How to Set Up Encrypted DNS: Android, iPhone, Windows, Mac and Browsers
Step-by-step encrypted DNS setup for Android Private DNS, iPhone profiles, Windows 11, macOS and Chrome or Firefox, with a resolver comparison and how to check it works.
Every app and website on your device starts with a DNS lookup: the phone asks a resolver for the address of shopee.com.my or api.whatsapp.net before it connects. By default those questions go unencrypted to whichever resolver the Wi-Fi network or mobile carrier hands you, so the network sees a running list of what you use. Encrypted DNS moves those lookups into an encrypted connection to a resolver you pick.
This guide is the setup half. How DNS over HTTPS and DNS over TLS differ, and why enterprises treat them differently, is covered in DNS over HTTPS vs DNS over TLS.
Choose a resolver first
The resolver sees every domain you look up, so pick it on who runs it and what it keeps before anything else.
| Resolver | Run by | Blocks | Hostname for Android | DNS over HTTPS address | IPv4 for Windows |
|---|---|---|---|---|---|
| AdGuard DNS | AdGuard Software Ltd, Cyprus | ads, trackers | dns.adguard-dns.com | https://dns.adguard-dns.com/dns-query | 94.140.14.14, 94.140.15.15 |
| Quad9 | Quad9 Foundation, Switzerland (non-profit) | malicious domains | dns.quad9.net | https://dns.quad9.net/dns-query | 9.9.9.9, 149.112.112.112 |
| Cloudflare | Cloudflare, United States | nothing | 1dot1dot1dot1.cloudflare-dns.com | https://cloudflare-dns.com/dns-query | 1.1.1.1, 1.0.0.1 |
| Cloudflare for Families | Cloudflare, United States | malware (security.), plus adult content (family.) | security.cloudflare-dns.com | https://security.cloudflare-dns.com/dns-query | 1.1.1.2, 1.0.0.2 |
| Google Public DNS | Google, United States | nothing | dns.google | https://dns.google/dns-query | 8.8.8.8, 8.8.4.4 |
| NextDNS | NextDNS Inc, United States | whatever you configure | <your-id>.dns.nextdns.io | https://dns.nextdns.io/<your-id> | shown in your account |
| Mullvad DNS | Mullvad VPN AB, Sweden | ads, trackers, malware | closes 2 November 2026 | closes 2 November 2026 | closes 2 November 2026 |
Three practical defaults:
- You want fewer ads and trackers everywhere, with no account: AdGuard DNS. Its privacy policy says it processes no personal data from users of the public resolver and keeps only aggregate server statistics.
- You want malware blocking and nothing else touched: Quad9.
- You want your own rules and per-device logs: NextDNS. The free tier covers 300,000 queries a month; past that it keeps resolving and stops filtering until the next month.
AdGuard was founded in Moscow in 2009 and is now based in Limassol, Cyprus. Mullvad ran a popular free filtering resolver until it announced in September 2026 that it would discontinue it on 2 November 2026 and fund Quad9 instead. If a phone or profile still points at a *.dns.mullvad.net hostname, change it before that date: Android treats an unreachable Private DNS hostname as no connection at all.
Android: Private DNS
Android 9 and later have a system-wide setting that covers Wi-Fi and mobile data.
- Open Settings and search for Private DNS. Stock Android keeps it under Network & internet; Samsung puts it under Connections, More connection settings; OPPO and realme under Connection & sharing; Xiaomi under Connection & sharing or More connectivity options.
- Choose Private DNS provider hostname. Some skins call it "Specify" or "Designated private DNS".
- Type the hostname from the table, with no
https://and no path, for exampledns.adguard-dns.com, and save.
Automatic mode filters nothing. In Automatic mode Android tries DNS over TLS with whatever resolver the network assigned and quietly uses plain DNS when that fails. Nothing is filtered and, on most home and mobile networks, nothing is encrypted either.
The protocol under the hood is DNS over TLS on port 853. Recent Android versions switch to DNS over HTTPS (HTTP/3) for a few large providers that support it, Google and Cloudflare at launch. Every other hostname, AdGuard and Quad9 included, stays on DNS over TLS.
When a network blocks port 853 (some corporate, school and hotel networks do), Android fails closed: pages stop loading until you switch back to Automatic. Failing closed is the safer behaviour, and it is the source of most "my Wi-Fi broke" reports.
Stopping shopping apps from opening on their own
A filtering resolver is also a reliable fix for apps that jump open while you are reading or playing something else. Those launches usually come from ads served inside other apps, through ad SDKs that call the shopping app's link directly. Blocking the ad networks' domains stops the ad from loading at all. Pair it with the per-app link setting: Settings, Apps, the shopping app, Open by default, then choose to open links in the browser. On some phones that screen shows "Default options partially set" with an app-or-browser choice instead of an "Open supported links" switch; picking the browser changes it to "No defaults set". The malvertising guide explains how those ads work.
iPhone and iPad
iOS supports encrypted DNS through configuration profiles and DNS apps rather than a single switch.
- Provider profile. AdGuard and Quad9 publish configuration profiles. Open the provider's setup page in Safari, allow the download, then go to Settings, General, VPN & Device Management, select the downloaded profile and tap Install.
- Provider app. AdGuard's app installs a DNS configuration for you. Cloudflare's 1.1.1.1 app installs a VPN configuration instead, so it appears under VPN rather than in the DNS list.
