Shutting down our public encrypted DNS
Mullvad’s decision to shut down its public encrypted DNS service and instead fund Swiss-based Quad9 raises questions about centralization, censorship pressure, and how much users should trust large privacy-focused resolvers. Commenters weigh the trade-offs between relying on Quad9—which offers DNSSEC validation and malware blocking but no ad blocking and has faced court-ordered blocking in Europe—and running their own recursive, often ad-blocking DNS stacks with tools like Unbound, Pi-hole, or AdGuard Home. The conversation also touches on broader concerns about state surveillance, legal liability for DNS providers, and how the political activities of Mullvad’s co-founder affect user trust.
Mullvad’s shutdown & Quad9 sponsorship
- Many see sponsoring Quad9 instead of running Mullvad’s own encrypted DNS as pragmatic and “brilliant,” letting a specialist operate the service.
- Others think calling public DNS “highly specialized” is overstated; running a small recursive resolver (e.g., Unbound) for home or small orgs is seen as easy. Counterpoint: operating a global anycast service with legal exposure is very different from a home setup.
- Some suspect cost-cutting and legal risk, not technical difficulty, are the main drivers.
DNSSEC, DoH, and security tradeoffs
- Quad9 warns against enabling DNSSEC validation on a forwarder when Quad9 already validates; some found this “dodgy” and worried about upstream poisoning.
- Thread debates:
- DNSSEC between stub and recursive essentially collapses to a “validated/insecure” flag; to distrust a malicious resolver you must validate locally/recursively.
- Local DNSSEC validation is rare and fragile; one user hit subtle bugs (Atlassian + systemd-resolved) and concluded it’s “not for non‑experts.”
- Some argue DNSSEC’s model is awkward for stubs, which helped DoH gain popularity, but others stress DoH doesn’t protect against a malicious resolver at all.
Adblocking & alternative DNS options
- Big disappointment that Quad9 doesn’t offer adblocking or the “no government blacklist” stance Mullvad DNS had.
- Heavy emphasis on system-wide adblocking, especially on mobile and outside home networks.
- Suggested alternatives: NextDNS, ControlD, AdGuard DNS, Cloudflare “Families” (malware-only), dot.sb, DNS4EU-based resolvers, AdGuard Home, Pi-hole, Technitium, Unbound with community blocklists, and router-based OpenWRT setups.
- Many recommend self-hosted filtering (Pi-hole/AdGuard Home) + Quad9 (or similar) upstream for privacy and control; others avoid self-hosting for non‑technical users and use managed services like NextDNS.
Centralization, censorship & law
- Multiple comments worry that pushing users to Quad9 increases resolver centralization and makes legal blocking orders more attractive and effective.
- Quad9 has faced blocking injunctions (e.g., in Germany and Italy) over copyright; one case in Germany was ultimately won on appeal, but similar actions continue, especially in France.
- Some tie this to broader criticisms of EU courts, copyright maximalism, and creeping infrastructure-level censorship.
Quad9’s performance, design and privacy claims
- Mixed reports on performance: some saw Mullvad DoH as faster; others found Mullvad slow/unstable and Quad9 (or Cloudflare) much more reliable and lower-latency.
- A Quad9 representative explains:
- They run ~200+ “islanded” locations, no central backbone, and support DoT, DoH, HTTP/3, DoQ, plus experiments with encrypting resolver–authoritative links (ADOx).
- They claim to store no per-user query data and say no government has requested data so far.
- Scale and legal defense (not adblocking features) are their focus; adblocking is left to local tools or commercial services.
Trust, politics & surveillance
- Some users dropped Mullvad after learning a cofounder is the dominant funder of a Swedish party with hardline anti‑immigration / “population replacement” rhetoric; others debate whether that party is “far-right,” Marxist, or syncretic.
- Several respect Mullvad’s public response as non‑performative and not ejecting the cofounder, while others still won’t fund him via subscriptions.
- Broad concern that centralized “privacy” services are prime targets for intelligence agencies; disagreement over how much non‑US jurisdiction, strong no‑logging, and encryption meaningfully mitigate that risk.