Mullvad Encrypted DNS Shutdown: 7 Key Changes Explained
The Mullvad encrypted DNS shutdown ends Mullvad’s free public DNS-over-HTTPS service on November 2. Most Mullvad VPN users remain unaffected because the VPN uses its own internal DNS, while people with manually configured DoH endpoints or Mullvad profiles on iOS and macOS must replace those settings. Default Mullvad Browser DNS configurations will move automatically to Quad9.
This is an infrastructure change, not evidence that encrypted DNS has failed and not the end of Mullvad VPN. The practical risk is much quieter: an old profile or hard-coded endpoint can sit in your settings looking impressively technical while domain resolution stops working. DNS rarely kicks down the door. It usually leaves you wondering why every website has suddenly taken the afternoon off.
The goal of Mullvad Encrypted DNS Shutdown: 7 Essential Next Steps is to help you identify whether you are affected, choose a suitable replacement, migrate one layer at a time, and verify the result. I also explain where Quad9 DNS fits, when a managed alternative makes sense, and why changing a resolver is not the same as changing your VPN.
| Your setup | What changes | What to do |
|---|---|---|
| Mullvad VPN with default DNS | Internal VPN DNS continues | No migration normally required |
| Default Mullvad Browser DNS | Moves automatically to Quad9 | Update the browser and verify |
| Included browser ad-blocking DNS | Moves automatically to Quad9 | Check behavior after the update |
| Customized browser DoH | Not changed automatically | Replace it or restore the default |
| Manual Mullvad DoH endpoint | Stops resolving after shutdown | Replace it before November 2 |
| iOS or macOS Mullvad profile | Existing profile stops working | Remove and replace the profile |
| Router or other manual client | A hard-coded endpoint may fail | Audit, migrate, then test |
Key Takeaways From the Mullvad Encrypted DNS Shutdown
- The public resolver is closing; Mullvad VPN itself is not losing DNS protection.
- Default Mullvad Browser users should be migrated to Quad9 encrypted DNS, but custom browser settings remain your responsibility.
- Existing Mullvad DNS profiles on iOS and macOS will not repair themselves when the endpoint stops responding.
- An IP address and a DNS-over-HTTPS URL are not interchangeable. The correct replacement depends on what the configuration field accepts.
- Quad9 is Mullvad’s designated successor; AdGuard DNS is a separate option when you want customizable filtering and device-level management.
- The safest migration changes one DNS layer at a time and records a working rollback value first.
- A successful page load proves that DNS works, not that the resolver and encrypted transport match your intended policy.
Exclusive HackersGhost discount code HACKERSGHOST20 applies automatically — AdGuard may occasionally run separate public promotions with similar pricing.
This is an affiliate link. I may earn a commission at no extra cost to you.
Mullvad Encrypted DNS Shutdown: What Actually Changed
Mullvad announced that it will retire the public encrypted DNS servers it operated outside its VPN service. The company is redirecting financial support toward Quad9 rather than continuing to duplicate a specialized global resolver operation. That is a strategic handover of a public service, not a security incident.
The distinction between public Mullvad encrypted DNS and Mullvad VPN’s internal resolver is the most important detail. When the Mullvad VPN app creates its tunnel, it already encrypts the traffic moving through that tunnel and handles DNS internally. Normal VPN users therefore do not need to paste a new public resolver into the app merely because they saw the words Mullvad DNS shutdown.
The people who do need to act are those who copied a Mullvad DoH address into a browser, operating system, router, DNS proxy, mobile configuration or another client. The same applies to existing Mullvad profiles on iOS and macOS. These configurations point directly at the retiring public infrastructure and can stop resolving domains after the deadline.
Mullvad Browser sits between those two groups. Its default DoH configuration and included ad-blocking option are scheduled to move automatically to Quad9. A customized Mullvad Browser DNS value will not be overwritten, which is sensible: software should not quietly replace a choice you made deliberately. It also means the owner of that choice is now staring back at you from the mirror.
HackersGhost Note: I treat this as a configuration-lifecycle problem. Privacy settings are not fire-and-forget decorations. Every endpoint you enter manually becomes a small dependency that you also agree to maintain.

Why Encrypted DNS Still Matters After the Shutdown
DNS translates a readable domain name into the network address your device needs. Traditional DNS commonly sends those requests without transport encryption. Someone able to observe that path may see which domains you ask to resolve, even when the website connection itself later uses HTTPS.
