>We want a public service to be available. Going forward, we will support Quad9 instead of running it ourselves. Running a privacy-focused public DNS service is a highly specialized undertaking, and the Quad9 Foundation is the undisputed leader in the field. Rather than duplicating their efforts to achieve only part of what they do, we're putting those resources toward financially supporting Quad9 instead.
I'm all for supporting quad9; but what if we just disable dnssec instead, it really solves nothing and continued support of it just makes it show up in compliance guides unnecessarily.
This is a very important detail. Adblock in 2026 is necessary and DNS will transparently do a lot of that work for you. It isn't just about lightning fast lookups and five-nines uptime anymore.
Mullvad had adblocking, malware blocking. And they didn’t block websites from governments blacklists in France and Italy. None of these features are available on Quad9.
That's something people should run themselves. I run Adguard Home on my router. Unlike the main Adguard product, Adguard Home is fully FOSS. It's been rock-solid for me, and improves on pi-hole in various ways - like full IPv6 support.
It's probably the software I trust the most on my network to 'just work', and with the local caching I can use slower upstream dns providers and still have sub 1ms average latency (no performance worries by excluding google and cloudflare). I don't use it for dhcp, but it is a good fit that it's available as well. Couldn't be happier.
There's also Orion browser, but I found it to be a bit more glitchy, especially around sites like YouTube (fuck the app, I'm not watching videos there): https://orionbrowser.com/
I've been using NextDNS [0] for a long time. It's worth the price because you can set up all kinds of different blocking profiles and have different ones on different devices, allows you to have overrides for local network items (or internals like on a Tailnet, Pangolin, Wireguard, etc) and a lot more. The ad blocking ends up working so well a lot not only are ads blocked on web pages but it works with some streaming audio ads as well as VoD that has ads injected. Highly recommend.
Yes, I use Firefox on Android with ublock origin, it works great. But using adblocking DNS on your phone will also block most in-app ads which is a big quality of life improvement.
I could also use a VPN to keep my phone always on my home network and thus behind my own ad blocking DNS but Mullvad's adblocking DNS was really nice and convenient.
Really? I never found it effective unless I messed with certs on my phone.
For example, DNS blocking isn't going to block YouTube ads if you're using the app since they don't need to respect your DNS, but it will if you're in browser because they can't control that.
Ads from providers like Google AdMob and AppLovin are blocked. Apps could bundle their own DNS or DoH resolver or use hardcoded static IP addresses but in my experience most do not.
Youtube ads do not get blocked by DNS adblock because Youtube ads are served from the same domains as the content and thus DNS blocking would be counterproductive. I don't think it has anything to do with respecting DNS.
I don't have the Youtube app installed to test but the Internet suggests that at least in 2023 it was very possible to block the Youtube android app (content and all) via DNS, which hints it does not bypass system DNS. [1]
Are you explaining my comment or rebuting it? I really can't tell what the intent is. Maybe the internet has trained me poorly in thinking most replys are generally rebuttals. But it really does seems like you're just explaining my comment.
Mostly a clarification of what I find DNS ad blocking works for on Android, which seems to be somewhat different from your experience (probably we use different apps).
A weak rebuttal of the reason why DNS adblock doesn't work for Youtube and the Youtube app.
> That's something people should run themselves. I run Adguard Home on my router.
I'll second this. People should really be flashing their routers. OpenWRT is simple enough that if you're on HN I think you'll easily be able to do it. And like most routers, you set it up and forget it.
But you'll also get a bunch more benefits from OpenWRT, to make it worth your while.
- I was able to buy a router for <$100 that was WiFi 7 capable (W1700K[0]) and had better hardware than most consumer routers. You can find plenty of cheaper routers that are flashable and more capable.
- Adguard Home
- Split tunneling/VLANs: Since we're talking Mullvad, you can put devices behind Mullvad on a VLAN. So activate Mullvad by changing SSIDs.
- Trivial to put IOT devices on a VLAN (can make one directional too so you can access from your main network but they can't reach back. I throttle everything IOT)
- Tailscale
- QoS (Control the speed and prioritization of different connections)
- It's a fucking computer, you can even run shell scripts
[0] You don't need something like this unless you're getting >1Gbps from your ISP. Big thing I wanted is the 2 10G ports.
I stopped recommending anything I host myself for those people. When it breaks I'm the support team, and I'd rather not be. NextDNS free tier is what I give them now, takes two minutes, and I never hear about it again.
I'd argue you don't need to run DoT/DoH yourself if it is just for your local network.
Setting up a local resolver, such as a Pi-Hole or Unbound on a firewall can serve unencrypted responses to your devices. Those resolvers in turn can use DoT/DoH with their upstream resolvers to encrypt the requests that go through untrusted networks on the Internet.
This is the best of both worlds, the simplicity of unencrypted DNS while encrypting traffic where it matters.
My internet is rock solid and super fast, extra low latencies. OpenWRT shapes my traffic to 90% of line speeds, so zero bufferbloat on my end. All my devices connect to this setup. The proxmox box is just an old dual core mini-pc with 8gb ram and 2x 1gbps NIC's and a wifi 6 module for 2.3gbps wireless (only 5Ghz, no 2.4Ghz). I want to replace this box with a new one to get 2.5gb ethernet & better power efficiency as my box is a 51W cpu, but total powerdraw is about 20w without causing wifi to drop. Aggressive power saving can make wifi unstable.
Unfortunately, Quad9 is censoring some domains in Europe (notably in France and Italy) following injunctions issued by rights holders [1]. That was not the case with Mullvad's DNS.
> The German courts entirely disregarded our use of geo-IP lookups on queries, and asserted that since tests via a VPN were able to resolve the domain, we were in breach of court orders
Seriously, what the fuck? So you're supposed to block VPNs as well? What's next, Tor exit nodes? New VPN and Tor nodes as they pop up? I really don't like where this is going.
