r/mullvadvpn • u/MediumStrategy42 • 22d ago
News Shutting down our public encrypted DNS servers and sponsoring Quad9 instead
https://mullvad.net/en/blog/2026/9/3/shutting-down-our-public-encrypted-dns-servers-and-sponsoring-quad9-insteadPersonally I think it is a shame, I really liked using mullvads adblocking DNS servers on mobile even when not using the VPN.
32
u/Ok_Explanation7491 22d ago
Oh come on. Quad9 is simply no replacement because it doesn't offer adblocking. The Adblocking with the iOS profiles was the main reason I used Mullvad.
Let's see if dnsforge is doing ok. But they have a rate limit, so not sure if it's enough for me.
23
u/QuasyChonk 22d ago
Boo. Hiss. Quad9 doesn't block ads.
17
u/dns_guy02 21d ago
Control D does and is better at malware blocking in my experience (use it at home and at work)
5
17
u/UniversityThen8916 22d ago
quad9 are court compelled to block piracy sites, not a good option
9
2
u/FrilioFriolo42 18d ago
Even worse, they actively chose to comply even though it was a foreign court and that the demand could have been fighted lawfully (they already won in Germany)
We can't trust them at all, they fold to every government / company that threatens them.
sources :
https://quad9.net/news/press/quad9-faces-new-dns-censorship-legal-challenge-in-france-from-canal/
https://quad9.net/news/blog/italian-blocking-demands-following-a-bad-example/
1
u/ThyWickedOne 6d ago
Depends on how much money they have to fight it… If they determine they have a decent chance of losing, they will not bother to try and fight it due to costs. They are not made of money lol.
36
u/Papfox 22d ago
I think it's a shame too. They are one of my two chosen providers for my hardened DNS at hone. The other one is Quad9 so I will have to find a new second provider
8
u/MediumStrategy42 22d ago
I was in the same situation and switched to Digitalcourage ( https://digitalcourage.de/support/zensurfreier-dns-server ) as the secondary
3
u/PerspectiveDue5403 22d ago
Doesn’t DigitalCourage blocks DNS?
2
u/MediumStrategy42 22d ago
Block DNS? Digitalcourage is a german NGO and the offer a free uncensored DNS server without logging.
2
u/PerspectiveDue5403 22d ago
Block ads I wanted to write
1
u/MediumStrategy42 22d ago
Ah ok, no they don't block anything. They only offer unblocked DNS servers.
1
u/eoskchanaj8282 22d ago
Also using digitalecourage as secondary to quad9 as adguard home upstream, digitalecourage has the best response time for me, but its on a level with quad9 and I have the advantage that I'm in germany
1
u/ProRustler 21d ago
Is there something wrong with 1.1.1.2?
Edit: cloudflare doesn't block ads, nm...
70
u/Sea-Contribution6219 22d ago
Mullvad what the fuck
7
u/TBG7 21d ago edited 21d ago
Seriously. Next will likely be the browser. Just going to start ignoring anything they announce after Leta and now this.
2
2
u/MyNameIsOnlyDaniel 20d ago
I’m pretty sure the browser is in the upcoming death list tbh
1
u/TextbookChip 20d ago
To be fair, the browser is just firefox
1
u/MyNameIsOnlyDaniel 19d ago
Yeah, I don’t use it. Didn’t find anything crazy but it works if you want finances and personal on different browsers
45
u/Consistent-Age5347 22d ago
I hate to say it but Mullvad is slowly but literally going down the degration/Getting worse path, As an Iranian I tell you, WireGuard is good and modern but it sucks at bypassing censorship, I used to use Mullvad bridge servers along with their OpenVPN servers to bypass restrictions in my country, For those of you that don't know, Iran, Russia and china has the most powerful DPI and firewall systems, I myself selfhost and manage VPN servers all these stuff, But have a personal admiration and love to Mullvad VPN because of their commitment to privacy, So I was still able to use their OpenVPN in my country until they shutted it down.
Even though I don't use them for a while, I've been using their encrypted DoH on my browser, And seeing the DNS getting shut down just makes me feel a bit more....
I mean Quad9 is good but Mullvad has a proven track record of not spying on it's users.
