Mullvad is shutting down its own DNS service because it thinks this free one is better
Mullvad’s decision to retire its free public encrypted DNS service and endorse Quad9 forces privacy‑focused users to reconsider how they resolve domain names, a core vector for tracking and malware. Understanding the motivations, the alternative’s strengths, and the migration deadline is essential for anyone who relies on DNS privacy as part of a broader security posture.
Mullvad’s DNS service shutdown rationale
In a recent announcement, Mullvad declared it will cease operating its own public encrypted DNS servers, citing resource allocation and strategic focus. The provider frames the move as a “business decision” to concentrate on its VPN core while still supporting user privacy through a third‑party resolver. By ending the service, Mullvad eliminates the operational overhead of maintaining DNS infrastructure, which can be costly and complex.
The announcement emphasizes that the change does not diminish Mullvad’s commitment to privacy; instead, it redirects users toward a service the company deems superior. This shift reflects a broader industry trend where smaller players outsource DNS to specialized providers that can offer higher uptime and stronger threat intelligence. Mullvad’s own DNS servers will be fully discontinued once the migration window closes.
Quad9’s positioning as the “undisputed leader”
Quad9 is described by Mullvad as the “undisputed leader” in public DNS, a claim backed by its reputation for blocking malicious domains and not logging client IP addresses. The service operates a global network of anycast servers, ensuring low latency while applying real‑time threat feeds from multiple security partners. This architecture provides both performance and a layer of protection against phishing and malware.
Quad9’s privacy model aligns with Mullvad’s ethos: it does not retain personally identifiable information and filters queries against a curated blocklist. The partnership allows Mullvad users to inherit these safeguards without additional configuration. Quad9’s public DNS is free and encrypted (DNS over TLS/HTTPS), matching the security guarantees previously offered by Mullvad’s own servers.
Migration timeline and user impact
Mullvad gave its user base a clear deadline: all manual configurations must switch to Quad9 before November 2, 2026. This window provides ample time for individuals and organizations to update router settings, device DNS entries, or automated scripts. Failure to migrate could result in DNS resolution failures or a fallback to less secure resolvers.
The transition is technically straightforward but requires awareness. Users who rely on Mullvad’s DNS for privacy‑enhanced browsing must replace the IP addresses (currently 10.8.0.1, etc.) with Quad9’s endpoints (e.g., 9.9.9.9 for IPv4). The change does not affect Mullvad’s VPN tunnel; it merely alters the upstream name‑resolution path. For enterprises, the deadline also triggers a need to audit policy documents that reference Mullvad’s DNS.
What This Actually Means For You
- Maintain privacy continuity: Switching to Quad9 preserves encrypted DNS without additional cost.
- Update all devices—routers, smartphones, PCs—to point at Quad9’s DNS servers before the November 2026 cutoff.
- Verify that your VPN connection still routes DNS queries through the new resolver to avoid DNS leaks.
- Monitor for any connectivity issues after the switch; most problems stem from cached settings.
- Document the new DNS configuration in your security policy to streamline future audits.
Immediate Action Steps
First, locate every place where Mullvad’s DNS IPs are configured—home routers, DHCP scopes, and manual device entries. Replace them with Quad9’s IPv4 address 9.9.9.9 and IPv6 address 2620:fe::fe, ensuring you enable DNS over TLS or HTTPS if supported.
Second, run a quick test using a DNS leak detection tool while connected to Mullvad’s VPN to confirm that queries are now resolved by Quad9. Record the results and keep a screenshot as proof of compliance before the deadline.
Frequently Asked Questions
What happens if I don’t switch to Quad9 by November 2, 2026?
Mullvad’s public DNS servers will stop responding, causing DNS resolution failures for any device still pointing at them. Your VPN will still work, but you’ll lose the encrypted DNS layer.
Is Quad9 truly free and privacy‑preserving?
Quad9 offers free DNS over TLS/HTTPS and does not log client IP addresses, matching Mullvad’s privacy standards. It also blocks known malicious domains, adding a security benefit.
Do I need to change anything in my Mullvad VPN client?
No. The VPN client continues to function unchanged; only the DNS server addresses need updating. Ensure the client’s DNS leak protection is enabled to route queries through Quad9.
What Do You Think?
Given Mullvad’s confidence in Quad9, does consolidating DNS under a single “undisputed leader” improve overall privacy, or does it create a new single point of failure?