How to Enable Private DNS (DNS over TLS) on Android

10 min read Learn step‑by‑step how to turn on Android’s Private DNS feature, test the connection and troubleshoot common issues for a more private internet experience. September 27, 2026 17:00 How to Enable Private DNS (DNS over TLS) on Android for Safer Browsing

Many Android users assume their internet traffic is private because they are on Wi‑Fi or cellular data, but the DNS queries that translate domain names into IP addresses travel in clear text. A rogue ISP, public Wi‑Fi hotspot, or malicious app can intercept or modify those queries, leading to privacy leaks or phishing attacks. Android 9 (Pie) introduced Private DNS, which routes DNS lookups through an encrypted TLS tunnel (often called DNS‑over‑TLS or DoT). Enabling this feature is a low‑effort way to harden your browsing without installing third‑party apps.

Before you start

  • Device must be running Android 9 (Pie) or newer. Some manufacturers keep the feature but rename it; check your UI version if you can’t find it.
  • Make sure you have a stable internet connection (Wi‑Fi or mobile data) while configuring the setting.
  • Pick a trusted DNS‑over‑TLS provider. Public options include dns.google (Google), 1dot1dot1dot1.cloudflare-dns.com (Cloudflare), and dns.quad9.net (Quad9). Write the hostname down for later.
  • Optionally, back up your current network settings (Settings > System > Backup > Back up now) so you can revert if needed.

Step‑by‑step: Enabling Private DNS via the UI

1. Open the Settings app

Tap the gear icon in your app drawer or pull down the notification shade and select the Settings shortcut.

2. Navigate to the network section

On stock Android the path is Network & internet. On Samsung devices it may be Connections > More connection settings. Look for any entry that mentions Private DNS or DNS over TLS.

3. Open the Private DNS screen

You should see three options:

  • Off – default, unencrypted DNS.
  • Automatic – lets the system pick a DNS provider that supports DoT (available on some OEM skins).
  • Private DNS provider hostname – manual entry.

4. Choose “Private DNS provider hostname”

Tap the radio button, then a text field appears. Enter the hostname of your chosen provider, for example dns.google for Google’s public DNS‑over‑TLS service.

5. Save the setting

Press Save or the back arrow (the system saves automatically on most devices). You should see a brief toast notification confirming the change.

6. Verify the connection

Open a browser and visit dnsleaktest.com. Run the “Standard test”. The displayed resolver should match the provider you entered (e.g., “Google Public DNS”). If the test still shows your ISP’s DNS, the setting did not take effect – see the troubleshooting section below.

Alternative method: Enabling Private DNS with ADB

Some OEM skins hide the Private DNS UI, or you may be configuring a device without a screen (e.g., a headless Android TV). In those cases you can use ADB to set the system property directly.

1. Install ADB on your computer

If you haven’t already, download the Android platform‑tools package and extract it.

2. Enable Developer Options and USB debugging

On the phone, go to Settings > About phone and tap Build number seven times. Then return to Settings > System > Developer options and toggle USB debugging on.

3. Connect the device

Plug the phone into your PC via USB. In a terminal, run:

adb devices

You should see your device listed as “device”. If not, check the USB mode (choose “File Transfer”) and accept the RSA prompt on the phone.

4. Set the Private DNS property

Execute the following command, replacing dns.google with your chosen hostname:

adb shell settings put global private_dns_mode hostname
adb shell settings put global private_dns_specifier dns.google

The first line tells Android to use the “hostname” mode; the second line supplies the actual DNS‑over‑TLS server.

5. Reboot (optional)

Most devices apply the change instantly, but a quick reboot guarantees the new resolver is used for all network stacks.

6. Verify

Follow step 6 of the UI method – open a browser and run a DNS leak test.

Understanding why Private DNS matters

When you type example.com into a browser, the device first asks a DNS server for the corresponding IP address. Without encryption, anyone on the same network (e.g., a coffee‑shop Wi‑Fi) can see which domains you query. Some ISPs also inject ads or redirect you to malicious sites by tampering with DNS responses. DNS‑over‑TLS wraps that query in TLS, the same encryption used for HTTPS, preventing eavesdropping and tampering.

Private DNS does not replace a VPN; it only protects the DNS layer. Your actual HTTP/HTTPS traffic still follows the normal path, so you still benefit from a VPN if you need full‑tunnel privacy.

Common pitfalls and troubleshooting

  • No internet after enabling Private DNS – The provider you entered may be unreachable from your network (some carriers block DoT). Switch to another provider (e.g., Cloudflare) or revert to “Off” and test connectivity.
  • DNS leak test still shows ISP DNS – Verify you entered the hostname correctly; there should be no trailing spaces or “https://”. Also, ensure you are not on a VPN that forces its own DNS.
  • Only Wi‑Fi works, mobile data fails – Some carriers only support DoT on Wi‑Fi. In that case, you can keep Private DNS enabled and fall back to the carrier’s DNS on mobile by toggling the setting off when using cellular.
  • App‑specific DNS issues – Certain apps (e.g., some VPN clients) bypass the system DNS resolver. If an app fails to load content, check its own network settings or disable the VPN temporarily.

Changing DNS providers can affect content filtering or parental controls that rely on the ISP’s DNS. If you depend on such filters, choose a provider that offers optional filtering (e.g., dns.quad9.net blocks known malicious domains).

Advanced checks (optional)

If you like to confirm that TLS is truly in use, you can inspect the network traffic with a packet capture app (e.g., tPacketCapture) or use adb logcat to look for lines containing “dns_over_tls”. The log entry typically reads:

DnsResolver: DNS over TLS established with dns.google

Seeing that line confirms the encrypted tunnel is active.

When to revert the setting

Private DNS is safe for the vast majority of users, but you may need to disable it temporarily when troubleshooting network‑related issues, such as:

  • Connecting to a corporate Wi‑Fi that uses an internal DNS server not reachable over DoT.
  • Using a device‑specific app that requires DNS hijacking (some streaming services).
  • Diagnosing a suspected DNS‑related connectivity problem – switch back to “Off” and see if the issue persists.

Recap

Enabling Private DNS on Android is a straightforward way to encrypt one of the most visible parts of your internet traffic. By following the UI steps (or the ADB fallback) you gain:

  • Protection against ISP‑level snooping and DNS hijacking.
  • Compatibility with most apps without additional configuration.
  • Easy rollback if a particular network does not support DoT.

Keep a short list of trusted DoT hostnames handy, test after each change, and you’ll enjoy a more private browsing experience on every Android device you own.

User Comments (0)

Add Comment
We'll never share your email with anyone else.