DNS over HTTPS carries those lookups inside an HTTPS connection between your client and the chosen resolver. DNS over TLS performs a similar transport-protection job through a dedicated TLS connection. Both can reduce casual observation or modification of DNS traffic on the local network and by intermediaries between you and the resolver.
That does not turn an encrypted DNS server into a VPN. The resolver can still process the domain request, the destination can still see a connecting IP address, and other traffic metadata still exists. Encryption protects the route to the resolver; the provider’s privacy policy and operating practices determine what happens at the resolver.
This is why the Mullvad encrypted DNS shutdown should lead to a controlled migration rather than abandoning encrypted DNS. You are replacing one component in the path. You are not rebuilding the internet before lunch.
AdGuard DNS on Router: 7 Proven Setup Tips
7 Essential Next Steps to Replace Mullvad DNS Safely
1. Confirm Whether the Mullvad Encrypted DNS Shutdown Affects You
Start by identifying which product actually supplies DNS. If you only run Mullvad VPN with its standard configuration, the internal VPN resolver normally continues without action. If you use Mullvad Browser with untouched defaults, the move to Quad9 should happen automatically through a browser update.
You are more likely to be affected if you remember pasting a URL containing a Mullvad hostname into Secure DNS, installing a downloadable profile, editing a router field, or configuring a local DNS proxy. Check every device that may operate outside the VPN. A phone can use a profile while the laptop uses browser DoH and the router supplies something else entirely. DNS enjoys committees, especially committees whose members have never met.
2. Record Your Current Mullvad DNS Settings Before Editing
Take screenshots or write down the current endpoint, protocol, device and location of each setting. Record whether it provides standard resolution, ad blocking, family filtering or another policy. This gives you a rollback path and prevents you from replacing a filtered profile with an unfiltered service without noticing.
I also note which layer owns the setting: browser, operating system, VPN app or router. If a test changes after migration, that small inventory tells me where to look. Without it, troubleshooting becomes a guided tour of every network menu ever invented.
This short inventory also keeps the Mullvad encrypted DNS shutdown separate from unrelated VPN or firewall changes. When only one dependency moves, the evidence remains readable.
3. Let Default Mullvad Browser DNS Migrate, Then Verify It
If you retained the default Mullvad Browser DNS setting or its included ad-blocking choice, update the browser normally and allow the planned migration. Do not manually add another resolver first, because that turns an automatic migration into a custom configuration and makes the result harder to interpret.
For these default users, the Mullvad encrypted DNS shutdown should therefore feel like a provider change rather than a manual rebuild. Verification is still useful because extensions, enterprise policies or an older custom value can alter the expected path.
After updating, open the browser’s privacy or network settings and confirm that Secure DNS is active with the expected provider. Then restart the browser and test several normal domains. I would also compare behavior outside and inside the VPN so I know which layer supplies DNS in each state.
4. Replace Custom DNS over HTTPS Endpoints Manually
Custom settings are not migrated. If your browser or client contains a Mullvad DoH URL, replace it with the documented URL for your chosen provider. For standard Quad9 threat-blocking DoH, the endpoint is:
https://dns.quad9.net/dns-query
Use that only in a field that requests a DoH template or URL. If a field asks for an IP address, entering an HTTPS URL will fail. Likewise, entering 9.9.9.9 into a DoH URL field does not magically add HTTPS. Configuration labels matter here more than enthusiasm.
If you used a special Mullvad filtering variant, confirm that your replacement provides the behavior you still want. A working resolver that silently drops your previous filtering policy is technically functional but operationally different.

5. Replace Mullvad DNS Profiles on iOS and macOS
Existing Mullvad DoH profiles on iOS and macOS will stop working and are not automatically transformed into Quad9 profiles. Before the deadline, identify the installed profile, obtain the replacement from the resolver’s official setup guidance, install it, and confirm that the new profile is enabled.
Once the replacement works, remove the obsolete Mullvad profile so there is no ambiguity about which policy is active. If the device is managed by an employer or school, do not install a personal profile over organizational controls. Ask the administrator instead; surprise DNS policies are rarely appreciated as a team-building exercise.
