Set Up a Local DNS Server on Android with Termux

24 min read Learn how to turn an Android phone into a local DNS server using Termux and dnsmasq. Step‑by‑step guide with configuration, testing, and troubleshooting. September 27, 2026 19:30 How to Set Up a Local DNS Server on Android with Termux and dnsmasq

Why Run a DNS Server on Android?

Most Android users never think about DNS – the service that translates human‑readable hostnames into IP addresses. Having a local DNS server on your phone can be useful for several reasons:

  • Ad‑blocking and content filtering without installing a separate app.
  • Testing custom host mappings while developing web or mobile apps.
  • Providing DNS for a small LAN when you have no router with DNS capabilities.
  • Learning networking fundamentals on a device you already carry.

Because the solution uses only free, open‑source tools (Termux and dnsmasq) it works on the majority of Android devices, regardless of manufacturer or carrier.

Before You Start

Prerequisites

  • Android 7.0 (Nougat) or newer. Older versions may lack the required Linux kernel features.
  • At least 500 MB of free storage for Termux and dnsmasq packages.
  • Wi‑Fi connection (cellular data is not suitable for DNS testing).
  • Basic familiarity with the Linux command line.
  • Optional but recommended: a rooted device if you want the DNS server to listen on the standard port 53 for other devices on the network.

If you cannot or do not want to root the phone, the tutorial shows how to run dnsmasq on an unprivileged port (e.g., 5353) and how to point other devices to that port using IP:port syntax where the Android UI allows it.

Step 1 – Install Termux and Update Packages

  1. Open the Google Play Store (or F-Droid) and install Termux. The F-Droid version receives updates more frequently.
  2. Launch Termux. The first run will set up a minimal Linux environment.
  3. Update the package repository and upgrade existing packages:
    pkg update && pkg upgrade -y

    This ensures you have the latest apt metadata and security patches.

  4. Install the termux-api package (optional) – it lets you control Wi‑Fi and other hardware from the command line, which we will use later for keeping the service alive:
    pkg install termux-api -y

After the upgrade, you should see a prompt similar to ~$. You are now ready to install dnsmasq.

Step 2 – Install dnsmasq

  1. In the Termux shell, run:
    pkg install dnsmasq -y

    Termux pulls the pre‑compiled dnsmasq binary from its repository. The installation takes only a few seconds.

  2. Verify the binary is available:
    which dnsmasq

    It should return /data/data/com.termux/files/usr/sbin/dnsmasq.

If the command fails, double‑check that you have a stable internet connection and that the pkg repositories are reachable.

Step 3 – Create a Basic dnsmasq Configuration

dnsmasq reads a configuration file called dnsmasq.conf. We will create a minimal version that works for most testing scenarios.

  1. Create a directory to store the config (you can keep it in your home folder):
    mkdir -p ~/dnsmasq && cd ~/dnsmasq
  2. Open a text editor. Termux ships with nano and vim. We will use nano for readability:
    nano dnsmasq.conf
  3. Paste the following content into the editor:
    # Basic dnsmasq configuration for Android
    # Listen only on the Wi‑Fi interface (usually wlan0)
    interface=wlan0
    # Bind to the IP address assigned to wlan0
    listen-address=192.168.4.1
    # Use Google Public DNS as upstream resolver (you can change this)
    server=8.8.8.8
    server=8.8.4.4
    # Cache size – 150 entries is more than enough for a small LAN
    cache-size=150
    # Optional: block known ad domains (example entry)
    address=/ads.example.com/0.0.0.0
    # Log queries to /data/data/com.termux/files/usr/var/log/dnsmasq.log
    log-queries
    log-facility=/data/data/com.termux/files/usr/var/log/dnsmasq.log
    

    Explanation of the key lines:

    • interface=wlan0 – restricts dnsmasq to the Wi‑Fi NIC, preventing it from answering on cellular data.
    • listen-address=192.168.4.1 – replace this IP with the one your phone obtains when you enable the hotspot (see Step 4). Using a static address simplifies client configuration.
    • server=8.8.8.8 – forwards unknown queries to Google DNS. You can substitute any public resolver.
    • address=/ads.example.com/0.0.0.0 – demonstrates how to block a domain. Add more address= lines to create a custom blocklist.
    • log-queries and log-facility=… – enable simple logging for debugging.
  4. Save the file (Ctrl+O in nano) and exit (Ctrl+X).

At this point you have a ready‑to‑run configuration. The next step is to make the Android Wi‑Fi interface reachable by other devices.

Step 4 – Turn Your Phone into a Wi‑Fi Hotspot (Optional but Recommended)

If you want other devices on the same network to use the DNS server, the easiest method is to enable Android’s built‑in hotspot feature. This creates a private Wi‑Fi network where your phone acts as the router.

