Setting Up Private DNS on Android
8 min read
Learn how to enable Private DNS (DNS over TLS) on Android devices, choose a trusted resolver, verify encryption, and troubleshoot common issues.
September 26, 2026 08:30
What is Private DNS and Why It Matters
Private DNS, also known as DNS over TLS (DoT), encrypts the communication between your Android device and the DNS server that translates domain names into IP addresses. By default, most mobile networks use unencrypted DNS queries, which can be intercepted, logged, or modified by network operators, public Wi‑Fi hotspots, or malicious actors. Enabling Private DNS ensures that your DNS traffic is encrypted, improving privacy, preventing DNS‑based hijacking, and often speeding up name resolution when using a fast, reliable resolver.
Prerequisites and Compatibility
- Android 9 Pie (API level 28) or newer. The built‑in Private DNS feature was introduced in Android 9.
- An active internet connection (mobile data or Wi‑Fi) to download the DNS resolver’s configuration.
- A DNS provider that supports DNS over TLS. Popular options include Google (dns.google), Cloudflare (1.1.1.1), Quad9 (9.9.9.9), and many regional providers.
If you are running a device with a custom ROM or a heavily modified UI, the location of the setting may vary slightly, but the underlying functionality remains the same.
Step‑by‑Step Guide to Enabling Private DNS
- Open Settings. Swipe down from the top of the screen and tap the gear icon, or locate the Settings app in your app drawer.
- Navigate to Network & Internet. On most devices this option is near the top of the main Settings list. On some OEM skins it may be labeled Connections or Wi‑Fi & Network.
- Tap “Private DNS”. You will see three options:
- Off – DNS queries are sent in clear text.
- Automatic – The system tries to use a DNS‑over‑TLS provider automatically if the network advertises one.
- Private DNS provider hostname – Allows you to specify a custom DNS resolver that supports DoT.
- Select “Private DNS provider hostname”. In the text field that appears, type the hostname of the DNS service you want to use. For example:
- Google:
dns.google - Cloudflare:
1dot1dot1dot1.cloudflare-dns.com - Quad9:
dns.quad9.net
Make sure you type the hostname exactly as shown; a typo will cause the setting to fail.
- Save the setting. Tap “Save” or the check‑mark icon (depending on your device). Android will immediately attempt to establish a TLS‑encrypted connection to the specified server.
- Verify the connection. Return to the Private DNS screen – if the status reads “Private DNS mode active”, the configuration succeeded. If you see an error message such as “Private DNS mode failed”, double‑check the hostname and your internet connection.
Testing That Private DNS Is Working
After enabling the feature, it’s a good idea to confirm that DNS queries are indeed encrypted. You can use one of the following methods:
- Online test tools. Visit dnsleaktest.com or Cloudflare’s test page from your Android browser. The site will report the DNS resolver it sees; it should match the provider you configured.
- ADB logcat. If you have developer options enabled, connect the device to a PC and run
adb logcat | grep -i dns. Look for entries indicating “DoT” or “TLS handshake”. - Network packet capture. Tools like Wireshark on a PC connected to the same Wi‑Fi can capture traffic from the device. Encrypted DNS packets will appear as TLS traffic on port 853, not as plain DNS on port 53.
Choosing a Reliable Private DNS Provider
Not all DNS resolvers support DoT, and performance can vary. Here are a few considerations when picking a provider:
- Privacy policy. Look for providers that log minimal or no data. Cloudflare and Quad9 are known for strong privacy commitments.
- Geographic coverage. Some providers have servers worldwide, which can reduce latency.
- Security features. DNSSEC validation prevents forged DNS responses. Most reputable DoT providers support DNSSEC automatically.
- Filtering options. Quad9 blocks known malicious domains, while Cloudflare offers optional filtering for adult content.
Potential Issues and How to Troubleshoot
While Private DNS works smoothly for most users, you may encounter the following problems:
1. “Private DNS mode failed” error
- Check the hostname for typos.
- Ensure your network allows outbound connections on TCP port 853. Some corporate or school Wi‑Fi networks block this port.
- Try a different provider to see if the issue is specific to the chosen resolver.
2. Certain apps lose connectivity
Some older apps or devices that rely on custom DNS configurations may not function correctly when DoT is enforced. If you notice an app failing to load content, you can temporarily switch Private DNS back to “Off” or “Automatic” and see if the problem resolves.
3. Slower browsing on the first connection
The initial TLS handshake adds a small amount of latency. Subsequent queries are cached, so performance usually improves after the first few requests.
4. VPN conflicts
If you use a VPN that also provides its own DNS service, Android may prioritize the VPN’s DNS over Private DNS. In most cases this is harmless, but if you want to force a specific DoT provider, disable the VPN’s DNS or use a split‑tunnel configuration.
Advanced: Using a Custom DNS-over‑TLS Configuration File
For power users who want to run their own resolver (e.g., Stubby or Unbound) on a home server, Android can point to a hostname that resolves to that server’s IP address. The steps are identical; just ensure the server’s TLS certificate is valid and trusted by the Android system, or install the certificate manually via Settings → Security → Encryption & credentials → Install a certificate.
Best Practices for Maintaining a Secure DNS Setup
- Keep your Android version up to date. Security patches often include improvements to DNS handling.
- Periodically test your DNS. Use the online tools mentioned earlier to verify that your traffic is still encrypted.
- Monitor provider announcements. DNS services occasionally change hostnames or discontinue DoT support.
- Combine Private DNS with a reputable VPN. This adds an additional layer of encryption for all traffic, not just DNS.
Conclusion
Enabling Private DNS on Android is a straightforward way to boost your privacy and protect against DNS‑based attacks without needing third‑party apps. By following the steps above, you can configure a trusted resolver, verify that encryption is active, and troubleshoot common issues. Regularly reviewing your DNS settings ensures you stay ahead of potential threats and enjoy a faster, more secure browsing experience on your Android device.