Shutting down our public encrypted DNS

381 points · 177 comments on HN · read original →

Points and comments are a snapshot, not live.

Mullvad is shutting down its public encrypted DNS servers and sponsoring Quad9 instead.

Mullvad has operated public encrypted DNS (DoH) servers since 2022. They are unnecessary when using Mullvad VPN, which handles DNS internally. Outside the VPN, they serve Mullvad Browser users and the general public. Mullvad will now financially support Quad9, calling them the undisputed leader in privacy-focused DNS. Users should switch to Quad9 before November 2nd 2026. Mullvad Browser users with default DoH settings will be automatically migrated. Custom configurations and iOS/macOS profiles must be updated manually.

What commenters are saying

Most commenters praised Mullvad's decision, calling it brilliant. However, several pointed out drawbacks. Quad9 censors some domains in Europe following court injunctions, unlike Mullvad's DNS. Quad9 also lacks adblocking, which Mullvad offered. Some suggested running local adblocking with AdGuard Home or Pi-hole. A debate emerged over DNSSEC: one commenter worried Quad9 could poison DNS, while others explained that DNSSEC validation on the forwarder would prevent that. A technical discussion noted that Quad9's advice against enabling DNSSEC on forwarders is standard, as it avoids duplication and false BOGUS responses. Overall, support for the move was high, but concerns about censorship and lost features remained.