  1. Open Settings → Network & internet → Hotspot & tethering → Wi‑Fi hotspot.
  2. Configure the hotspot:
    • Network name (SSID): any name you like.
    • Security: WPA2‑PSK (recommended).
    • Password: choose a strong password.
    • AP band: 2.4 GHz for maximum compatibility.
  3. Tap Save and then toggle the hotspot On.

    When the hotspot starts, Android assigns the phone the IP address 192.168.43.1 by default. You can keep this address or change it by editing the system file /system/etc/dhcpcd/dhcpcd.conf – which requires root. For a non‑root workflow we will keep the default and adjust the config file accordingly.

  4. Connect a second Android device, a laptop, or any Wi‑Fi client to the newly created hotspot.

Now the phone’s Wi‑Fi interface (often reported as wlan0) has a stable address that clients can reach.

Step 5 – Start dnsmasq

Running dnsmasq is as simple as invoking the binary with the configuration file we created.

  1. Return to the Termux session and navigate to the config directory if you left it:
    cd ~/dnsmasq
  2. Start dnsmasq in the foreground first to see any immediate errors:
    dnsmasq -C ./dnsmasq.conf -d

    The -d flag tells dnsmasq to stay in the foreground and print log messages to the terminal.

  3. If you see messages like dnsmasq: failed to bind DHCP server socket it means another service (perhaps Android’s built‑in DHCP server for the hotspot) is already using port 67. Since we are only using DNS, you can ignore the DHCP warning – dnsmasq will continue to serve DNS.
  4. Press Ctrl+C to stop the foreground instance once you have verified it starts without fatal errors.
  5. Now start dnsmasq as a background service that survives screen lock. Termux provides termux-wake-lock to keep the CPU awake and nohup to detach the process:
    termux-wake-lock && nohup dnsmasq -C ./dnsmasq.conf > /dev/null 2>&1 &

    This command does three things:

    • Acquires a wake lock so the phone does not sleep the CPU while the service runs.
    • Redirects all output to /dev/null to keep the terminal clean.
    • Runs dnsmasq in the background.
  6. Verify that the process is running:
    ps | grep dnsmasq

    You should see a line containing dnsmasq -C ./dnsmasq.conf.

If the process exits immediately, check the log file you defined earlier (/data/data/com.termux/files/usr/var/log/dnsmasq.log) for clues.

Step 6 – Point Clients to Your New DNS Server

Now that dnsmasq is listening on the phone’s hotspot IP (e.g., 192.168.43.1), you need to tell other devices to use it for DNS resolution.

Option A – Change DNS Settings on the Hotspot Client

  1. On the client device (another Android phone, laptop, etc.), open the Wi‑Fi settings for the hotspot network.
  2. Look for an “Advanced” or “IP settings” section. Switch from “DHCP” to “Static”.
  3. Enter the following values (adjust the IP if your hotspot uses a different subnet):
    • IP address: any free address in the hotspot’s range, e.g., 192.168.43.10.
    • Gateway: 192.168.43.1 (the phone).
    • DNS 1: 192.168.43.1.
    • DNS 2: optional – you can leave blank or use a public DNS as fallback.
  4. Save the settings and reconnect to the network.

After reconnecting, the client will send DNS queries directly to your Android phone.

Option B – Use a Non‑Privileged Port (No Root Required)

Some Android UI layers do not allow you to specify a custom DNS port. In that case you can run dnsmasq on a higher port (e.g., 5353) and use the iptables redirection trick. This method requires root because iptables manipulates the kernel’s network stack.

  1. Stop the running dnsmasq instance:
    pkill dnsmasq
  2. Start dnsmasq on port 5353 by adding port=5353 to the config file, then restart:
    echo "port=5353" >> dnsmasq.conf
    nohup dnsmasq -C ./dnsmasq.conf > /dev/null 2>&1 &
  3. Redirect incoming traffic on port 53 to 5353 (root only):
    su -c "iptables -t nat -A PREROUTING -p udp --dport 53 -j REDIRECT --to-port 5353"
    su -c "iptables -t nat -A PREROUTING -p tcp --dport 53 -j REDIRECT --to-port 5353"

    After this rule, any DNS request that reaches the phone on the standard port 53 is silently forwarded to dnsmasq listening on 5353.

Clients can now keep the default DNS settings (pointing to 192.168.43.1) and the redirection will handle the port conversion.

Step 7 – Test the DNS Server

Testing confirms that the server is reachable and that custom mappings work.

  1. On the client device, open a terminal (Linux/macOS) or use the nslookup app on Android.
  2. Run a basic lookup:
    nslookup example.com 192.168.43.1

    You should see an answer section with an IP address returned by Google’s resolver (since we forward to 8.8.8.8).

  3. Test a blocked domain (the example we added earlier):
    nslookup ads.example.com 192.168.43.1

    The result should be 0.0.0.0, confirming the address= rule is active.