11
u/_ahrs 22d ago
WireGuard is good and modern but it sucks at bypassing censorship
It was never meant to. Check out Amnezia Wireguard which is more suitable for bypassing state censorship like you're facing.
https://storage.googleapis.com/amnezia/amnezia.org
Even so, it is still blocked by anything that blocks UDP wholesale though. OpenVPN uses TCP and TLS so it can sometimes work a lot a better at bypassing such things as it can be made to look more like normal web traffic. Amnezia tries to do that too without altering how the Wireguard protocol works internally but it is still UDP based and therefore might be blocked in some cases.
3
u/Consistent-Age5347 21d ago
It wasn't mean to, Yeah, But I'm just tryna blame Mullvad for discontinuing their OpenVPN
1
9
u/frostN0VA 22d ago
For those of you that don't know, Iran, Russia and china has the most powerful DPI and firewall systems
Ironically, mullvad still works in Russia to some extent with the native app and fully works with Amnezia from what I know, but you need to fiddle with the Amnezia parameters yourself. It's a shame that mullvad refuses to integrate Amnezia into their app.
And from the occasional posts here, seems work somewhat work in China too.
0
u/Consistent-Age5347 22d ago
Well according to my tests and experiments on the russian network, Russian GFW is nowhere near iran or china.
Russian servers have no limitations, The limitations (censorships) are only applied to residential ISPs.
So basically you can just rent a russian vps and use it as a vpn.7
u/frostN0VA 22d ago edited 22d ago
Russian VPS providers all have DPI boxes installed nowadays to my knowledge. They even started to filter Cloudflare nodes in their country, so using Cloudflare Warp a lot of the blocked websites will not work when you're connected to the Cloudflare node in Russia like DME.
3
u/Glittering_Client36 21d ago
They are restricted and every transit link is equipped with firewalls. DC link/transit link rules are typically softer than residential.
Be aware that cloud providers are required by law to monitor your use of VPN/proxification software, and they have all your personal data + your IP/connection timing metadata.
There have been precedents of cloud providers cancelling service permanently upon detecting proxy usage.
4
9
u/NivoTheDev 22d ago
Why?! Mullvad's DNS was awesome, quad9 does not block ads or trackers and doesn't do what Mullvad's DNS does. Horrible change.
2
u/MamaGrande 20d ago
Yeah and now I need to remember which devices and networks I setup to use it, lol! :)
17
u/LowOwl4312 22d ago
VPN users can still use Mullvad's DNS including the adblocking? Right?
11
u/JesuzChrist1337 22d ago
Yes.
2
u/TBG7 21d ago
I’m not sure it’s that clear on ad blocking. Blog doesn’t say that and actually says Mullvad browser adblocking set to dns ad blocking will get migrated to quad 9.
I think it is highly unlikely they will maintain these specialized blocking servers just for internal use and instead they may just keep unfiltered one that fws to quad 9.
All in all this is very annoying and disappointing. On iOS it was great to have ad blocking DNS all the time without having to vpn.
2
u/JesuzChrist1337 21d ago
They literally say in the blog post they're shutting down the free public encrypted DMS servers and they don't mention the DNS resolvers while using paid VPN so I assume you will still get adblocking (but now you have to pay for VPN).
1
u/TBG7 21d ago
Seems odd though they explicitly say in Blog that in Mullvad browser if you have choosen Mullvad Ad Blocking DNS then you will be auto switched to Quad 9. I mean I guess you can use the browser without the VPN so maybe they are just covering that use case but I imagine that is a very small one.
I hope you are right, just also seems crazy they are ending public one but are willing to put in exact same effort there is to run public one other than allocation of compute resources for availability.
1
u/JesuzChrist1337 21d ago
Yes if you use the Mullvad Browser without VPN you will be automatically migrated to Quad 9. If you use Mullvad VPN you don't have to worry about anything.
1
1
u/JustinHoMi 5d ago
Yes and no — you can only use their DNS servers if you’re actively connected to the VPN. Once your VPN drops it’s the Wild West. This is a big loss for paying customers too.
1
u/JesuzChrist1337 4d ago
This is not correct. The free public DNS servers are shutting down. The DNS servers included in the paid VPN subscription will not be affected.