There's some irony in Germany using censorship for the purpose of ensuring people don't get into reading materials that might convince them to become... fascists who censor people
German federal LE agencies have been doing it for years. Threatening to put you on lists of wanted and sanctioned individuals as a basically islamic suicide bomber for not taking down tiny things globally.
That kind of thing isn't unheard of for police agencies with moral and oversight issues, though. Orgs start seeking for bigger reasons. A simple copyright issue creatively expounded into an imaginary global drug bombing cyber trafficking crime ring takedown creates a massive internal win. So they do that.
What's even worse: the court fined us because they claimed this use case was in some way in contempt of their ruling. Then, when we won the overall case, that money was never returned because it wasn't specifically referenced by the final court. The response from the lower court was effectively: "Well, you will need to sue the court to get that money back." <table flip>
>wasn't specifically referenced by the final court.
Maybe your lawyer fucked up? Did you immediately appeal the fine or request a stay pending the main action?
Appeal court ruled on the substantive case. My understanding is that in Germany it has no procedural jurisdiction to order the state treasury to refund an enforcement fine. You need restitution claim that makes the thing yet another hoop.
Cost and staff time to pursue were not significantly higher than the return. We just want to help people with security and privacy and do DNS stuff - this legal fighting is absurd and misplaced and a spectacular waste of time, but here we are.
In related news, the Spanish soccer league LaLiga successfully won an injunction against Cloudflare so that during Spanish soccer matches ISPs have to prevent access for their users to the entire Cloudflare CDN network.
The reason is that the CDN network is/was being used to illegally stream games so access to the entire CDN network is closed.
disappointing, because alternatives matter too. quad9 and other well known servers are potentially blocked by some countries, so the more lesser known services there are the better.
Been using them for years. The price is reasonable too. It’s the only way I found to block ads everywhere on iOS (except the YT app, Mullvad’s Albania wireguard did that)
I did too, but I really miss Mullvad's static port forwarding system. It's a pain having to continually run a NAT-PMP client, and it doesn't work when you're connecting to ProtonVPN on your router.
I've found DoH was pretty unusable for me on Windows because the TCP connection doesn't seem to stay open between queries. No idea if it's a software or network issue, but big unpredictable delays on DNS queries broke all kinds of weird unexpected stuff.
NB. I don't use Windows and I don't use "Private DNS". I'm referring to using HTTP/1.1 pipelining^1 with a TCP client plus TLS forward proxy or HTTP/2 with an ldns-based client to fetch DNS data in bulk, outside the browser, from the command line. I got some incredible speeds from Mullvad
1. Not every service still supports 1.1, RFC recommends H2
They are not far right, AFAICT they are “right” Marxists, probably most similar to Albanian Hoxhaism.
If you aren’t familiar with splits inside Marxism-Leninism, the “left” is most often represented by Trotskyism with the “right” tendency being more like Stalinism and North Korean Juche. (Note that these left/right terms aren’t universally used or applied because every faction claims to be correct.)
Whoever openly spouts the concept of "remigration" [1] has no business being called anything else but far-right.
> In its political program for the 2026 Swedish general election the Örebro Party writes that they want to "stop the ongoing population replacement" and make Sweden a monocultural society, rather than a multicultural one. The party also writes that this "will be a Sweden where ethnic Swedes are once again the clear majority."
In particular, the "population replacement" is the most clear sign. That's as antisemitic and far-right as it gets [2].
I think it is more accurate to think of them as syncretic. (that is what Wikipedia has them listed as) Their main focus seems to be on nationalism/anti-immigration rather than socialism. Many fascist parties historically flirt with socialist policies as a way to make inroads with working class voters.
Translation: one of Mullvad’s two cofounders has donated money to Örebropartiet, a left-leaning Swedish political party that promotes strict and restrictive immigration laws.
There's no such thing as a left-leaning party that harsh on immigration. Only parties that call themselves left-leaning. You may as well speak of a capitalist party that wants to seize and redistribute the means of production.
Or that the Nazis are socialist because they have socialist in their name instead of it being a front name to hide their fascist and racist intentions.
which shows how thoroughly they've been subverted by their purported enemy.
siding with the capital on its quest to drive the wages down and the rents up will rightfully be their doom. no amount of progressive signaling can make up for that betrayal.
I'm always wondering whether those centralized privacy services are not the easiest first target for three-letter-agencies to infiltrate to gain access to the most relevant users to track - and what currently would prevent them from doing so if they haven't already ? Maybe, as with the case of many TOR nodes , they might be running them.
Adversaries don't always ask nicely. Sometimes they break in and silently take the data. These services centralize traffic flows and make it so that an adversary only needs to tap one or two circuits to get a full picture for all users of a service.
CIA is not stupid enough to break into a guarded data center in Switzerland or one of the less America friendly EU countries. They tell the NSA to look for security holes and spread narratives that only criminals use VPN hoping that a politician will notice and try to ban them, like what's happening in the UK.
Big tech services are less private than you think but almost every provider who cares about privacy is safer than you expect. Most of the people who work there are committed to their mission, and if they ever get a gag order someone will leak it in no time because they know exactly how to do it without exposing their identity.
Why would they serve a secret subpoena and gag order, when instead they can just drive to a secluded location 5km away from the super secure datacenter, dig a few meters down, passively tap a strand or two, facility and service operators none the wiser?
The data would/should be encrypted; while the NSA did successfully tap Google's inter-datacenter traffic before the Snowden leaks, since then it is encrypted, too. Hopefully other providers won't fall for that trick anymore, either.
IIRC, Google addressed the incident you're referring to by adding E2E encryption to sensitive inter-DC RPC sessions, rather than by fully encrypting inter-DC traffic at the link level. It would be nice to be able to reasonably expect carrier/ISP backbones to be secure against this threat, but in our actual reality this seems like fantastical thinking.