- Turn it on. After installing, Settings, General, VPN & Device Management, DNS lists the configurations. Select the one you want active.
The manual DNS field under Settings, Wi-Fi, the network's (i) button, Configure DNS, is plain DNS on port 53 and applies only to that one Wi-Fi network. It is neither encrypted nor active on mobile data.
Windows 11
Windows 11 has a built-in DNS over HTTPS client.
- Settings, Network & internet, then Wi-Fi or Ethernet, then the connection's Hardware properties.
- Next to DNS server assignment, click Edit and switch to Manual.
- Turn on IPv4, enter the resolver's two IPv4 addresses from the table, and set DNS over HTTPS to On. Windows fills the template automatically for providers it knows (Cloudflare, Google and Quad9 among them). For others, choose the manual template option and paste the DNS over HTTPS address from the table.
- Repeat for IPv6 if your network uses it, or the IPv6 lookups keep going to the old resolver.
The setting is per network adapter, so set it on each one you use.
macOS
macOS uses the same profile format as iOS. Download the provider's .mobileconfig profile, open System Settings, Privacy & Security, Profiles (on some versions it is under General, Device Management), and install it. The network settings DNS field, like iOS, is unencrypted.
Browser only: Chrome and Firefox
When you cannot change the device, the browser can encrypt its own lookups. This covers only that browser: other apps still use the system resolver.
- Chrome: Settings, Privacy and security, Security, Use secure DNS, then choose a provider or enter the DNS over HTTPS address.
- Edge: Settings, Privacy, search, and services, Security, Use secure DNS, then choose a provider or enter the address.
- Firefox: Settings, Privacy & Security, DNS over HTTPS, choose Increased or Max Protection, then pick a provider or enter a custom address. Max Protection warns you before it ever uses plain DNS.
On managed work machines these settings are often locked by policy. That is deliberate: the organisation's DNS filtering is part of its security monitoring.
Check that it works
Run the VPN and DNS leak test after setting up. It makes your device look up names that only our server can answer, then reports which resolvers actually asked. If you chose AdGuard, the test labels the resolvers as AdGuard DNS. Some providers, Quad9 among them, answer from partner hosting networks the test cannot name, so check the network column against your provider rather than expecting a label every time. If you see your ISP or the hotel's network, the setting did not take effect.
Two other quick signs:
- With a filtering resolver, open a free game or app that normally shows banner ads. Most banners should be empty.
- With Cloudflare,
one.one.one.one/helpshows whether your lookups reach Cloudflare over an encrypted protocol.
What encrypted DNS does not hide
- The addresses you connect to. After the lookup, your device opens a connection to an IP address the network can see. Many sites share addresses behind a CDN, which blurs this, and many do not.
- The site name in the TLS handshake. Most HTTPS connections still send the hostname in clear text (Server Name Indication). Encrypted Client Hello hides it, and support across sites and browsers is still partial.
- Your activity from the resolver. You have moved trust from the network to the resolver operator. That is the reason to choose the operator carefully.
What a DNS blocklist can and cannot block
A filtering resolver answers "no such domain" for domains on its list. That works well for ads and trackers served from their own domains, which is most of the programmatic ad stack: in our own phone-emulated tests in October 2026, a single Malaysian news article loaded 150 to 220 third-party domains, and the bulk of them are ad exchanges, bidders and trackers that a blocklist names.
It does not work when the ad comes from the same domain as the content. YouTube serves ads and video from the same infrastructure, and a site that proxies its ad scripts through its own domain looks like content. It also cannot hide page layout: an empty ad box stays an empty box. A browser content blocker such as uBlock Origin handles those cases, and the two layers work well together. The browser hardening guide covers the browser side.
Troubleshooting
| Symptom | Likely cause | Fix |
|---|---|---|
| Hotel or café Wi-Fi login page does not appear | The network intercepts DNS, and on some networks and phone builds the login check fails with Private DNS set | Switch to Automatic, log in, switch back |
| Nothing loads on one network only | That network blocks port 853 | Use Automatic on that network, or a provider app that uses DNS over HTTPS |
| Nothing loads anywhere from 2 November 2026 | Private DNS still points at a discontinued Mullvad hostname | Change the hostname to another provider |
| One app fails to open a link or log in | The app relies on a tracking domain the blocklist covers | Test with Automatic; if confirmed, switch that phone to a less strict list such as Quad9 |
| Leak test shows your VPN's resolver | The VPN overrides system DNS while connected | Expected. Set the filtering resolver inside the VPN app if it offers custom DNS |
| Leak test shows your ISP on Windows | IPv6 still uses the old resolver, or the setting is on a different adapter | Set DNS over HTTPS on IPv6 and on every adapter |
Related guides
Sources & further reading
- Shutting down our public encrypted DNS servers and sponsoring Quad9 instead (Mullvad VPN)
- AdGuard DNS privacy policy (AdGuard)
- AdGuard DNS public servers (AdGuard)
- Quad9 setup guides (Quad9)
- Cloudflare 1.1.1.1: set up on Android (Cloudflare)
- Secure transports for DNS (Google Public DNS)
- Android 13 finally adds native support for DNS over HTTPS (XDA Developers)
- Secure DNS Client over HTTPS (DoH) on Windows (Microsoft Learn)
- Firefox DNS over HTTPS (Mozilla Support)