Mullvad announced on September 3, 2026 that it’s shutting down the public, encrypted DNS servers it’s operated since 2022, with a hard migration deadline of November 2, 2026. In their place, Mullvad is putting its financial weight behind Quad9, a move the company frames as consolidating around an established specialist rather than continuing to run a smaller, parallel service of its own.
What’s actually shutting down
According to Mullvad’s own announcement, this affects only the standalone public DNS-over-HTTPS servers that anyone could point their browser or operating system at directly, independent of using the Mullvad VPN app at all. It does not affect the built-in DNS that Mullvad VPN uses automatically whenever you’re actually connected to the VPN, that keeps working exactly as it did before. If you’ve never manually configured a device to use Mullvad’s public DNS outside of the VPN app, this change doesn’t touch you at all.
Why Mullvad is doing this
Mullvad’s stated reasoning, per its own post, is twofold. First, the company argues its public DNS servers were “unnecessary when using Mullvad VPN,” since traffic through the VPN is already encrypted end to end, making a separately encrypted DNS layer redundant for anyone actually using the product it’s built to complement. Second, and more broadly, Mullvad describes running a privacy-focused public DNS service as “a highly specialized undertaking” and says it would rather back the field’s established leader than keep duplicating that specialized effort in parallel.
Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.
What Quad9 is, if you haven’t used it
Quad9, run by the nonprofit Quad9 Foundation, is described in Mullvad’s own announcement as “the undisputed leader” among privacy-focused public DNS services. It blocks known-malicious domains by default, doesn’t log queries tied to your IP address, and has been operating specifically as a public DNS resolver, rather than as a side feature of a VPN product, for years. Mullvad’s announcement specifies financial sponsorship of Quad9 going forward, though it doesn’t disclose a specific dollar amount.
The November 2 deadline and who needs to act
Anyone who manually configured a device, router, or browser to use Mullvad’s public DNS servers directly needs to switch to Quad9’s equivalent settings before November 2, 2026, when Mullvad’s servers stop responding. Mullvad Browser users running default settings are handled automatically and will migrate without needing to do anything. iOS and macOS users who installed a Mullvad DNS configuration profile specifically will need to remove the old profile and install Quad9’s equivalent one manually, since profile-based DNS settings don’t update themselves the way an app’s internal settings can.
Why this is a bigger deal for some users than others
If your only relationship with Mullvad is the VPN app itself, this change is close to irrelevant day to day, since the VPN’s own DNS handling is unaffected. The people who need to actually do something are a narrower group: privacy-conscious users who specifically set up Mullvad’s DNS on a router, a non-Mullvad device, or a browser configuration independent of running the VPN, often specifically to get encrypted DNS on a device where installing a full VPN client wasn’t practical, like a smart TV or a shared home router serving multiple devices.
What this says about the DNS provider landscape
Mullvad positioning this as consolidation rather than abandonment is a reasonable way to read it: rather than several privacy-focused providers each running smaller, thinner DNS infrastructure in parallel, Mullvad’s move puts more resources behind Quad9 specifically. Whether other privacy-focused VPN providers follow a similar path, backing an established DNS specialist rather than running their own, isn’t something this announcement addresses, but it’s a notable data point for anyone tracking how the privacy tooling ecosystem consolidates around specialists over time rather than every provider building every layer itself.
A quick refresher on what public encrypted DNS actually does
Regular DNS lookups, the process that translates a website address you type into the actual server address your device connects to, are typically sent unencrypted, which means your ISP or anyone else on the network path can see which domains you’re looking up even if the rest of your traffic is encrypted. An encrypted public DNS service like Mullvad’s old offering, or Quad9, wraps that lookup in encryption too, so a device that isn’t running a full VPN, a smart TV, a router serving a whole household, an older laptop, can still stop its DNS queries from being visible in plain text. This is a narrower form of privacy protection than a full VPN, since it only covers DNS lookups rather than all of your traffic, but it’s meaningfully better than doing nothing on a device where installing a VPN client isn’t an option.
Why some privacy-conscious users specifically chose Mullvad’s DNS over Quad9 before
Part of the appeal of using Mullvad’s own DNS servers, for users who set it up independently of the VPN, was consolidating trust in a single company already known for a strong privacy track record, rather than adding a second, separate provider into the mix. With that option going away, those users are being asked to extend trust to Quad9 instead, a switch that’s low-friction technically but does mean researching a new provider’s own privacy policy and track record if you hadn’t used Quad9 before. Quad9’s nonprofit structure and its established reputation specifically in the DNS privacy space, per Mullvad’s own framing, are the reasons given for why this is a reasonable provider to consolidate around rather than simply shutting the service down with no recommended alternative at all.
How to actually migrate before the deadline
If you’re on the list of people who need to act, the process is straightforward: on a device or router with manually configured DNS, replace Mullvad’s DNS server addresses with Quad9’s published resolver addresses, available directly from Quad9’s own site. On iOS or macOS with a Mullvad DNS configuration profile installed, delete that profile through your device’s settings and install Quad9’s equivalent profile in its place. TechRadar’s coverage of the announcement confirms the same November 2 deadline and the same scope: standalone public DNS only, with the VPN app’s own DNS handling unaffected throughout.
The practical takeaway
This isn’t a security concern or a sign of trouble at Mullvad, it’s a deliberate narrowing of scope toward the company’s core VPN product, paired with financial support for a specialist doing the DNS-specific job better than a side project could. If you’ve never touched Mullvad’s public DNS settings directly, there’s nothing to do. If you have, mark November 2 and make the switch to Quad9 before then to avoid an unexpected DNS failure on whatever device you configured it on. Set a reminder for a couple of weeks before the deadline rather than the day of, since router-level DNS changes in particular sometimes need a device reboot or a cache clear to fully take effect across every device on the network.
Mullvad's public DNS shutdown only affects users who configured it manually, outside the VPN app itself, and the November 2 deadline gives plenty of time to switch to Quad9. If you use Mullvad VPN normally, nothing changes. Mullvad remains one of the strongest privacy-focused VPNs in our testing regardless of this change.
Keep reading: Mullvad VPN Review 2026 and DNS-over-HTTPS vs VPN: What’s the Difference?.