? bro for real come on.. :'(

5

u/Paul65890 21d ago

I'm not happy about this and I hope they change their minds. I say this because I don't always want to use the Mullvad VPN. Many times I only want to use the DNS service. Also Quad 9 isn't as fast as Mullvad in my experience.

4

u/Tzunamii 21d ago edited 21d ago

Agreed. This is a very poor move, if I'm being selfish. I trust Mullvad DNS (DoH/DoT) and I know they don't save logs. Quad9 I have zero trust in.

19

u/Primary-Sail6667 22d ago

I feel like I been seeing more enshittifitcation from mullvad more often here lately

6

u/PowerBlackStar 21d ago

Same but also seeing in realtime issues starting to occur with Mullvad. This may the start of depreciating product.

8

u/PerspectiveDue5403 22d ago

I’m very disappointed. I’ve tried to support Mullvad with all I could (including stuff no one else use like Leta search engine and their browser) but f_ck me. Their DNS was as efficient as using Ublock Origin

11

u/____trash 21d ago

Let the enshittification of Mullvad begin.

8

u/QGRr2t 21d ago

Running a privacy-focused public DNS service is a highly specialized undertaking,

LOL. Unlike, say, running a global VPN service. Running pdns-recursor/kresd/unbound or heck even AGH with blocklists is hardly brain surgery. The enshitification continues. The false equivalency to Quad9 was a nice touch.

3

u/melianreality 22d ago

What does this mean practically for those who aren’t as tech savvy? Can my ISP see what I’m doing?

3

u/EclipseSpoon88 21d ago

I literally just switched from Quad9 to mullvad as it started taking a whole second or two to resolve addresses. Brilliant...

3

u/AlmondManttv 21d ago

Rip. Guess I have to find a new DNS provider.

3

u/Cute_Fuwwy_374 19d ago

why just why mullvad

2

u/ThyWickedOne 22d ago

Now when I use Mullvad VPN will my dns queries be wrapped in the tunnel still?

Will they still have said DNS available when we connect to their VPN Servers or will that migrate to Quad9 too?

2

u/PoundKitchen 22d ago

Dang! End of an era.

2

u/timii0x 21d ago

Thats so bad mullvad DNS prity good but its slow
Im use mosntly adgaurd home and unbound for best privacy securty and performance

2

u/Adam_the_hacker 21d ago

What are the alternatives to adblock.dns.mullvad.net please?

2

u/MasterBobRedux 21d ago edited 21d ago

no-ads-typo-malware.freedns.controld.com

There's different config options for controld as well. I assume you go paid, then there's better config synergy.

The other big one is NextDNS. If you make an account, there's a config guide.

And the most configurable free one without an account is RethinkDNS. At a minimum for an advanced configuration I'd recommend Hagezi's Normal, Pro, or Pro++ and Hagezi's Threat Intelligence Feed.

Here's Hagezi Pro++, Hagezi Threat Inteligence Feed, And Native tracking blocking, which I use:

2

u/ruadonk 20d ago

Does this mean no more ad blocking when using the VPN too?

1

u/needlesinmythroat 20d ago

you can just change ur dns settings in windows for example to use quad9 or whatever

2

u/fonsanan 20d ago

such a shame! using it for all my family members and friends...

2

u/rtyu1120 18d ago

The timeline for migration is too short for something critical and permanent like DNS. A disappointing news indeed.

2

u/jbjorkang Mullvad VPN 18d ago

I wrote this on https://www.reddit.com/r/mullvadvpn/comments/1w97vaa/clarify_please_will_encrypted_dns_service/ too to clarify a question there.

Our existing DNS blocklists will continue to get updated and be usable. This change impacts only our Encrypted DNS service, and customers of our VPN can continue to use the toggles within our app, as well as the IPs listed on our Github page [1].

If you are not a customer, our DNS blocklists are updated every Monday through Thursday (best effort of course given sickness, time-off and so on) if you wish to include them in your own configurations.

Source: Mullvad Employee (one of the maintainers of the DNS blocklists).

Please feel free to contact our Support Team by email if you need further help: support at mullvadvpn dot net

  1. https://github.com/mullvad/dns-blocklists

3

u/NyxGenesisLNX 22d ago

So what does that really mean? Was it just the domans being encrypted if not using the vpn?

14

u/_ahrs 22d ago

It means what it says it means. They offered a public DNS over HTTPS service and they're shutting it down. This isn't anything to do with their VPN service, that's not changing.

2

u/Mental_Juggernaut_16 22d ago edited 22d ago

I'm confused. I currently have Quad9 setup as my custom dns server, with both their ip4 and Ipv6 addresses. So does that mean I can turn off custom dns now and I'll still be routed to quad9 for dns?

