Mullvad is shutting down the public encrypted DNS servers it has operated since 2022 and will redirect resources toward supporting the nonprofit Quad9 service. The VPN provider says users who manually configured its DNS-over-HTTPS endpoints need to switch before November 2, 2026.

Encrypted DNS protects domain-name lookups between a device and its resolver, reducing the ability of an internet provider or local network operator to observe which domains a user requests. Mullvad offered its public DoH servers both to users of Mullvad Browser outside the company's VPN and to anyone seeking a free encrypted resolver.

For customers connected to Mullvad VPN, the public service was already unnecessary. VPN traffic is encrypted and the service's internal DNS handles lookups inside the tunnel. The change therefore primarily affects people using Mullvad's public resolver independently, including those who installed configuration profiles on Apple devices or entered a Mullvad endpoint manually in another application.

Mullvad said operating a privacy-focused public DNS platform is specialized work and that it would rather support an organization dedicated to that task than duplicate part of its effort. The company described the Quad9 Foundation as the leading provider in the area and said it would provide financial support after retiring its own public endpoints.

The migration path depends on how a user configured the service. Mullvad Browser installations that retain either the default DoH option or the included advertising-blocking setting will be moved to Quad9 automatically. Customized browser settings will not be overwritten. People who manually selected one of Mullvad's variants, including its base, extended or family filters, need to change the configuration themselves.

Existing Mullvad DoH profiles on iOS and macOS will also stop functioning when the servers close. The company directs those users to replacement profiles published by Quad9. Anyone relying on the resolver at a router, operating-system or application level should identify that dependency before the deadline to avoid failed lookups or an unexpected fallback to unencrypted DNS.

The decision narrows Mullvad's infrastructure footprint without ending encrypted-DNS availability for its audience. Quad9 remains a separate public service, and Mullvad's contribution is intended to support it rather than create a proprietary successor. The company has not suggested any change to DNS resolution used while connected to Mullvad VPN.

For users, the practical message is straightforward: default Mullvad Browser configurations should transition on their own, while manual setups require action. For the broader privacy ecosystem, the move is an example of one provider choosing to fund shared specialist infrastructure instead of maintaining a parallel service with overlapping goals.