Last Call

AI on duty

Get the digest

SaaS

Mullvad

Mullvad is shutting down its public encrypted DNS (DoH) servers at dns.mullvad.net and recommending Quad9 instead; anyone who manually configured a Mullvad DoH resolver must switch before 2 November 2026 or lose DNS resolution

Boarding
45days00hrs00min

departs 2 Nov 2026

Official source Shutting down our public encrypted DNS servers and sponsoring Quad9 instead — Mullvad blog (official announcement) ↗ (mullvad.net)

Quick answers

Is it true that Mullvad shuts down its public encrypted DNS (DoH) servers — migrate to Quad9 before 2 November 2026?
Yes. Mullvad has officially announced it, effective 2 Nov 2026. Mullvad has run free public encrypted DNS (DNS-over-HTTPS) servers since 2022 — the resolvers at `dns.mullvad.net` and its variants (base, extended, family, adblock) that anyone could point a device or browser at to keep their ISP from seeing the domains they visit.
When does it take effect?
2 Nov 2026. Verified against the vendor's own announcement.
What should I use instead?
If you manually configured any Mullvad DoH resolver (`dns.mullvad.net`, `base.dns.mullvad.net`, `extended.dns.mullvad.net`, `family.dns.mullvad.net`, `adblock.dns.mullvad.net`, or similar), replace it with a Quad9 endpoint before 2 November 2026 — Mullvad points to Quad9's own setup guides.

What this means for you

Mullvad has run free public encrypted DNS (DNS-over-HTTPS) servers since 2022 — the resolvers at `dns.mullvad.net` and its variants (base, extended, family, adblock) that anyone could point a device or browser at to keep their ISP from seeing the domains they visit. Mullvad is shutting that public service down and financially supporting the Quad9 Foundation instead, on the reasoning that running a privacy-focused public resolver is a specialized job Quad9 already does well. The date to plan against: **if you have manually configured a Mullvad DoH server, switch before 2 November 2026.** This does not affect people using the Mullvad VPN app, whose DNS is handled internally by the VPN and never used these public servers. It affects three groups: anyone who hardcoded a Mullvad DoH endpoint into a device, router, browser, or systemd-resolved / DoH-client config; Mullvad Browser users who customized their DoH away from the default; and iOS/macOS users who installed a Mullvad DoH configuration profile — those profiles will stop working. Mullvad Browser users on the default DoH (or the default ad-blocking one) are migrated to Quad9 automatically and need do nothing.

Where to go

If you manually configured any Mullvad DoH resolver (`dns.mullvad.net`, `base.dns.mullvad.net`, `extended.dns.mullvad.net`, `family.dns.mullvad.net`, `adblock.dns.mullvad.net`, or similar), replace it with a Quad9 endpoint before 2 November 2026 — Mullvad points to Quad9's own setup guides. On iOS and macOS, remove the existing Mullvad DoH configuration profile and install the equivalent Quad9 profile. In Mullvad Browser, if you customized the DoH setting, change it back to the default so you are migrated to Quad9 automatically; if you kept the default (or the default ad-blocking option), no action is needed. Mullvad VPN app users are unaffected — the app's internal DNS handles queries and does not depend on the public servers.

  • Quad9 (9.9.9.9 / dns.quad9.net) — the privacy-focused public resolver Mullvad now recommends and financially supports, with its own DoH/DoT setup guides for browsers, iOS, and macOS

Mullvad has announced that it is shutting down its public encrypted DNS (DoH) servers and directing users to Quad9 instead. If you manually configured one of Mullvad’s DoH resolvers, the date to act on is 2 November 2026 — “switch before November 2nd 2026,” in the announcement’s words.

Mullvad has run these free public DoH servers since 2022. The resolvers at dns.mullvad.net — along with the base, extended, family, and adblock variants — let anyone encrypt their DNS queries so an ISP could not see which domains they were visiting, whether or not they used Mullvad’s VPN. Mullvad’s reasoning for stepping back is that running a privacy-focused public resolver is a specialized undertaking, and rather than duplicate the Quad9 Foundation’s work, it is putting those resources toward financially supporting Quad9.

Who is affected comes down to how you used it:

  • Mullvad VPN app users: not affected. When you are on the VPN, DNS is handled internally by Mullvad and never touched these public servers.
  • Anyone who hardcoded a Mullvad DoH endpoint — in a device, router, browser, or a resolver config like systemd-resolved or a DoH client — must repoint it to Quad9 before 2 November 2026, following Quad9’s guides.
  • iOS and macOS profile users: any installed Mullvad DoH configuration profile will stop working. Replace it with the equivalent Quad9 iOS or macOS profile.
  • Mullvad Browser users: if you kept the default DoH (or the default ad-blocking option), you are migrated to Quad9 automatically. If you customized the DoH to a specific Mullvad variant, set it back to the default so the automatic migration applies.

For most people this is a small config change, but it is an easy one to miss: a resolver that quietly works today simply stops resolving after the date, which surfaces as “the internet is down” rather than an obvious DNS error. If a Mullvad DoH hostname is written into a config somewhere in your setup, the lastcall CLI will flag it — the fingerprint matches the retiring dns.mullvad.net hostname, not the Quad9 replacement.

Entry changelog

  • — last reviewed.
  • — Entry created from Mullvad's official blog post (3 September 2026): the company is shutting down its public encrypted DNS (DoH) servers and sponsoring Quad9 instead, with the instruction to switch manually configured Mullvad DoH servers "before November 2nd 2026." Surfaced via Layer-2 discovery (Hacker News) and verified directly against the Mullvad primary source. detect: fingerprint `text:dns.mullvad.net` targets the going-away resolver hostname shared by every Mullvad DoH variant; it does not match the Quad9 replacement. CLI-validated against a scratch config before publishing.

Related on the calendar

Put this countdown in your README

Building on Mullvad? Drop this badge into a project’s README or docs — it shows the days left and refreshes on its own every night from this page. Last Call countdown for Mullvad is shutting down its public encrypted DNS (DoH) servers at dns.mullvad.net and recommending Quad9 instead; anyone who manually configured a Mullvad DoH resolver must switch before 2 November 2026 or lose DNS resolution

[![Last Call countdown](https://lastcall.dev/badge/mullvad-public-encrypted-dns-shutdown.svg)](https://lastcall.dev/entries/mullvad-public-encrypted-dns-shutdown)

Spot an error or a changed date? Tell us and it’s corrected the same night.