Many Android users assume their internet traffic is private because they are on Wi‑Fi or cellular data, but the DNS queries that translate domain names into IP addresses travel in clear text. A rogue ISP, public Wi‑Fi hotspot, or malicious app can intercept or modify those queries, leading to privacy leaks or phishing attacks. Android 9 (Pie) introduced Private DNS, which routes DNS lookups through an encrypted TLS tunnel (often called DNS‑over‑TLS or DoT). Enabling this feature is a low‑effort way to harden your browsing without installing third‑party apps.
dns.google (Google), 1dot1dot1dot1.cloudflare-dns.com (Cloudflare), and dns.quad9.net (Quad9). Write the hostname down for later.Tap the gear icon in your app drawer or pull down the notification shade and select the Settings shortcut.
On stock Android the path is Network & internet. On Samsung devices it may be Connections > More connection settings. Look for any entry that mentions Private DNS or DNS over TLS.
You should see three options:
Tap the radio button, then a text field appears. Enter the hostname of your chosen provider, for example dns.google for Google’s public DNS‑over‑TLS service.
Press Save or the back arrow (the system saves automatically on most devices). You should see a brief toast notification confirming the change.
Open a browser and visit dnsleaktest.com. Run the “Standard test”. The displayed resolver should match the provider you entered (e.g., “Google Public DNS”). If the test still shows your ISP’s DNS, the setting did not take effect – see the troubleshooting section below.
Some OEM skins hide the Private DNS UI, or you may be configuring a device without a screen (e.g., a headless Android TV). In those cases you can use ADB to set the system property directly.
If you haven’t already, download the Android platform‑tools package and extract it.
On the phone, go to Settings > About phone and tap Build number seven times. Then return to Settings > System > Developer options and toggle USB debugging on.
Plug the phone into your PC via USB. In a terminal, run:
adb devices
You should see your device listed as “device”. If not, check the USB mode (choose “File Transfer”) and accept the RSA prompt on the phone.
Execute the following command, replacing dns.google with your chosen hostname:
adb shell settings put global private_dns_mode hostnameadb shell settings put global private_dns_specifier dns.google
The first line tells Android to use the “hostname” mode; the second line supplies the actual DNS‑over‑TLS server.
Most devices apply the change instantly, but a quick reboot guarantees the new resolver is used for all network stacks.
Follow step 6 of the UI method – open a browser and run a DNS leak test.
When you type example.com into a browser, the device first asks a DNS server for the corresponding IP address. Without encryption, anyone on the same network (e.g., a coffee‑shop Wi‑Fi) can see which domains you query. Some ISPs also inject ads or redirect you to malicious sites by tampering with DNS responses. DNS‑over‑TLS wraps that query in TLS, the same encryption used for HTTPS, preventing eavesdropping and tampering.
Private DNS does not replace a VPN; it only protects the DNS layer. Your actual HTTP/HTTPS traffic still follows the normal path, so you still benefit from a VPN if you need full‑tunnel privacy.
Changing DNS providers can affect content filtering or parental controls that rely on the ISP’s DNS. If you depend on such filters, choose a provider that offers optional filtering (e.g., dns.quad9.net blocks known malicious domains).
If you like to confirm that TLS is truly in use, you can inspect the network traffic with a packet capture app (e.g., tPacketCapture) or use adb logcat to look for lines containing “dns_over_tls”. The log entry typically reads:
DnsResolver: DNS over TLS established with dns.google
Seeing that line confirms the encrypted tunnel is active.
Private DNS is safe for the vast majority of users, but you may need to disable it temporarily when troubleshooting network‑related issues, such as:
Enabling Private DNS on Android is a straightforward way to encrypt one of the most visible parts of your internet traffic. By following the UI steps (or the ADB fallback) you gain:
Keep a short list of trusted DoT hostnames handy, test after each change, and you’ll enjoy a more private browsing experience on every Android device you own.