They’ve already done both. When they can get a cooperative party (AT&T, for example), they colocate their splitter equipment. When they can’t, they tap undersea and overland cables.
When it’s a hostile environment entirely, they hack and do secret operations and bribe.
Are you sure? Someone broke into a Hetzner data center and a Linode one, physically intercepted the Ethernet cables for jabber.ru, and got certificates signed on their behalf.
dear sockpuppet =) I think the above commenter meant illegal physical access. The jabber.ru MitM situation was likely carried out by a cybercrime unit of the German police forces with a court order... and this is the adversary most people forget about.
Lesson to learn: Let's Encrypt does not protect against MitM by a state-level actor, unless you take precautions.
*let's assume network admins won't MitM your server for personal vengeance reasons
I don't think there's any company with useful information on the American public that isn't being forced to regularly hand over that data. That's probably been true to some extent for a long time (see Room 641A) but it's certainly gotten worse. At this point you can't check out a book from the library without the feds demanding that your librarian turn over a list of everything you've ever read, or rent a hotel room for a night without the hotel being forced to provide your information to the government.
Use an online service that's new enough and small enough and it might not be compromised, but the moment it gets popular men with guns and national security letters with gag orders will show up to install hardware on their prem, take over entire offices, or just demand reports.
VPNs and secure DNS services aren't there to keep your data from the NSA, ICE, or even the police. They are useful for keeping your ISP from selling your browsing history to anyone willing to pay them. It'll help keep a little of what you do online away from data brokers and not much else.
For clarification, this is completely true of the US, without needing to speculate, thanks to a combination of FISA 702, the ECPA, CALEA, EO 12333, and the CLOUD act. It all has legal footing in the States.
However, it's not at all the reality of a vast swath of other countries (or, at least, not yet; see Chat Control v2). The US is particularly foul (and effective) when it comes to this practice, but anything outside of US jurisdiction that doesn't have an office in the US can't be touched by laws like these, and the laws of most other countries tend to be significantly less invasive than American ones when it comes to data interception and the practices surrounding it.
Quad9 is a reasonable choice given the stance on privacy and the similar jurisdiction (Mullvad would probably face the same takedown orders as Quad9), but really anyone who cares about bypassing national blocking orders should run a local caching recursive resolver. Unbound is a great choice.
Unbound can also be used to block malware and advertising domains using shared public lists, or you can build your own list. Your resolver’s DNS queries could be piped through Mullvad or Tor if you want additional privacy.
I don’t honestly see how that’s necessarily better. Now your ISP can tap your individual household to see what’s being queried. Whereas if you use Do[THU] to connect to some remote recursive resolver it practically functions as a mixer.
I don't see how that's an improvement over using a big public resolver. Probably worse privacy (you've basically just swapped your ISP for another virtual ISP), and worse performance (likely longer network paths from your resolver to various authoritative servers, as well as not getting the benefits from the nicely-warmed caches that big public resolvers will have).
A “virtual” ISP may not have my personal details, especially if I am careful about it. I agree that it’s a tradeoff. Some people may live under regimes where big DNS servers are blocked or under legal orders, or they may have concerns about imminent DNS censorship or logging orders.
- Personal details isn't the point (and while a VPN service may have those, a big DNS resolver certainly doesn't)--the point is that correlating DNS traffic with your source/home IP address is likely easier with a big DNS resolver. In any case, I don't see how the VPN approach is superior here.
- People may also live under regimes where VPN providers are blocked. Unless there's some order of magnitude more limitations on DNS resolvers, I don't see how the VPN approach is superior here.
Anonymizing VPNs, especially multi-hop ones, and Tor in particular makes correlation much more difficult. Mullvad paid in crypto or cash is a very good option.
I agree about blocked VPN providers, but in the real world it’s usually possible to get around those blocks, even in places like China where there are sophisticated national firewalls.
These things you suggest incur significant latency. Also, can you simply pipe DNS over Tor? I don't see how, since Tor is TCP-only. I suppose DoT or DoH could potentially work, but not all authoritative servers may support those protocols. The TCP handshake will also add further latency.
Furthermore, even once you layer all that tunneling on top, it's still unclear how doing recursive resolution from your end of the tunnel is better than going through one of the big resolvers. The privacy benefits seem marginal at best. Overall, I don't think you have convinced me in the slightest of your original point that "really anyone who cares about bypassing national blocking orders should run a local caching recursive resolver."
If your centralized DNS server receives a blocking order, what are you doing to do? You’ll have to do something. Give me another alternative then. In the current geopolitical environment, this is not idle speculation, it’s a real threat.
Latency is a tradeoff, I mentioned there are tradeoffs. For an individual or home network, the latency should not be a problem especially with caching.
As for TCP/UDP, current RFCs say that DNS servers must accept TCP, but not all may follow the standard and some misconfigured firewalls may block it. But it doesn’t seem to be an issue when tunneling all traffic over Tor using something like Tails. So I don’t think this is really a problem.
> Running a privacy-focused public DNS service is a highly specialized undertaking
This seems like an overstatement: I have been running my own recursive DNS with Unbound for years and never though it was a "highly specialized undertaking." It took perhaps a couple of hours to set up in the pre-AI age. I filter ads and trackers using an aggressive blacklist[0].
What does everybody here think about Daniel Berntsson, founder and co-owner of Mullvad, personally donating 5 million Swedish krona to the populist Örebro party, criticized for its stances on race & immigration?
I'm not trying to start an unhealthy discussion about this topic, genuinely curious about your opinion on the matter.
He is in his full right to support whatever party he wants?
Those parties exists for a reason, a response to certain pressures. Nothing happens in isolation. If you zoom out a bit and if you can for a second try to empathize with both sides, you will often find that both sides of an issue is correct, reasonable & rational from their own perspectives. It is often more an emotional response than one of pure survival.