6. Update Routers and Other Public Encrypted DNS Servers
A router may accept plain DNS addresses, encrypted upstream URLs, or both. Check the manual before changing anything. Quad9’s standard threat-blocking IPv4 addresses are 9.9.9.9 and 149.112.112.112. Using those in an ordinary DNS field selects Quad9, but it does not guarantee encrypted transport from the router. The router must explicitly support DoH or DoT for that link to be encrypted.
Also inspect local services such as AdGuard Home, Pi-hole, dnscrypt-proxy, Unbound forwarding rules and containerized DNS gateways. The Mullvad encrypted DNS shutdown affects any manual upstream that points to the retiring service, even if the setting lives inside a machine you last opened months ago.
Change one upstream, restart the relevant service, flush caches and test before editing the next layer. If you change the router, browser and operating system simultaneously, success tells you very little and failure gives you three suspects wearing the same coat.
7. Verify the New Encrypted DNS Server and Its Fallback
First confirm basic resolution with several unrelated domains. On the latest Windows version, I inspect the active adapter and resolver addresses with:
ipconfig /all
ipconfig /flushdns
nslookup example.com
powershell -Command "Get-DnsClientServerAddress"
On a Linux system using systemd-resolved, resolvectl status shows the configured DNS state. These commands do not always prove which encrypted browser resolver handled a specific lookup, so I also inspect the browser setting and use the chosen provider’s status or test page.
Finally, disconnect and reconnect Wi-Fi, restart the browser, reboot the device and briefly test without the VPN. The interesting failure often appears after state changes rather than during the perfect first connection. Decide in advance whether you want fail-closed behavior or an ordinary fallback resolver. Availability and strict privacy can pull in different directions, and your configuration should make that tradeoff deliberately.
HackersGhost Note: I do not call a DNS migration successful because one page loaded. I call it successful when the correct resolver survives a browser restart, network reconnect and VPN state change without quietly borrowing my ISP’s DNS.

Quad9 DNS or AdGuard DNS: Which Mullvad DNS Alternative Fits?
Quad9 is the direct successor named by Mullvad. It is a Swiss-based nonprofit resolver that requires no account for its public service, supports encrypted DNS protocols, and blocks domains associated with threats such as malware and phishing on its standard secure service. Quad9 states that it does not log end-user IP addresses.
That makes Quad9 DNS servers a strong default when you want a straightforward, privacy-oriented public resolver with security filtering. It also explains why the automatic Mullvad Browser migration points there. If your priority is replacing the retiring service with minimal account management, following Mullvad’s chosen path is reasonable.
AdGuard DNS fits a different preference. Its private service adds a dashboard, per-device statistics, customizable allowlists and blocklists, and filtering controls for ads, trackers and malicious domains. I find that visibility useful when I want to understand why a device contacted a domain or when I manage different policies for a laptop, phone and router.
AdGuard DNS is therefore not the replacement Mullvad selected on your behalf. It is an alternative for readers who want more control than a simple public resolver supplies. That distinction matters because recommending every privacy product as the universal winner is how useful advice slowly turns into a catalogue wearing a trench coat.
When comparing the best encrypted DNS servers, look at transport support, privacy policy, threat filtering, customization, account requirements and how easily the service fits your devices. A resolver can be excellent and still be the wrong operational fit for your network.
Exclusive HackersGhost discount code HACKERSGHOST20 applies automatically — AdGuard may occasionally run separate public promotions with similar pricing.
How I Test DNS over HTTPS in My Own Network Lab
I would test this migration on my second-hand HP EliteBook, which I upgraded from 16 GB to 32 GB of RAM. That is extravagant for changing one resolver, but it lets me keep the latest Windows version running while VMware hosts Parrot OS and other lab machines without everything moving at the pace of a cautious potato.
My Cudy WR3000 normally handles a WireGuard VPN connection. For a clean encrypted DNS test, I record whether the VPN is active, whether the router supplies DNS through DHCP, and whether the browser has its own DoH setting. I never change the VPN route and resolver at the same time because I want one variable, not a small networking opera.
I can also use my TP-Link Archer C6 as an isolated lab router connected directly to the laptop rather than to my modem. That lets me test a manual Mullvad DNS alternative without affecting normal household devices. Parrot OS gives me a second viewpoint for checking routes, resolver state and destination connections.
