Most Android users never think about DNS – the service that translates human‑readable hostnames into IP addresses. Having a local DNS server on your phone can be useful for several reasons:
Because the solution uses only free, open‑source tools (Termux and dnsmasq) it works on the majority of Android devices, regardless of manufacturer or carrier.
Prerequisites
If you cannot or do not want to root the phone, the tutorial shows how to run dnsmasq on an unprivileged port (e.g., 5353) and how to point other devices to that port using IP:port syntax where the Android UI allows it.
pkg update && pkg upgrade -y
This ensures you have the latest apt metadata and security patches.
termux-api package (optional) – it lets you control Wi‑Fi and other hardware from the command line, which we will use later for keeping the service alive:
pkg install termux-api -y
After the upgrade, you should see a prompt similar to ~$. You are now ready to install dnsmasq.
pkg install dnsmasq -y
Termux pulls the pre‑compiled dnsmasq binary from its repository. The installation takes only a few seconds.
which dnsmasq
It should return /data/data/com.termux/files/usr/sbin/dnsmasq.
If the command fails, double‑check that you have a stable internet connection and that the pkg repositories are reachable.
dnsmasq reads a configuration file called dnsmasq.conf. We will create a minimal version that works for most testing scenarios.
mkdir -p ~/dnsmasq && cd ~/dnsmasq
nano and vim. We will use nano for readability:
nano dnsmasq.conf
# Basic dnsmasq configuration for Android
# Listen only on the Wi‑Fi interface (usually wlan0)
interface=wlan0
# Bind to the IP address assigned to wlan0
listen-address=192.168.4.1
# Use Google Public DNS as upstream resolver (you can change this)
server=8.8.8.8
server=8.8.4.4
# Cache size – 150 entries is more than enough for a small LAN
cache-size=150
# Optional: block known ad domains (example entry)
address=/ads.example.com/0.0.0.0
# Log queries to /data/data/com.termux/files/usr/var/log/dnsmasq.log
log-queries
log-facility=/data/data/com.termux/files/usr/var/log/dnsmasq.log
Explanation of the key lines:
interface=wlan0 – restricts dnsmasq to the Wi‑Fi NIC, preventing it from answering on cellular data.listen-address=192.168.4.1 – replace this IP with the one your phone obtains when you enable the hotspot (see Step 4). Using a static address simplifies client configuration.server=8.8.8.8 – forwards unknown queries to Google DNS. You can substitute any public resolver.address=/ads.example.com/0.0.0.0 – demonstrates how to block a domain. Add more address= lines to create a custom blocklist.log-queries and log-facility=… – enable simple logging for debugging.At this point you have a ready‑to‑run configuration. The next step is to make the Android Wi‑Fi interface reachable by other devices.
If you want other devices on the same network to use the DNS server, the easiest method is to enable Android’s built‑in hotspot feature. This creates a private Wi‑Fi network where your phone acts as the router.
When the hotspot starts, Android assigns the phone the IP address 192.168.43.1 by default. You can keep this address or change it by editing the system file /system/etc/dhcpcd/dhcpcd.conf – which requires root. For a non‑root workflow we will keep the default and adjust the config file accordingly.
Now the phone’s Wi‑Fi interface (often reported as wlan0) has a stable address that clients can reach.
Running dnsmasq is as simple as invoking the binary with the configuration file we created.
cd ~/dnsmasq
dnsmasq -C ./dnsmasq.conf -d
The -d flag tells dnsmasq to stay in the foreground and print log messages to the terminal.
dnsmasq: failed to bind DHCP server socket it means another service (perhaps Android’s built‑in DHCP server for the hotspot) is already using port 67. Since we are only using DNS, you can ignore the DHCP warning – dnsmasq will continue to serve DNS.termux-wake-lock to keep the CPU awake and nohup to detach the process:
termux-wake-lock && nohup dnsmasq -C ./dnsmasq.conf > /dev/null 2>&1 &
This command does three things:
/dev/null to keep the terminal clean.ps | grep dnsmasq
You should see a line containing dnsmasq -C ./dnsmasq.conf.
If the process exits immediately, check the log file you defined earlier (/data/data/com.termux/files/usr/var/log/dnsmasq.log) for clues.
Now that dnsmasq is listening on the phone’s hotspot IP (e.g., 192.168.43.1), you need to tell other devices to use it for DNS resolution.