The more you force things on people or suppress them, the more they will resist & push back. The rise of the far-right is not random or just pure evil manifesting out of thin air. It is like a acute inflammatory/immune system response. Obviously it can be exploited by bad actors to further inflame/divide & accelerate certain agendas. Often times extremism takes hold when certain justices are denied (which is in fact evil).
Life is best if you assume the guy on the other side (90% of a group) is just a bro trying to survive & have no real bad intent towards you, they don't know you or have been in your shoes, and the other way around too. Thus it is very important to become non-reactive, become observant who is trying to stoke the flames, who benefits from the chaos and so on.
Irrespective of political affiliations, I felt that Mullvad addressed the outrage in a mature and non culture war manner. Because of how they handled the situation, I have a lot more respect for the company.
It's great that they didn't try to cancel the guy or get seduced into driving a wedge into their team. It is great they chose their principle over pleasing the crowd in such a transparent way.
I have been a customer for many years. I once even used the cash payment option out of curiosity.
Their DoH going down for hours multiple times is what forced me back to cloudflare, i don't trust cloudflare more but at least it works consistently.
Additionally the default of blocking 'malware' doesn't jive with uncensored internet - that should be an opt in and not a default on their flagship address if they want to be taken seriously as unfiltered provider.
If the encrypted endpoint can go down for extended periods and they curate list of 'malware' they are not something that should be considered a gateway to uncensored and open internet.
I frequently get mini failures with quad9 and my DNS client is too dumb to retry with another server (or quad9 returns a valid but bogus response that prevents my client from hoping to the next server) so I had to ditch quad9.
Quad9 also has worse latency but I could live with it, I just can't live with web pages failing to load several times per day(especially hacker News that has their DNS TTL set to 1 second)
It doesn't happen with my ISP's servers nor with CloudFlare or google or even good ol' L3.
Hi - I'm with Quad9 (CTO). I'm going to try to put together a single post replying to some of these topics.
First: We welcome the Mullvad users who will be shifted onto our systems, and we appreciate that Mullvad contacted us instead of doing this unilaterally. Since we have no signup process, they could have just moved users across but we very much appreciate their cooperation and communication, both with us and with the users of the service - this is exactly how an ideal transfer should go, at least from our perspective.
I'll try to make some short summaries of some of the points here, and a reply on each.
"You should just run your own DNS server - it's easy." - Yes, we agree that for a small company or home running your own recursive resolver is a reasonable solution. You probably won't get the threat mitigation depth of service that Quad9 offers, but you may not want that. Privacy also suffers a bit, since it's still the same IP address (your home "public" address) sending queries to authoritative servers, probably unencrypted. A good middle compromise is to run PiHole or AdGuard software, and forward your queries to Quad9 via an encrypted connection. (see below) This mixes your queries in with a large number of other users, and gets the potential improvements of having a much larger active cache nearby which will have "hot" answers.
Running a home resolver for yourself or even a few dozen (or even a few hundred) people is not difficult. But with all services, things change with scale. As the query volume and number of locations grow, you soon find yourself hitting all possible exception cases, instantly. Many millions of requests a second requires a lot of time, expertise, and money to ensure nearly 100% uptime. We are admittedly quite a small group - less than 10 full time - but even that is under-staffed for supporting more than 100 million daily users. We do quite a bit with a very small resource set, and I doubt it could be done less expensively with the same robustness for the same scale. Again, we appreciate Mullvad's sponsorship to help keep this expanding at our normal weekly growth rate of around 2%.
"I want ad blocking, and Quad9 doesn't do that" - Correct, Quad9 does not do ad blocking at this time. There are good solutions like PiHole or AdGuard extensions that provide this functionality, and getting local control and logging of your DNS queries is probably useful for power users. There are also commercial platforms that provide this capability, and they may provide significantly more "knobs" for what you want to block. Quad9 is a non-profit - we're not out to corner the market, and as long as privacy and security is increased for the end user, we're all for commercial solutions!
"Quad9 blocks domains in Germany" - Currently there are no mandatory blocks that Quad9 is integrating or enforcing on our DNS platform, from any external party. We did briefly block some domains as a result of legal actions against us in Germany. The good news is that we won that case in Germany, after two years and three appeals and an enormous amount of time and money (which despite Germany's "loser pays" rule, is not even close to expenditures.) https://quad9.net/news/blog/quad9-turns-the-sony-case-around... The bad news is that the identical thing is happening now in France where we have a number of legal cases open against Quad9, and we do not see an end to this any time soon as long as there is an open question in the EU about what a content-neutral intermediary is and is not required to do.
"Mullvad exiting creates more centralization, and that is bad." On the fact that centralization is bad, we agree. DNS resolver centralization is not a great thing, and it seems to be trending in the wrong direction. It'...
You are probably the guy to ask. I have always found dns over TLS to be the fastest, but with the quic versions making an entrance, maybe things have changed. Which is the one that gives me the fastest replies?
Not OP but I don’t think DoQ is very interesting. DoH is nice because it blends in with HTTPS. Both do the protocol level things to avoid connection handshakes. The HTTP overhead isn’t that much really.
DoT is more complex than you’d imagine because it has to try hard to implement its own solutions to avoid handshakes.
We actually quite like DOQ and DOH3, both of which use QUIC.
All modern Apple systems use QUIC. For instance if given 9.9.9.9 via DHCP they will automatically upgrade to encryption via DDR, then then upgrade to DOH3 with no intervention by the end user. We find that encryption load is lower with QUIC-based transports, but we need to really get a formal research paper together on that "in our spare time."
Faster? Probably, but is it measurably "better" remains a question for others to answer. Due to parallelism in most query sets, minor wins with DNS latency matter less than you might think.
> On the fact that centralization is bad, we agree. DNS resolver centralization is not a great thing, and it seems to be trending in the wrong direction.