Wireshark can confirm ordinary DNS on port 53 or DoT on port 853. DoH normally blends into HTTPS traffic on port 443, so a packet capture does not reveal the encrypted domain query itself. I can still correlate connections to the expected resolver, but I combine that evidence with client settings and provider diagnostics rather than pretending encryption has become transparent because I opened Wireshark.
My sequence is simple: capture a baseline, change one endpoint, flush caches, reconnect, verify, restart and test again. I also restore the old value in the isolated lab to confirm that my rollback notes are correct. The point is not to create the most complicated encrypted DNS server setup. It is to make the final configuration explainable.
NordVPN Review: My Hands-On Security Testing
Common Mullvad DNS Settings Mistakes to Avoid
- Assuming every Mullvad user must migrate: standard Mullvad VPN DNS is separate from the retiring public service.
- Waiting for a custom browser setting to change itself: customized DoH values are intentionally left alone.
- Putting an IP address in a DoH URL field: select the endpoint format the client requests.
- Mixing unrelated primary and secondary resolvers: clients may use either, producing inconsistent filtering and privacy policies.
- Forgetting IPv6: a device can use an IPv6 resolver even after you carefully changed only IPv4.
- Changing every layer at once: browser, operating-system, VPN and router settings can override one another.
- Calling encrypted DNS anonymous: DoH protects transport to the resolver; it does not hide every piece of network metadata.
The most useful response to the Mullvad encrypted DNS shutdown is not to chase every toggle. Identify the active layer, preserve a rollback value, choose one replacement and test the path after reconnects. That approach is slower than random clicking for roughly three minutes and faster for every minute after that.
My Verdict on the Mullvad Encrypted DNS Shutdown
The Mullvad encrypted DNS shutdown is manageable, but manual users should not ignore it. Standard Mullvad VPN users normally remain protected by the VPN’s internal DNS, and default Mullvad Browser users should move automatically. Custom DoH configurations and Apple profiles require direct attention before November 2.
For the simplest transition, Quad9 is the logical first choice because Mullvad selected and supports it. For more granular filtering, device statistics and custom rules, AdGuard DNS is worth considering as a managed alternative. Neither choice removes the need to verify the configured protocol and fallback behavior.
My final advice is pleasantly unexciting: document, replace, reconnect and test. Privacy infrastructure works best when it becomes boring for the right reasons.
Exclusive HackersGhost discount code HACKERSGHOST20 applies automatically — AdGuard may occasionally run separate public promotions with similar pricing.

Frequently Asked Questions
What is the Mullvad encrypted DNS shutdown
The Mullvad encrypted DNS shutdown is the retirement of Mullvad’s free public DNS-over-HTTPS servers. It does not mean Mullvad VPN is closing or that encrypted DNS technology is ending. Manual users must replace the retiring public endpoint.
Are Mullvad VPN users affected by the Mullvad encrypted DNS shutdown
Most standard Mullvad VPN users are not affected because the VPN uses internal DNS inside its encrypted tunnel. You may still need to act if you separately configured Mullvad’s public DoH service in a browser, device profile, router or another client.
Will Mullvad Browser DNS switch automatically
Default Mullvad Browser DoH settings and the included ad-blocking choice should migrate automatically to Quad9. Customized DoH settings will not be overwritten. If you previously selected a manual Mullvad variant, review it yourself.
When should I replace Mullvad DNS
Replace manual Mullvad public DoH settings and mobile or desktop profiles before November 2. Migrating earlier gives you time to test the replacement and restore your previous configuration if something was entered incorrectly.
Is Quad9 DNS encrypted
Quad9 supports encrypted protocols including DNS over HTTPS and DNS over TLS. Simply entering 9.9.9.9 into a traditional DNS field selects Quad9 but does not automatically encrypt that connection. Your client or router must support and enable an encrypted protocol.
What is the best Mullvad DNS alternative
Quad9 is the direct replacement supported by Mullvad and suits users wanting a free, privacy-oriented public resolver with malicious-domain blocking. AdGuard DNS can suit users who want configurable filtering, per-device controls and a management dashboard.
Will existing iOS and macOS profiles update automatically
No. Existing Mullvad DoH profiles on iOS and macOS will stop working and must be replaced. Install a profile from your chosen provider’s official guidance, verify it, and remove the obsolete Mullvad profile afterward.