  4. Check the log file for the query record (optional):
    cat /data/data/com.termux/files/usr/var/log/dnsmasq.log | grep ads.example.com

If the client reports “timed out” or “server not reachable”, re‑verify the IP address of the hotspot, ensure the phone’s Wi‑Fi interface is still up, and confirm that the wake lock is active (run termux-wake-lock -s to see status).

Troubleshooting Common Issues

Warning: Changing network settings can temporarily disconnect you from the internet. Keep a second device handy to restore connectivity if needed.

  • dnsmasq fails to start with “permission denied”
    • Cause: Attempting to bind to port 53 without root.
    • Fix: Either run dnsmasq on an unprivileged port (e.g., 5353) as described in Option B, or root the device and allow binding to 53.
  • No DNS responses from the client
    • Check that the client’s DNS setting points to the correct IP (the hotspot’s gateway).
    • Verify that the hotspot is still active; Android may turn it off after a period of inactivity.
    • Run ping 192.168.43.1 from the client to ensure basic connectivity.
  • Log file is empty
    • Make sure the directory /data/data/com.termux/files/usr/var/log exists and is writable.
    • Create it manually if needed:
      mkdir -p /data/data/com.termux/files/usr/var/log
  • dnsmasq stops when the screen turns off
    • Android may kill background processes to save battery. The termux-wake-lock command prevents the CPU from sleeping, but some OEMs still enforce aggressive task killing.
    • Solution: Install the termux:boot add‑on from the Play Store and add a script ~/.termux/boot/start-dnsmasq.sh that launches dnsmasq on boot. Also enable “Battery optimization” exclusion for Termux in Settings → Apps → Termux → Battery.

Advanced Use Cases

1. Using dnsmasq as an Ad‑Blocker for the Whole Hotspot

Replace the single address= line with a comprehensive blocklist. One popular source is the hosts file from StevenBlack. To import it:

# Download the hosts file (requires termux-api curl or wget)
curl -L https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts -o hosts.txt
# Convert to dnsmasq format (each line: address=/domain/0.0.0.0)
awk '/^0\.0\.0\.0/ {gsub(/^0\.0\.0\.0[ \t]+/, ""); print "address=/" $1 "/0.0.0.0"}' hosts.txt >> dnsmasq.conf

After updating the file, restart dnsmasq (kill the old process and start a new one). All devices connected to the hotspot will now benefit from the blocklist without installing any extra apps.

2. Custom Host Overrides for Development

When testing a web service that is not yet publicly reachable, you can map a hostname to your development server’s IP:

address=/my‑test‑api.local/10.0.0.42

Clients that resolve my-test-api.local will connect directly to 10.0.0.42. This is handy for mobile‑first developers who need to test on real devices.

3. Using dnsmasq for DHCP (Experimental)

dnsmasq can also serve DHCP leases, but Android’s built‑in hotspot already runs a DHCP server on port 67. Running a second DHCP server on the same interface will cause conflicts. If you disable the hotspot’s DHCP (possible only on rooted devices or custom ROMs), you can enable it in dnsmasq by adding:

dhcp-range=192.168.43.50,192.168.43.150,12h

Because this tutorial targets non‑root users, we keep DHCP disabled and rely on Android’s native implementation.

Cleaning Up – Stopping dnsmasq and Removing the Configuration

If you no longer need the DNS server, follow these steps to shut it down cleanly.

  1. Terminate the running process:
    pkill dnsmasq
  2. Release the wake lock (optional):
    termux-wake-unlock
  3. Delete the configuration directory if you do not plan to reuse it:
    rm -rf ~/dnsmasq
  4. Turn off the hotspot to return the phone to normal Wi‑Fi mode.

All log files are stored inside Termux’s private directory, so they disappear when you delete the folder.

Security and Privacy Considerations

  • Local network exposure – By default dnsmasq listens only on the Wi‑Fi interface, but if you later enable it on cellular data, any device on that network could query your phone. Keep the interface= line to limit exposure.
  • Query logging – The log file contains every hostname queried by your clients. If you share the device with others, consider disabling log-queries or regularly truncating the log.
  • Rooted devices – Using iptables redirection requires root. Granting root access to Termux gives the app full control over the device, so only do this on a device you trust.
  • Public Wi‑Fi – Never enable the hotspot while connected to a public Wi‑Fi network, as it can unintentionally bridge traffic between networks.

Recap – What You Have Achieved

By the end of this tutorial you should be able to:

  • Install Termux and dnsmasq on an Android phone without rooting.
  • Configure dnsmasq to act as a lightweight DNS resolver that forwards to upstream servers.
  • Run dnsmasq as a background service that survives screen lock.
  • Direct other devices on the same hotspot to use the phone’s DNS server.
  • Implement simple ad‑blocking or custom host overrides.
  • Troubleshoot common startup and connectivity problems.

This capability turns a regular Android phone into a handy network tool for developers, privacy‑conscious users, and anyone who wants fine‑grained control over DNS on a small LAN.

User Comments (0)

Add Comment
We'll never share your email with anyone else.