It seems all too similar to the degradation of peer-to-peer networks where nodes are replaced by few supernodes. You mentioned a couple reasons yourself: consolidation and legal pressure. Add to this the technical qualification aspect and time investment (Mullvad's position), and the financial cost of sustaining such a non-profit project. Suddenly there are very few people or even organizations worldwide, who can bear the burden.
Thanks for this! I was looking at your transparency report (https://quad9.net/about/transparency-report/) and I notice 2026 is not included in the 'list of years in which we have not received a request for data', despite the list being updated quarterly according to the text below it. When I saw the page earlier, I assumed that either the list isn't actually updated quarterly, or I'd discovered an exciting example of a warrant canary.
No, canaries in our opinion are not a particularly good idea for a variety of reasons. We have not received any requests/demands for information in 2026 - we'll try to update the page to reflect that this is no longer a quarterly update.
> Quad9 is based in Switzerland. Despite what may be common knowledge from movies, there is a very formal and rigorous process for governments (Swiss or non-Swiss) to demand data.
Due to Lugano Convention [0] / Budapest Convention [1] / Hague Convention etc, I don't see how Switzerland is any more insulated than, say, Norway is (both these countries are part of EFTA & signatories to various UN/EU/EFTA treaties). Per this article [2], Switzerland ranks below Ireland, Portugal, Denmark, France in Data privacy laws (in fact, it ranks the same as the UK).
If I am being honest, at this point, "based in Switzerland" (or Cyprus or Sweden or Gibraltar) comes across as marketing gimmick VPN companies are notorious for.
Our goal is not "insulation" as much as it is "transparency." Governments that do not adhere to legal frameworks like the ones you reference above are also governments that have inconsistent or easily-changed legal structures - we are not hiding in some obscure and possibly unstable nation that ignores international standards. Our jurisdictional choice of Switzerland is the opposite of that. Switzerland has a strong history of making legal enforcement events transparent, with processes that follow expected process. We cannot avoid following the law, nor is that our goal.
Swiss data privacy law is also much more strict on us, which "puts our money where out mouth is" as the saying goes. Violating privacy laws in Switzerland may result in criminal penalties, not simply civil penalties - jail time, rather than just fines.
I saw your response about not blocking ads currently.
What about blocking adult content, for a child's computer? Mullvad had such an option[1] under family.dns.mullvad.net. Very useful!
This is an area that is fraught with challenges. Serving a truly global audience means standards are difficult to measure as to what is "adult content" - it varies widely (Wikipedia in some areas is "adult content", as an example.)
In the near term, there is no filter set that we offer that mimics that functionality.
However, we recognize some variation of "best effort" adult content segmentation is a useful filter to have. We're considering it in the near term, as we have some specific educational institutional pressure to try to meet as well, since students are often easy targets for phishing, classroom computers are rife with malware, and there is also the problem of inappropriate DNS-based profiling of students and schools - problems that Quad9 can help solve.
Perhaps you could ask Mullvad how they did it? You might protect yourself with disclaimers that your results may not be perfect? You still could create a useful/ effective service even if it's not 100% perfect I would think.
Thanks for the clarification, I mistakenly assumed you were also required to block sanctioned media (mostly Russian/Iranian), but upon further research apparently that only applies to ISP DNS.
I ran a self-hosted adguard dns server for 6 months. It allows iphone profiles thus forcing DNS. I eventually disabled it due to timeout issues specific to iOS.
While reproing the issue I noted the average roundtrip time from my OVH server hosted in Oregon to the default upstream DNS - Quad9 - was around 70ms. When I changed it to Hurricane Electric the roundtrip dropped to a steady 20ms. Later I changed it again to Cloudflare and the roundtrip was a consistent 2 to 3ms.
This feels like a nitpick but it's important to mention anyway
> Mullvad Browser uses them [ the DoH servers ] by default when you're not on Mullvad VPN, preventing your ISP from seeing the domains you visit.
This is a half-truth until Encrypted Client Hello (ECH) is in-use for most of your traffic. Sure, you won't have clear-text DNS floating out there in the series of tubes. However, without ECH the hostname you're connecting to is exposed in the SNI field during TLS handshakes.
I imagine most sites we are browsing will eventually be able to leverage ECH, so this should become less of an issue over time, but in the event you frequent any self-hosted operations (e.g. no Cloudflare or similar), encrypted client hello could still reveal identifying information since it requires still exposing an "outer SNI" that a valid certificate needs to be presented for. You only get to easily hide in with the masses when you use a big infrastructure provider as a consequence, since the common outer SNI of cloudflare-ech.com doesn't really reveal anything different than an IP <-> ASN database would. But if the outer SNI is "dunder-cat-enterprises.com", then all I've protected you from is your ISP snooping on the subdomain or pinpointing exactly which one of my domains you might be talking to.
Even ECH isn't that helpful. ISP still sees the IP addresses you connect to. Even when non-dedicated IPs are used, I'd be surprised if a quite basic traffic analysis (say, bytes transferred on first visit) wouldn't identify the domain.
VPN providers at the tier of Mullvad should be precise about this stuff -- I think it's more than just a nitpick, considering the audience. oh god did I just use an emdash.
Note that you need some flavor of secure DNS to enforce ECH. The protocol is designed to be downgradable.
164 comments
[ 0.26 ms ] story [ 38.1 ms ] threadBrilliant.
Maybe it’s time to try nym.com?
If you're on an iPhone, uBlock is now supported: https://apps.apple.com/us/app/ublock-origin-lite/id674534269...
There's also Orion browser, but I found it to be a bit more glitchy, especially around sites like YouTube (fuck the app, I'm not watching videos there): https://orionbrowser.com/
[0] https://nextdns.io
Look, I still run AdGuard on my router, but it's not the same thing
I could also use a VPN to keep my phone always on my home network and thus behind my own ad blocking DNS but Mullvad's adblocking DNS was really nice and convenient.