How do I verify my new encrypted DNS server
Confirm the configured resolver, flush caches, test normal domain resolution, inspect browser Secure DNS separately, and use the provider’s diagnostic page. Repeat after a browser restart, network reconnect and VPN state change to expose unwanted fallback behavior.
VPN & Network Infrastructure Cluster
- Mullvad Encrypted DNS Shutdown: 7 Key Changes Explained 》
- NordVPN DNS Leak: 7 Essential AdGuard DNS Checks 》
- Proton VPN Custom DNS: 7 Real AdGuard Setup Lessons 》
- AmneziaWG vs WireGuard: 7 Key Obfuscation Changes 》
- Are Free VPNs Safe? 7 Essential Mobile Privacy Checks 》
- AdGuard Ad Blocker and VPN Together: 7 Proven Findings 》
- AdGuard DNS on Router: Complete 7-Step Setup Guide 》
- Public Wifi Security: 9 Essential Rules to Stay Safe
- AdGuard VPN Subscription: 7 Key Pros and Cons 》
- AdGuard Promo Code: Save Up to 80% on VPN, DNS and Ad Blocker 》
- AdGuard DNS: 7 Essential Features I Tested 》
- Proton VPN: 7 Privacy Features Most Users Miss
- Proton VPN Free Tier: 7 Limits You Should Know Before Using It
- What VPN Do Hackers Use? 7 Myths You Should Stop Believing
- PrivadoVPN Review: 7 Strong Reasons to Try It
- NordVPN Plans: 7 Smart Ways to Choose the Right Plan 》
- GL.iNet + ProtonVPN: Fast Privacy Setup or a False Sense of Security? 🧐
- Best Packet Sniffing Tools for Network Analysis & Ethical Hacking 📡
- Man in the Middle Attacks Explained: How Attackers Intercept Traffic 🧠
- WiFi Monitor Mode Problems: Why Your Adapter Refuses to Listen 📡
- WiFi Monitor Mode Explained: Sniffing Networks the Ethical Way
- Will a VPN Protect Me From Hackers? The Real Security Truth 🛰️
- Tor vs VPN: Which One Actually Protects Your Privacy? 🕸️
- WireGuard vs OpenVPN: Which VPN Protocol Is Better? 🛰️
- ProtonVPN WireGuard Config: 7 Proven Setup Steps
- Linux VPN Kill Switch: 7 Essential Safety Checks
- Linux Split Tunneling: 7 Essential Routing Methods
- Cudy WR3000 WireGuard Router Setup with Proton VPN
- NordVPN Review: 9 Powerful Features I Tested 》
- NordVPN Router Setup: 7 Easy Bulletproof Steps for Security 🛡️👻
- How to Test DNS & WebRTC Leaks: 7 Sneaky Checks 🕵️♂️
- VPN Myths in Ethical Hacking Labs: 7 Dangerous Mistakes 🧨
- NordVPN OpenWrt Lab Setup: How I Run It Without Leaks, Drama, or Guesswork 🧪
- How Routers Break OPSEC Without You Noticing 🧠
- Using VPN Routers For Ethical Hacking Labs 🧪
- NordVPN vs ProtonVPN Router Speeds in Real Setups: Limits, Protocols, Stability, and the OPSEC Traps 😈
- NordVPN on GL.iNet Routers: Real-World Performance, Leaks, and OPSEC Failure Points 😈
- NordVPN on Cudy Routers: Real-World Performance, Stability, and OPSEC Failure Points 😈
- Cudy Router WireGuard Performance: Real-World Speed, Stability, and Tradeoffs 😈
- Saily eSIM Review: Secure Mobile Data Without the SIM Card Circus 🛰️
- Saily Ultra Review: A Premium eSIM Subscription Explained 🧬
- Best VPN Routers for Ethical Hacking Labs: Complete GuideVPNs Explained: Real-World Privacy, OPSEC, and Common Mistakes 🧭
Some links in this article are affiliate links. If you use them, I may earn a small commission — at no extra cost to you. I only recommend tools I’ve actually tested inside my own cybersecurity lab. Read the full disclaimer.
In many cases, these links unlock better deals than you’ll find on your own.
No paid reviews. No sponsored opinions. Just real testing and real setups.
If you decide to use them, you’re not just getting a discount — you’re helping keep this lab running.
