Setting Up Android Private DNS (DoH)

9 min read Step‑by‑step guide to configure Android's Private DNS (DNS‑over‑HTTPS) for better security, faster browsing, and reduced tracking on any Android 9+ device. September 24, 2026 23:00 How to Set Up Android Private DNS (DoH) for Enhanced Privacy and Speed

Why Use Private DNS (DoH) on Android?

Traditional DNS queries travel in clear text, allowing ISPs, public Wi‑Fi operators, or any network observer to see which domains you request. Private DNS—often implemented as DNS‑over‑HTTPS (DoH) or DNS‑over‑TLS (DoT)—encrypts those queries, preventing eavesdropping and tampering. The feature is built into Android 9 (Pie) and later, making it a convenient, system‑wide solution without needing third‑party apps.

What Exactly Is Private DNS (DoH)?

DoH sends DNS requests over HTTPS, using the same encrypted channel as regular web traffic. This means:

  • Queries are hidden from the local network.
  • Responses are verified using TLS certificates, reducing the risk of DNS spoofing.
  • Performance can improve because many DoH providers run large, globally distributed networks.

Android lets you point the system resolver to a DoH server of your choice, or you can use the “Automatic” mode that selects a compatible provider based on the current network.

Prerequisites

  1. A device running Android 9 (Pie) or newer. The steps are similar on Android 10, 11, 12, and 13.
  2. An active internet connection (Wi‑Fi or mobile data).
  3. A DoH server address. Popular public providers include:
    • Google: dns.google
    • Cloudflare: 1dot1dot1dot1.cloudflare-dns.com
    • Quad9: dns.quad9.net
    • NextDNS (custom): dns.nextdns.io (requires a personal ID)
  4. Optional: A DNS testing app (e.g., Network Info II) or a web‑based tool like dnsleaktest.com to verify that your queries are indeed encrypted.

Step‑by‑Step Setup

Follow these steps carefully. The UI may vary slightly depending on the device manufacturer, but the core path remains the same.

1. Open the Settings app

Locate the Settings icon in your app drawer or pull down the notification shade and tap the gear icon.

2. Navigate to Network & Internet

On most stock Android skins the path is Settings → Network & Internet. On Samsung devices you may find it under Connections or Wi‑Fi & network.

3. Tap “Private DNS”

Within the Network & Internet screen, scroll down until you see Private DNS. This option may be hidden under an “Advanced” dropdown on some OEM skins.

4. Choose the configuration mode

You will see three options:

  • Off – DNS queries are unencrypted (default on older devices).
  • Automatic – Android tries to use a DoH provider that supports the current network.
  • Private DNS provider hostname – Manually specify a DoH server.

For maximum control, select Private DNS provider hostname.

5. Enter the DoH hostname

Type the hostname of the DoH server you wish to use. Do not include https:// or any path—just the domain name. Examples:

  • Google: dns.google
  • Cloudflare: 1dot1dot1dot1.cloudflare-dns.com
  • Quad9: dns.quad9.net

After entering the hostname, tap Save or the check‑mark icon.

6. Verify the change

The system will test the connection. If the hostname resolves and the TLS handshake succeeds, you’ll see a toast notification that says “Private DNS mode set to hostname”. If the test fails, Android will revert to the previous setting and show an error message.

How to Verify That DoH Is Working

Simply enabling the setting does not guarantee that all apps respect it—most do, but a few legacy apps may still use the device’s default DNS.

Method 1: Use a DNS‑Leak Test Website

  1. Open a browser (Chrome, Firefox, or the built‑in Android WebView).
  2. Visit dnsleaktest.com and run the “Standard” test.
  3. If the displayed DNS servers match the provider you configured (e.g., 1.1.1.1 for Cloudflare), the tunnel is active.

Method 2: Use a Network Info App

Apps like Network Info II or IP Tools can display the active DNS servers for the current network. Look for the DoH hostname you entered.

Method 3: Command‑Line (Advanced Users)

If you have adb access, you can run:

adb shell getprop net.dns1
adb shell getprop net.dns2

These properties will show the IP addresses resolved by the DoH provider.

Common Issues and How to Fix Them

  • Connection fails after entering hostname: Double‑check that you typed the hostname exactly. Do not include spaces or protocol prefixes.
  • Some apps still show your ISP’s DNS: A few VPN or custom‑ROM apps may bypass the system resolver. In such cases, consider using a full‑device VPN that forces DNS over the VPN tunnel.
  • Wi‑Fi networks with captive portals: Private DNS may not work on networks that require a web‑based login (e.g., hotels, airports). Temporarily switch to “Automatic” or “Off” to complete the login, then re‑enable Private DNS.
  • Device reports “Private DNS mode set to hostname” but DNS queries are still unencrypted: Verify using the DNS‑leak test. If the test shows your ISP, the network may be intercepting TLS and presenting an invalid certificate. In such rare cases, you may need to switch to a different provider.

When to Use Private DNS (DoH) and When It May Not Be Needed

Private DNS is most beneficial on untrusted networks—public Wi‑Fi, coffee‑shop hotspots, or any place where the router is not under your control. On trusted home networks where you already control the router’s DNS settings, the privacy gain is smaller, though the encryption still protects against ISP‑level snooping.

If you already use a VPN that routes all traffic through its own DNS servers, enabling Private DNS may be redundant. However, it does not hurt to keep it on, as it adds an extra layer of protection should the VPN connection drop.

Additional Tips and Best Practices

  • Choose a reputable DoH provider: Look for providers with a clear privacy policy, no logging of query data, and strong TLS configurations.
  • Combine with a reputable VPN if you need location masking in addition to DNS privacy.
  • Regularly test your configuration after major OS updates, as system changes can reset the Private DNS setting.
  • Consider custom DoH configurations if you run your own DNS server (e.g., Pi‑hole with DoH support). Use the hostname of your server.
  • Be aware of DNS‑based content filtering: Some parental‑control solutions rely on DNS responses. Switching to a neutral DoH provider may bypass these filters, so configure accordingly.

Conclusion

Android’s built‑in Private DNS feature offers a straightforward way to encrypt your DNS traffic without installing extra apps. By following the steps above, you can protect yourself from ISP‑level tracking, improve resilience against DNS spoofing, and potentially enjoy faster name resolution. Remember to verify the configuration, keep an eye on any connectivity quirks, and choose a privacy‑focused provider that aligns with your needs.

With a few taps, you’ve turned a simple setting into a meaningful privacy upgrade—something every Android user should consider, especially when connecting to public networks.

User Comments (0)

Add Comment
We'll never share your email with anyone else.