For example, DNS blocking isn't going to block YouTube ads if you're using the app since they don't need to respect your DNS, but it will if you're in browser because they can't control that.
For apps I always use revanced.
Youtube ads do not get blocked by DNS adblock because Youtube ads are served from the same domains as the content and thus DNS blocking would be counterproductive. I don't think it has anything to do with respecting DNS.
I don't have the Youtube app installed to test but the Internet suggests that at least in 2023 it was very possible to block the Youtube android app (content and all) via DNS, which hints it does not bypass system DNS. [1]
[1] https://superuser.com/questions/713289/blocking-youtube-andr...
A weak rebuttal of the reason why DNS adblock doesn't work for Youtube and the Youtube app.
I'm on your side but telling people to buy a new phone doesn't solve their problem. Short of that uBlock and/or Orion are their best options
But you'll also get a bunch more benefits from OpenWRT, to make it worth your while.
[0] You don't need something like this unless you're getting >1Gbps from your ISP. Big thing I wanted is the 2 10G ports.Setting up a local resolver, such as a Pi-Hole or Unbound on a firewall can serve unencrypted responses to your devices. Those resolvers in turn can use DoT/DoH with their upstream resolvers to encrypt the requests that go through untrusted networks on the Internet.
This is the best of both worlds, the simplicity of unencrypted DNS while encrypting traffic where it matters.
Fiber ONT -> Proxmox x86 -> OpenWRT -> Adguard Home -> unbound -> Quad9.
Browser: Firefox + ublock origin & privacy badger & strict privacy setting & Https-only.
My internet is rock solid and super fast, extra low latencies. OpenWRT shapes my traffic to 90% of line speeds, so zero bufferbloat on my end. All my devices connect to this setup. The proxmox box is just an old dual core mini-pc with 8gb ram and 2x 1gbps NIC's and a wifi 6 module for 2.3gbps wireless (only 5Ghz, no 2.4Ghz). I want to replace this box with a new one to get 2.5gb ethernet & better power efficiency as my box is a 51W cpu, but total powerdraw is about 20w without causing wifi to drop. Aggressive power saving can make wifi unstable.
[1] https://quad9.net/news/blog/italian-blocking-demands-followi...
Seriously, what the fuck? So you're supposed to block VPNs as well? What's next, Tor exit nodes? New VPN and Tor nodes as they pop up? I really don't like where this is going.
That kind of thing isn't unheard of for police agencies with moral and oversight issues, though. Orgs start seeking for bigger reasons. A simple copyright issue creatively expounded into an imaginary global drug bombing cyber trafficking crime ring takedown creates a massive internal win. So they do that.
Edit: I'm with Quad9 (CTO)
And thanks for the great DNS service, I'm using it everywhere!
Maybe your lawyer fucked up? Did you immediately appeal the fine or request a stay pending the main action?
Appeal court ruled on the substantive case. My understanding is that in Germany it has no procedural jurisdiction to order the state treasury to refund an enforcement fine. You need restitution claim that makes the thing yet another hoop.
Anybody can change their DNS and for an ISP to perform a man in the middle on all dns they would need to inspect every packet. Impossible
The reason is that the CDN network is/was being used to illegally stream games so access to the entire CDN network is closed.
https://apnews.com/article/laliga-cloudflare-piracy-spanish-...
https://hayahora.futbol/#sobre-los-bloqueos (click "IN" to view in English)
I hope at least they'll keep these options in their tunnel configuration but if not there's not much sense in keeping their service....
This is probably service you can host locally with the lowest maintenance and hardware requirements so it isn't even a hassle to do it yourself.
Trivial to self-host, and gives you full control of blocking.
Sometimes you need to unblock things to ensure something works properly, so having it be local is better in my opinion.
https://en.wikipedia.org/wiki/Public_recursive_name_server
IME, it was much faster than Quad9 for this purpose
First Mullvad shuts down its Google search proxy
Now its DoH service
What's next
For sailing the high seas, or for harboring? I, for one, am glad to not have Mullvad's IP ranges blacklisted everywhere.
Discontinued
1. Not every service still supports 1.1, RFC recommends H2
(Next time, might be worth to add a source yourself to prevent downvotes)
[1] https://www.reddit.com/r/ProtonMail/comments/1uivm45/mullvad...
If you aren’t familiar with splits inside Marxism-Leninism, the “left” is most often represented by Trotskyism with the “right” tendency being more like Stalinism and North Korean Juche. (Note that these left/right terms aren’t universally used or applied because every faction claims to be correct.)
> In its political program for the 2026 Swedish general election the Örebro Party writes that they want to "stop the ongoing population replacement" and make Sweden a monocultural society, rather than a multicultural one. The party also writes that this "will be a Sweden where ethnic Swedes are once again the clear majority."
In particular, the "population replacement" is the most clear sign. That's as antisemitic and far-right as it gets [2].
[1] https://en.wikipedia.org/wiki/%C3%96rebro_Party#Immigration_...
[2] https://en.wikipedia.org/wiki/Great_Replacement_conspiracy_t...
[0]: https://www.flamman.se/techprofil-ger-miljoner-till-orebropa...
siding with the capital on its quest to drive the wages down and the rents up will rightfully be their doom. no amount of progressive signaling can make up for that betrayal.
This was probably the most ignorant thing I've read today. You're knowledge of political history must not extend very far.
If that is what they say before they get power, you need only the basic lessons of history to understand what they might do after they get power.
Big tech services are less private than you think but almost every provider who cares about privacy is safer than you expect. Most of the people who work there are committed to their mission, and if they ever get a gag order someone will leak it in no time because they know exactly how to do it without exposing their identity.