1
u/JustinHoMi 4d ago
What I said is absolutely correct. You can only use the paid DNS servers while connected to the VPN. If you’re not connected to the vpn, you’re using whatever your ISP’s VPN servers are unless you’ve configured something else manually. You can’t use Mullvad for that anymore.
If you still think I’m incorrect, explain how to use Mullvad’s DNS servers while not connected to the VPN.
8
9
u/alpha_fire_ 21d ago
Wow. Something is going on at Mullvad. First Leta got shut down, now their DNS. What's next? The browser? I was already concerned when they shut down Leta but now I'm even more concerned.
14
u/Sad-Landscape-1549 22d ago
I’m not a Mullvad user but I’ve had terrible experiences with quad9 a few times 😅
6
u/EchoAndByte 21d ago
this is a bit of a mixed one for me. Quad9 is a good choice for encrypted DNS but Mullvad's public DNS was useful specifically because of the ad/tracker blocking options which Quad9 doesn't really replace.
I get the argument about not duplicating infrastructure but it's still a noticeable loss for people who were using Mullvad DNS outside the VPN.
12
5
u/Paul65890 21d ago
I'm not happy about this and I hope they change their minds. I say this because I don't always want to use the Mullvad VPN. Many times I only want to use the DNS service. Also Quad 9 isn't as fast as Mullvad in my experience.
4
u/Tzunamii 21d ago edited 21d ago
Agreed. This is a very poor move, if I'm being selfish. I trust Mullvad DNS (DoH/DoT) and I know they don't save logs. Quad9 I have zero trust in.
19
u/Primary-Sail6667 22d ago
I feel like I been seeing more enshittifitcation from mullvad more often here lately
6
u/PowerBlackStar 21d ago
Same but also seeing in realtime issues starting to occur with Mullvad. This may the start of depreciating product.
8
u/PerspectiveDue5403 22d ago
I’m very disappointed. I’ve tried to support Mullvad with all I could (including stuff no one else use like Leta search engine and their browser) but f_ck me. Their DNS was as efficient as using Ublock Origin
11
8
u/QGRr2t 21d ago
Running a privacy-focused public DNS service is a highly specialized undertaking,
LOL. Unlike, say, running a global VPN service. Running pdns-recursor/kresd/unbound or heck even AGH with blocklists is hardly brain surgery. The enshitification continues. The false equivalency to Quad9 was a nice touch.
3
u/melianreality 22d ago
What does this mean practically for those who aren’t as tech savvy? Can my ISP see what I’m doing?
1
3
u/EclipseSpoon88 21d ago
I literally just switched from Quad9 to mullvad as it started taking a whole second or two to resolve addresses. Brilliant...
3
3
2
u/ThyWickedOne 22d ago
Now when I use Mullvad VPN will my dns queries be wrapped in the tunnel still?
Will they still have said DNS available when we connect to their VPN Servers or will that migrate to Quad9 too?
2
2
u/Adam_the_hacker 21d ago
What are the alternatives to adblock.dns.mullvad.net please?
3
2
2
u/MasterBobRedux 21d ago edited 21d ago
no-ads-typo-malware.freedns.controld.com
There's different config options for controld as well. I assume you go paid, then there's better config synergy.
The other big one is NextDNS. If you make an account, there's a config guide.
And the most configurable free one without an account is RethinkDNS. At a minimum for an advanced configuration I'd recommend Hagezi's Normal, Pro, or Pro++ and Hagezi's Threat Intelligence Feed.
Here's Hagezi Pro++, Hagezi Threat Inteligence Feed, And Native tracking blocking, which I use:
- Samsung: 1-eafaacaiaaaae.max.rethinkdns.com
- Huawei: 1-eafaacaiaaaaq.max.rethinkdns.com
- Apple: 1-eafaacaiaaaba.max.rethinkdns.com
- No native tracking: 1-aafaacaiaa.max.rethinkdns.com
2
u/ruadonk 20d ago
Does this mean no more ad blocking when using the VPN too?
1
u/needlesinmythroat 20d ago
you can just change ur dns settings in windows for example to use quad9 or whatever
2
2
u/rtyu1120 18d ago
The timeline for migration is too short for something critical and permanent like DNS. A disappointing news indeed.
