HN
Today

Shutting down our public encrypted DNS

Mullvad, a privacy-focused VPN provider, announced it is discontinuing its public encrypted DNS servers, opting instead to financially support Quad9. This strategic shift, aimed at leveraging Quad9's specialization, has ignited a fervent debate among Hacker News users regarding the implications of centralizing privacy services, the future of ad-blocking, and concerns over potential censorship and trust in a consolidating market.

113
Score
24
Comments
#3
Highest Rank
10h
on Front Page
First Seen
Sep 4, 7:00 PM
Last Seen
Sep 5, 4:00 AM
Rank Over Time
4337777788

The Lowdown

Mullvad, a prominent privacy VPN provider, has announced its decision to shut down its public encrypted DNS (DoH) servers, which it has operated since 2022. The company explained that these servers were primarily used by Mullvad Browser and as a free public service for those not using their VPN, offering an additional layer of privacy by preventing ISPs from seeing visited domains. Moving forward, Mullvad will instead provide financial support to Quad9, citing Quad9's established leadership and specialization in privacy-focused public DNS.

Key aspects of this transition include:

  • Mullvad's DoH servers were deemed largely redundant for VPN users, as Mullvad VPN's internal DNS already handles queries securely.
  • The decision aims to reallocate resources towards supporting an existing, highly specialized entity rather than duplicating efforts.
  • Users who have manually configured Mullvad's DoH servers are advised to migrate to Quad9's services before November 2, 2026.
  • Mullvad Browser users with default or ad-blocking DoH settings will be automatically migrated to Quad9.
  • Users who customized their Mullvad DoH settings in Mullvad Browser, or used iOS/macOS profiles, must manually update them to Quad9's configurations.

This move by Mullvad reflects a strategic pivot to streamline its offerings and bolster a leading player in the privacy-focused DNS space, though it has sparked considerable discussion within the privacy-conscious community about centralization and alternative solutions.

The Gossip

Ad-blocking Alternatives and DNS Diversity

Many users immediately sought alternatives to Mullvad's DNS, specifically those that offer ad-blocking, a feature Quad9 does not natively provide. Suggestions ranged from self-hosting recursive resolvers like Unbound to commercial services such as NextDNS, ControlD, and AdGuard DNS. The consensus was that ad-blocking has become an essential capability for modern DNS services.

Centralization Concerns & Censorship Consequences

A major point of contention was the perceived increase in centralization of privacy-focused DNS services and its implications for censorship and state surveillance. Commenters noted Quad9's history of complying with blocking orders (e.g., from Sony in Germany, Italy) and worried that fewer independent DNS providers make it easier for authorities to enforce content blocking. This led to discussions about the trustworthiness of centralized services against powerful agencies and the recommendation for users to run local, recursive resolvers for maximum autonomy.

Mullvad's Strategic Pivot

The community had mixed reactions to Mullvad's decision to discontinue its DNS servers and support Quad9. Some lauded it as a pragmatic choice, allowing Mullvad to focus its resources and leverage Quad9's specialized expertise. Others expressed disappointment, viewing it as part of a trend of Mullvad reducing its offerings, citing past discontinuations like their Google search proxy and port forwarding, and questioned what services might be next on the chopping block.