192.168.43.10.192.168.43.1 (the phone).192.168.43.1.After reconnecting, the client will send DNS queries directly to your Android phone.
Some Android UI layers do not allow you to specify a custom DNS port. In that case you can run dnsmasq on a higher port (e.g., 5353) and use the iptables redirection trick. This method requires root because iptables manipulates the kernel’s network stack.
pkill dnsmasq
port=5353 to the config file, then restart:
echo "port=5353" >> dnsmasq.conf
nohup dnsmasq -C ./dnsmasq.conf > /dev/null 2>&1 &
su -c "iptables -t nat -A PREROUTING -p udp --dport 53 -j REDIRECT --to-port 5353"
su -c "iptables -t nat -A PREROUTING -p tcp --dport 53 -j REDIRECT --to-port 5353"
After this rule, any DNS request that reaches the phone on the standard port 53 is silently forwarded to dnsmasq listening on 5353.
Clients can now keep the default DNS settings (pointing to 192.168.43.1) and the redirection will handle the port conversion.
Testing confirms that the server is reachable and that custom mappings work.
nslookup app on Android.nslookup example.com 192.168.43.1
You should see an answer section with an IP address returned by Google’s resolver (since we forward to 8.8.8.8).
nslookup ads.example.com 192.168.43.1
The result should be 0.0.0.0, confirming the address= rule is active.
cat /data/data/com.termux/files/usr/var/log/dnsmasq.log | grep ads.example.com
If the client reports “timed out” or “server not reachable”, re‑verify the IP address of the hotspot, ensure the phone’s Wi‑Fi interface is still up, and confirm that the wake lock is active (run termux-wake-lock -s to see status).
Warning: Changing network settings can temporarily disconnect you from the internet. Keep a second device handy to restore connectivity if needed.
ping 192.168.43.1 from the client to ensure basic connectivity./data/data/com.termux/files/usr/var/log exists and is writable.
mkdir -p /data/data/com.termux/files/usr/var/log
termux-wake-lock command prevents the CPU from sleeping, but some OEMs still enforce aggressive task killing.termux:boot add‑on from the Play Store and add a script ~/.termux/boot/start-dnsmasq.sh that launches dnsmasq on boot. Also enable “Battery optimization” exclusion for Termux in Settings → Apps → Termux → Battery.
Replace the single address= line with a comprehensive blocklist. One popular source is the hosts file from StevenBlack. To import it:
# Download the hosts file (requires termux-api curl or wget)
curl -L https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts -o hosts.txt
# Convert to dnsmasq format (each line: address=/domain/0.0.0.0)
awk '/^0\.0\.0\.0/ {gsub(/^0\.0\.0\.0[ \t]+/, ""); print "address=/" $1 "/0.0.0.0"}' hosts.txt >> dnsmasq.conf
After updating the file, restart dnsmasq (kill the old process and start a new one). All devices connected to the hotspot will now benefit from the blocklist without installing any extra apps.
When testing a web service that is not yet publicly reachable, you can map a hostname to your development server’s IP:
address=/my‑test‑api.local/10.0.0.42
Clients that resolve my-test-api.local will connect directly to 10.0.0.42. This is handy for mobile‑first developers who need to test on real devices.
dnsmasq can also serve DHCP leases, but Android’s built‑in hotspot already runs a DHCP server on port 67. Running a second DHCP server on the same interface will cause conflicts. If you disable the hotspot’s DHCP (possible only on rooted devices or custom ROMs), you can enable it in dnsmasq by adding:
dhcp-range=192.168.43.50,192.168.43.150,12h
Because this tutorial targets non‑root users, we keep DHCP disabled and rely on Android’s native implementation.
If you no longer need the DNS server, follow these steps to shut it down cleanly.
pkill dnsmasq
termux-wake-unlock
rm -rf ~/dnsmasq
All log files are stored inside Termux’s private directory, so they disappear when you delete the folder.
interface= line to limit exposure.log-queries or regularly truncating the log.iptables redirection requires root. Granting root access to Termux gives the app full control over the device, so only do this on a device you trust.By the end of this tutorial you should be able to:
This capability turns a regular Android phone into a handy network tool for developers, privacy‑conscious users, and anyone who wants fine‑grained control over DNS on a small LAN.









