Shutting down our public encrypted DNS

Mullvad’s decision to shut down its public encrypted DNS service and instead fund Swiss-based Quad9 raises questions about centralization, censorship pressure, and how much users should trust large privacy-focused resolvers. Commenters weigh the trade-offs between relying on Quad9—which offers DNSSEC validation and malware blocking but no ad blocking and has faced court-ordered blocking in Europe—and running their own recursive, often ad-blocking DNS stacks with tools like Unbound, Pi-hole, or AdGuard Home. The conversation also touches on broader concerns about state surveillance, legal liability for DNS providers, and how the political activities of Mullvad’s co-founder affect user trust.

Mullvad’s shutdown & Quad9 sponsorship

  • Many see sponsoring Quad9 instead of running Mullvad’s own encrypted DNS as pragmatic and “brilliant,” letting a specialist operate the service.
  • Others think calling public DNS “highly specialized” is overstated; running a small recursive resolver (e.g., Unbound) for home or small orgs is seen as easy. Counterpoint: operating a global anycast service with legal exposure is very different from a home setup.
  • Some suspect cost-cutting and legal risk, not technical difficulty, are the main drivers.

DNSSEC, DoH, and security tradeoffs

  • Quad9 warns against enabling DNSSEC validation on a forwarder when Quad9 already validates; some found this “dodgy” and worried about upstream poisoning.
  • Thread debates:
    • DNSSEC between stub and recursive essentially collapses to a “validated/insecure” flag; to distrust a malicious resolver you must validate locally/recursively.
    • Local DNSSEC validation is rare and fragile; one user hit subtle bugs (Atlassian + systemd-resolved) and concluded it’s “not for non‑experts.”
  • Some argue DNSSEC’s model is awkward for stubs, which helped DoH gain popularity, but others stress DoH doesn’t protect against a malicious resolver at all.

Adblocking & alternative DNS options

  • Big disappointment that Quad9 doesn’t offer adblocking or the “no government blacklist” stance Mullvad DNS had.
  • Heavy emphasis on system-wide adblocking, especially on mobile and outside home networks.
  • Suggested alternatives: NextDNS, ControlD, AdGuard DNS, Cloudflare “Families” (malware-only), dot.sb, DNS4EU-based resolvers, AdGuard Home, Pi-hole, Technitium, Unbound with community blocklists, and router-based OpenWRT setups.
  • Many recommend self-hosted filtering (Pi-hole/AdGuard Home) + Quad9 (or similar) upstream for privacy and control; others avoid self-hosting for non‑technical users and use managed services like NextDNS.

Centralization, censorship & law

  • Multiple comments worry that pushing users to Quad9 increases resolver centralization and makes legal blocking orders more attractive and effective.
  • Quad9 has faced blocking injunctions (e.g., in Germany and Italy) over copyright; one case in Germany was ultimately won on appeal, but similar actions continue, especially in France.
  • Some tie this to broader criticisms of EU courts, copyright maximalism, and creeping infrastructure-level censorship.

Quad9’s performance, design and privacy claims

  • Mixed reports on performance: some saw Mullvad DoH as faster; others found Mullvad slow/unstable and Quad9 (or Cloudflare) much more reliable and lower-latency.
  • A Quad9 representative explains:
    • They run ~200+ “islanded” locations, no central backbone, and support DoT, DoH, HTTP/3, DoQ, plus experiments with encrypting resolver–authoritative links (ADOx).
    • They claim to store no per-user query data and say no government has requested data so far.
    • Scale and legal defense (not adblocking features) are their focus; adblocking is left to local tools or commercial services.

Trust, politics & surveillance

  • Some users dropped Mullvad after learning a cofounder is the dominant funder of a Swedish party with hardline anti‑immigration / “population replacement” rhetoric; others debate whether that party is “far-right,” Marxist, or syncretic.
  • Several respect Mullvad’s public response as non‑performative and not ejecting the cofounder, while others still won’t fund him via subscriptions.
  • Broad concern that centralized “privacy” services are prime targets for intelligence agencies; disagreement over how much non‑US jurisdiction, strong no‑logging, and encryption meaningfully mitigate that risk.