And they don't provide the key to law enforcement because ... they care about your privacy. /s
When it’s a hostile environment entirely, they hack and do secret operations and bribe.
https://notes.valdikss.org.ru/jabber.ru-mitm/
https://news.ycombinator.com/item?id=37961166
Lesson to learn: Let's Encrypt does not protect against MitM by a state-level actor, unless you take precautions. *let's assume network admins won't MitM your server for personal vengeance reasons
But S in https stands for secure, or ? /s
They don't need to break in guarded data centers. See Crypto AG
> or one of the less America friendly EU countries.
Besides Spain, there is no such country in EU. And even Spain might change its mind.
Use an online service that's new enough and small enough and it might not be compromised, but the moment it gets popular men with guns and national security letters with gag orders will show up to install hardware on their prem, take over entire offices, or just demand reports.
VPNs and secure DNS services aren't there to keep your data from the NSA, ICE, or even the police. They are useful for keeping your ISP from selling your browsing history to anyone willing to pay them. It'll help keep a little of what you do online away from data brokers and not much else.
However, it's not at all the reality of a vast swath of other countries (or, at least, not yet; see Chat Control v2). The US is particularly foul (and effective) when it comes to this practice, but anything outside of US jurisdiction that doesn't have an office in the US can't be touched by laws like these, and the laws of most other countries tend to be significantly less invasive than American ones when it comes to data interception and the practices surrounding it.
Citation needed. At least in DE it is also true.
Unbound can also be used to block malware and advertising domains using shared public lists, or you can build your own list. Your resolver’s DNS queries could be piped through Mullvad or Tor if you want additional privacy.
- People may also live under regimes where VPN providers are blocked. Unless there's some order of magnitude more limitations on DNS resolvers, I don't see how the VPN approach is superior here.
I agree about blocked VPN providers, but in the real world it’s usually possible to get around those blocks, even in places like China where there are sophisticated national firewalls.
Furthermore, even once you layer all that tunneling on top, it's still unclear how doing recursive resolution from your end of the tunnel is better than going through one of the big resolvers. The privacy benefits seem marginal at best. Overall, I don't think you have convinced me in the slightest of your original point that "really anyone who cares about bypassing national blocking orders should run a local caching recursive resolver."
Latency is a tradeoff, I mentioned there are tradeoffs. For an individual or home network, the latency should not be a problem especially with caching.
As for TCP/UDP, current RFCs say that DNS servers must accept TCP, but not all may follow the standard and some misconfigured firewalls may block it. But it doesn’t seem to be an issue when tunneling all traffic over Tor using something like Tails. So I don’t think this is really a problem.
Oh yeah crap, you're right about DNS over regular TCP. I totally brainfarted on that.
This seems like an overstatement: I have been running my own recursive DNS with Unbound for years and never though it was a "highly specialized undertaking." It took perhaps a couple of hours to set up in the pre-AI age. I filter ads and trackers using an aggressive blacklist[0].
[0] https://github.com/hagezi/dns-blocklists
Sad to see this going away, but I assume this is so Mullvad can focus on their primary services.
I'm not trying to start an unhealthy discussion about this topic, genuinely curious about your opinion on the matter.
Those parties exists for a reason, a response to certain pressures. Nothing happens in isolation. If you zoom out a bit and if you can for a second try to empathize with both sides, you will often find that both sides of an issue is correct, reasonable & rational from their own perspectives. It is often more an emotional response than one of pure survival.
The more you force things on people or suppress them, the more they will resist & push back. The rise of the far-right is not random or just pure evil manifesting out of thin air. It is like a acute inflammatory/immune system response. Obviously it can be exploited by bad actors to further inflame/divide & accelerate certain agendas. Often times extremism takes hold when certain justices are denied (which is in fact evil).
Life is best if you assume the guy on the other side (90% of a group) is just a bro trying to survive & have no real bad intent towards you, they don't know you or have been in your shoes, and the other way around too. Thus it is very important to become non-reactive, become observant who is trying to stoke the flames, who benefits from the chaos and so on.
It's great that they didn't try to cancel the guy or get seduced into driving a wedge into their team. It is great they chose their principle over pleasing the crowd in such a transparent way.
I have been a customer for many years. I once even used the cash payment option out of curiosity.
Here is their statement:
https://mullvad.net/en/blog/donation-controversy
They even linked his (Swedish language) private blog on which he wrote on the issue:
https://dberntsson.info/
Additionally the default of blocking 'malware' doesn't jive with uncensored internet - that should be an opt in and not a default on their flagship address if they want to be taken seriously as unfiltered provider.
If the encrypted endpoint can go down for extended periods and they curate list of 'malware' they are not something that should be considered a gateway to uncensored and open internet.
Quad9 also has worse latency but I could live with it, I just can't live with web pages failing to load several times per day(especially hacker News that has their DNS TTL set to 1 second)
It doesn't happen with my ISP's servers nor with CloudFlare or google or even good ol' L3.
First: We welcome the Mullvad users who will be shifted onto our systems, and we appreciate that Mullvad contacted us instead of doing this unilaterally. Since we have no signup process, they could have just moved users across but we very much appreciate their cooperation and communication, both with us and with the users of the service - this is exactly how an ideal transfer should go, at least from our perspective.
I'll try to make some short summaries of some of the points here, and a reply on each.
"You should just run your own DNS server - it's easy." - Yes, we agree that for a small company or home running your own recursive resolver is a reasonable solution. You probably won't get the threat mitigation depth of service that Quad9 offers, but you may not want that. Privacy also suffers a bit, since it's still the same IP address (your home "public" address) sending queries to authoritative servers, probably unencrypted. A good middle compromise is to run PiHole or AdGuard software, and forward your queries to Quad9 via an encrypted connection. (see below) This mixes your queries in with a large number of other users, and gets the potential improvements of having a much larger active cache nearby which will have "hot" answers. Running a home resolver for yourself or even a few dozen (or even a few hundred) people is not difficult. But with all services, things change with scale. As the query volume and number of locations grow, you soon find yourself hitting all possible exception cases, instantly. Many millions of requests a second requires a lot of time, expertise, and money to ensure nearly 100% uptime. We are admittedly quite a small group - less than 10 full time - but even that is under-staffed for supporting more than 100 million daily users. We do quite a bit with a very small resource set, and I doubt it could be done less expensively with the same robustness for the same scale. Again, we appreciate Mullvad's sponsorship to help keep this expanding at our normal weekly growth rate of around 2%.
