Technology
Hacker News

Shutting down our public encrypted DNS

Source Entity

Hacker News

September 6, 2026
Shutting down our public encrypted DNS

Mullvad is retiring its public encrypted DNS service, shifting its support to the Quad9 Foundation to consolidate privacy-focused infrastructure. This move reflects a broader industry trend toward specialized, collaborative efforts in securing DNS traffic against ISP monitoring.

The Shift in Privacy Infrastructure: Mullvad Retires Public DNS

On September 3, 2026, Mullvad announced the discontinuation of its public encrypted DNS (DoH) servers. Since 2022, Mullvad has provided these services to protect users from ISP-level tracking; however, the company has determined that maintaining these servers is redundant for their primary VPN users, whose traffic is already routed through an internal, encrypted DNS layer. By transitioning this responsibility to the Quad9 Foundation, Mullvad is signaling a strategic pivot toward focusing on its core VPN product while entrusting public DNS security to a specialized entity.

Why Infrastructure Consolidation Matters

Operating a privacy-focused DNS service is an intensive, highly specialized undertaking. Mullvad’s decision to sunset its service acknowledges that the Quad9 Foundation is the undisputed leader in the field. Rather than duplicating infrastructure, this transition aims to consolidate resources into a single, high-performance ecosystem. This move reflects a growing maturity in the privacy-tech sector, where companies are moving away from siloed proprietary solutions in favor of collaborative, industry-standard infrastructure that ensures higher levels of security and reliability for the end user.

The Role of Quad9 in the European Tech Ecosystem

Quad9, based in Europe, has gained significant praise for its ability to combine secure, privacy-preserving protocols with robust organizational policies. As noted by experts like Mallory Knodel from the Center for Democracy and Technology, encryption alone is insufficient; it must be complemented by rigorous governance. By leveraging the European regulatory environment, Quad9 provides a framework that protects users from malicious domains while maintaining the privacy standards that modern internet users demand.

DNS Security and the User Experience

The broader implications of this shift are significant for users who rely on privacy tools like the Mullvad Browser. While Mullvad will now point users toward Quad9, the underlying goal remains the same: preventing ISPs from logging domain queries. This transition ensures that even when a user is not connected to a VPN, they retain access to a hardened, privacy-first DNS environment. It underscores the ongoing industry effort to standardize secure recursive DNS as a default, rather than an optional configuration.

The Landscape of Free Secure DNS Providers

Parallel to these developments, the ecosystem for free, secure DNS continues to evolve with services like deSEC. Unlike the recursive services provided by Quad9 or the former Mullvad setup, deSEC offers free DNS hosting managed through open-source software. These diverse options illustrate a bifurcated market: one segment focused on recursive privacy for end users (like Quad9), and another focused on secure DNS management for administrators (like deSEC).

Future Trends in Internet Privacy

The move by Mullvad is a microcosm of a larger trend where privacy is no longer a niche feature but a fundamental requirement for the modern internet. As Dr. Andy Yen noted, the growth of infrastructure providers like Quad9 within the European ecosystem proves that privacy is increasingly being treated as a cornerstone of the future tech economy. Moving forward, we can expect to see further consolidation of specialized security services, as companies recognize that high-stakes infrastructure is best managed by organizations dedicated solely to that mission.

Verification Required?

Read the full report from the primary source

Go to Hacker News