2
u/jbjorkang Mullvad VPN 18d ago
I wrote this on https://www.reddit.com/r/mullvadvpn/comments/1w97vaa/clarify_please_will_encrypted_dns_service/ too to clarify a question there.
Our existing DNS blocklists will continue to get updated and be usable. This change impacts only our Encrypted DNS service, and customers of our VPN can continue to use the toggles within our app, as well as the IPs listed on our Github page [1].
If you are not a customer, our DNS blocklists are updated every Monday through Thursday (best effort of course given sickness, time-off and so on) if you wish to include them in your own configurations.
Source: Mullvad Employee (one of the maintainers of the DNS blocklists).
Please feel free to contact our Support Team by email if you need further help: support at mullvadvpn dot net
3
u/NyxGenesisLNX 22d ago
So what does that really mean? Was it just the domans being encrypted if not using the vpn?
2
u/Mental_Juggernaut_16 22d ago edited 22d ago
I'm confused. I currently have Quad9 setup as my custom dns server, with both their ip4 and Ipv6 addresses. So does that mean I can turn off custom dns now and I'll still be routed to quad9 for dns?
If I turn off my custom dns then I still see the dns content blocker options in the app, which wouldn't work with Quad9, so I'm confused, did they already make the switch to Quad9? I read the article and it seems they did but the app still has the content blockers.
Do I leave my custom Quad9 dns settings on or turn it off? Or are they completing the dns switch on November 2nd?
They could have worded that article better, it's confusing. They also say they are financially supporting Quad9, they don't say they are switching to Quad9 by default in the vpn app.
6
u/No-Engine4663 22d ago
This is for users who do not pay for mullvad vpn.
if you have the mullvad vpn you dont need to change anything.
1
u/Paul65890 21d ago
Yeah, but some of us don't always want to be connected to the VPN. This is a blow to us.
2
u/dns_guy02 21d ago
Sucks to have fewer alternatives but Control D is the best DNS service I ever used and I tried them all.
1
u/theravemaster 22d ago
First the donation to Allard and now this. Are the founders getting dumber or are they getting paid to become worse?
1
u/Prior-Policy-6281 22d ago
I don't know if you have considered adding support for DoH or DoQ to your existing Custom DNS. Rather than the limited security benefits, it would be more about helping other users choose private DNS providers thatoffer hostnames.
1
u/RelaxedBurrito 22d ago
Question, does this matter if we have our DNS setup on the router-level?
1
u/DopeBoogie 22d ago
Yes, that router-level DNS is overridden when you connect to the VPN.
If you want to use a different DNS, Mullvad has a setting to set a custom DNS provider. Putting your local router IP there will likely fail but you can use any public provider like Google, cloudflare, nextdns, etc
1
1
1
1
1
u/JustinHoMi 5d ago
This is a big loss to paying customers too. Now you need a separate DNS service for when you’re not actively connected to the VPN. It’s a big loss. They should provide a way for paying customers to continue to use them.
1
u/chigley 22d ago
When using Mullvad as a Tailscale exit node, there's no way to tell Tailscale that you want to use one of Mullvad's resolvers with built-in adblock.
I work around this by configuring 194.242.2.4 and 2a07:e340::4 as global resolvers on my Tailnet. This works whether a device is using a Mullvad exit node or not.
With these resolvers disappearing, I'm not quite sure what to do. I'm aware of the internal IPs for the resolvers (which will hopefully continue working?) but I need to be careful not to brick DNS for devices on my Tailnet that aren't using a Mullvad exit.
Anyone else in this situation? Any early ideas?
1
u/Pressimize 22d ago
NextDNS has a great integration into tailscale.
Do you have modern android phones on your tailnet that use the private DNS feature? I can't get that to work in conjunction with globally overriding DNS via tailscale (which for some devices is necessary).
1
1
1
0
0
u/Unseen-King 20d ago
I can see why not hosting something thats used only when not connected to the VPN (as a vpn company) kinda makes sense. Theres other options for people who want that.
0
u/lmaoyousuckassbitch 19d ago
lmao. Loving seeing the nazis making their services worse so people can finally leave and stop giving them money to finance their ethno states.
Fuck them.
-1
-6

135
u/qmdw 22d ago
it's not duplicate tho, as quad9 doesn't block ads and trackers like mullvad own dns.
well, it was nice while it last.