"I want ad blocking, and Quad9 doesn't do that" - Correct, Quad9 does not do ad blocking at this time. There are good solutions like PiHole or AdGuard extensions that provide this functionality, and getting local control and logging of your DNS queries is probably useful for power users. There are also commercial platforms that provide this capability, and they may provide significantly more "knobs" for what you want to block. Quad9 is a non-profit - we're not out to corner the market, and as long as privacy and security is increased for the end user, we're all for commercial solutions!
"Quad9 blocks domains in Germany" - Currently there are no mandatory blocks that Quad9 is integrating or enforcing on our DNS platform, from any external party. We did briefly block some domains as a result of legal actions against us in Germany. The good news is that we won that case in Germany, after two years and three appeals and an enormous amount of time and money (which despite Germany's "loser pays" rule, is not even close to expenditures.) https://quad9.net/news/blog/quad9-turns-the-sony-case-around... The bad news is that the identical thing is happening now in France where we have a number of legal cases open against Quad9, and we do not see an end to this any time soon as long as there is an open question in the EU about what a content-neutral intermediary is and is not required to do.
"Mullvad exiting creates more centralization, and that is bad." On the fact that centralization is bad, we agree. DNS resolver centralization is not a great thing, and it seems to be trending in the wrong direction. It'...
DoT is more complex than you’d imagine because it has to try hard to implement its own solutions to avoid handshakes.
All modern Apple systems use QUIC. For instance if given 9.9.9.9 via DHCP they will automatically upgrade to encryption via DDR, then then upgrade to DOH3 with no intervention by the end user. We find that encryption load is lower with QUIC-based transports, but we need to really get a formal research paper together on that "in our spare time."
Faster? Probably, but is it measurably "better" remains a question for others to answer. Due to parallelism in most query sets, minor wins with DNS latency matter less than you might think.
It seems all too similar to the degradation of peer-to-peer networks where nodes are replaced by few supernodes. You mentioned a couple reasons yourself: consolidation and legal pressure. Add to this the technical qualification aspect and time investment (Mullvad's position), and the financial cost of sustaining such a non-profit project. Suddenly there are very few people or even organizations worldwide, who can bear the burden.
Thank you for existing and your tireless work.
Due to Lugano Convention [0] / Budapest Convention [1] / Hague Convention etc, I don't see how Switzerland is any more insulated than, say, Norway is (both these countries are part of EFTA & signatories to various UN/EU/EFTA treaties). Per this article [2], Switzerland ranks below Ireland, Portugal, Denmark, France in Data privacy laws (in fact, it ranks the same as the UK).
If I am being honest, at this point, "based in Switzerland" (or Cyprus or Sweden or Gibraltar) comes across as marketing gimmick VPN companies are notorious for.
[0] EU civil & commercial law enforcement in Switzerland: https://www.legal500.com/guides/chapter/switzerland-enforcem...
[1] Mutual Legal Assistance Treaty (MLAT) is bypassed: https://rm.coe.int/16802e726c
[2] https://www.comparitech.com/blog/vpn-privacy/surveillance-st...
Swiss data privacy law is also much more strict on us, which "puts our money where out mouth is" as the saying goes. Violating privacy laws in Switzerland may result in criminal penalties, not simply civil penalties - jail time, rather than just fines.
[1]https://mullvad.net/en/help/dns-over-https-and-dns-over-tls
In the near term, there is no filter set that we offer that mimics that functionality.
However, we recognize some variation of "best effort" adult content segmentation is a useful filter to have. We're considering it in the near term, as we have some specific educational institutional pressure to try to meet as well, since students are often easy targets for phishing, classroom computers are rife with malware, and there is also the problem of inappropriate DNS-based profiling of students and schools - problems that Quad9 can help solve.
Are there any alternatives?
I'd tempted to setup a DNS Forwarder up on that with Ad-Blocking then use Quad9 as upstream, then just have Tailscale be always on.
While reproing the issue I noted the average roundtrip time from my OVH server hosted in Oregon to the default upstream DNS - Quad9 - was around 70ms. When I changed it to Hurricane Electric the roundtrip dropped to a steady 20ms. Later I changed it again to Cloudflare and the roundtrip was a consistent 2 to 3ms.
> Mullvad Browser uses them [ the DoH servers ] by default when you're not on Mullvad VPN, preventing your ISP from seeing the domains you visit.
This is a half-truth until Encrypted Client Hello (ECH) is in-use for most of your traffic. Sure, you won't have clear-text DNS floating out there in the series of tubes. However, without ECH the hostname you're connecting to is exposed in the SNI field during TLS handshakes.
I imagine most sites we are browsing will eventually be able to leverage ECH, so this should become less of an issue over time, but in the event you frequent any self-hosted operations (e.g. no Cloudflare or similar), encrypted client hello could still reveal identifying information since it requires still exposing an "outer SNI" that a valid certificate needs to be presented for. You only get to easily hide in with the masses when you use a big infrastructure provider as a consequence, since the common outer SNI of cloudflare-ech.com doesn't really reveal anything different than an IP <-> ASN database would. But if the outer SNI is "dunder-cat-enterprises.com", then all I've protected you from is your ISP snooping on the subdomain or pinpointing exactly which one of my domains you might be talking to.
VPN providers at the tier of Mullvad should be precise about this stuff -- I think it's more than just a nitpick, considering the audience. oh god did I just use an emdash.
Note that you need some flavor of secure DNS to enforce ECH. The protocol is designed to be downgradable.