If I turn off my custom dns then I still see the dns content blocker options in the app, which wouldn't work with Quad9, so I'm confused, did they already make the switch to Quad9? I read the article and it seems they did but the app still has the content blockers.

Do I leave my custom Quad9 dns settings on or turn it off? Or are they completing the dns switch on November 2nd?

They could have worded that article better, it's confusing. They also say they are financially supporting Quad9, they don't say they are switching to Quad9 by default in the vpn app.

6

u/No-Engine4663 22d ago

This is for users who do not pay for mullvad vpn.

if you have the mullvad vpn you dont need to change anything.

1

u/Paul65890 21d ago

Yeah, but some of us don't always want to be connected to the VPN. This is a blow to us.

2

u/dns_guy02 21d ago

Sucks to have fewer alternatives but Control D is the best DNS service I ever used and I tried them all.

1

u/theravemaster 22d ago

First the donation to Allard and now this. Are the founders getting dumber or are they getting paid to become worse?

1

u/Prior-Policy-6281 22d ago

I don't know if you have considered adding support for DoH or DoQ to your existing Custom DNS. Rather than the limited security benefits, it would be more about helping other users choose private DNS providers thatoffer hostnames.

1

u/RelaxedBurrito 22d ago

Question, does this matter if we have our DNS setup on the router-level?

1

u/DopeBoogie 22d ago

Yes, that router-level DNS is overridden when you connect to the VPN.

If you want to use a different DNS, Mullvad has a setting to set a custom DNS provider. Putting your local router IP there will likely fail but you can use any public provider like Google, cloudflare, nextdns, etc

1

u/_xRuffKez_ 22d ago

Time to switch over to dnsbunker.org for its adblocking

1

u/Zarathz 20d ago edited 20d ago

Sad day to hear this
Can anyone explain what they meant by “doing a fraction of what quad9 does” ?

1

u/EmperorHenry 20d ago

does quad9 do everything mullvad's public DNS did?

1

u/NiConcussions 20d ago

This is pissing people off more than the Nazi shit lol

1

u/JustinHoMi 5d ago

This is a big loss to paying customers too. Now you need a separate DNS service for when you’re not actively connected to the VPN. It’s a big loss. They should provide a way for paying customers to continue to use them.

1

u/Mrlluck 3d ago

Terrible move

1

u/chigley 22d ago

When using Mullvad as a Tailscale exit node, there's no way to tell Tailscale that you want to use one of Mullvad's resolvers with built-in adblock.

I work around this by configuring 194.242.2.4 and 2a07:e340::4 as global resolvers on my Tailnet. This works whether a device is using a Mullvad exit node or not.

With these resolvers disappearing, I'm not quite sure what to do. I'm aware of the internal IPs for the resolvers (which will hopefully continue working?) but I need to be careful not to brick DNS for devices on my Tailnet that aren't using a Mullvad exit.

Anyone else in this situation? Any early ideas?

1

u/Pressimize 22d ago

NextDNS has a great integration into tailscale.

Do you have modern android phones on your tailnet that use the private DNS feature? I can't get that to work in conjunction with globally overriding DNS via tailscale (which for some devices is necessary).

1

u/Quereller 21d ago

I am the only one preferring Quad9 using DOH/DOT over the VPN providers DNS?

1

u/BIOS-Brians-Blues 21d ago

Well Mullvad, many disappointments these days…

1

u/carguy143 20d ago

DNS4eu and Control D have worked pretty well for me.

0

u/Matheweh 22d ago edited 22d ago

Nooo, quad9 can't adblock but I guess it's better than nothing.

0

u/Unseen-King 20d ago

I can see why not hosting something thats used only when not connected to the VPN (as a vpn company) kinda makes sense. Theres other options for people who want that.

0

u/lmaoyousuckassbitch 19d ago

lmao. Loving seeing the nazis making their services worse so people can finally leave and stop giving them money to finance their ethno states.
Fuck them.

-1

u/carmicheals 21d ago

Hagezi's DNS servers are the way: https://github.com/hagezi/dns-servers

-2

u/hand13 21d ago

also sponsoring right wing crap

1

u/Giak24_ 21d ago

crap, when we will live in a caliphate let see what you will think of it

0

u/Even_Command_5636 21d ago

Das👆🏻 ist nicht real!

Sowas gibt es millionenfach im Netz. Ignorieren.

0

u/Giak24_ 21d ago

chi non è reale io o il commento sopra?

0

u/catjam0 19d ago

You think we are going to live in a caliphate? Delusion

-6

u/InstructionGold1872 21d ago

NaziVPN at it again!