Every time your phone looks up a website, it asks a DNS server to translate the domain name into an IP address. By default Android uses the DNS servers supplied by your carrier or Wi‑Fi network, which are often unencrypted and can be intercepted or used to serve unwanted ads. Enabling Private DNS (also known as DNS‑over‑TLS or DNS‑over‑HTTPS) encrypts those queries, hides them from prying eyes, and lets you pick a provider that blocks known ad‑serving domains.
| Provider | Hostname (DoT/DoH) | Notes |
|---|---|---|
| Cloudflare | 1dot1dot1dot1.cloudflare-dns.com | Fast, privacy‑focused, optional family mode blocks adult content. |
dns.google | Reliable, no built‑in ad block. | |
| Quad9 | dns.quad9.net | Blocks known malware domains. |
| AdGuard DNS | dns.adguard.com | Provides ad‑blocking out of the box. |
Tap the gear icon from the app drawer or pull‑down notification shade and select Settings. The exact wording may vary – on Samsung devices it appears as Connections → More connection settings.
On most Pixel‑style Android builds the path is Settings > Network & internet. On some OEM skins it may be called Connections or Wi‑Fi & internet. Look for a section that groups Wi‑Fi, mobile data, and VPN.
Scroll to the bottom of the screen and tap Advanced. If you don’t see this option, the device may already expose the Private DNS entry directly in the main screen.
You will see three options:
Type the hostname you selected earlier (e.g., 1dot1dot1dot1.cloudflare-dns.com) and tap Save. Android will immediately test the connection. If the test succeeds you’ll see a small toast that reads “Private DNS mode set to hostname”.
Open a browser and visit https://1.1.1.1/help (or the equivalent test page for your provider). The page should report that DNS‑over‑TLS is active. You can also run a DNS‑leak test at dnsleaktest.com – the displayed resolver should match the hostname you entered.
If your device runs Android 8 or a heavily customized OEM skin that hides Private DNS, a lightweight DoH client can fill the gap. Intra by Jigsaw is a popular, no‑root solution.
Search for Intra – DNS over HTTPS, install, and open the app.
The app ships with Cloudflare, Google, Quad9, and a custom entry field. Select the one you prefer or paste a custom hostname.
Tap the toggle labeled Enable. Intra creates a local VPN interface that routes all DNS queries through the chosen DoH endpoint, effectively giving you Private DNS without modifying system settings.
As with the built‑in method, visit the provider’s help page or run a DNS‑leak test. The result should show the DoH provider you selected.
Some DNS providers maintain blocklists that resolve known ad‑serving domains to 0.0.0.0 or NXDOMAIN. When your phone asks for ads.example.com, the provider simply says “no such address”, preventing the app or browser from loading the ad. This works at the network level, so it affects all apps without needing per‑app ad‑blockers.
For power users who want granular control, you can use dnscrypt-proxy on a rooted device or via Termux to run a local DNS resolver that merges a custom hosts file with the upstream DoH server. This approach lets you add personal block entries (e.g., exampletracker.com) while still benefiting from encrypted DNS. The setup is beyond the scope of this article, but the principle is the same: all DNS queries are encrypted and filtered locally before leaving the phone.
If you encounter persistent connectivity issues, captive‑portal prompts that never appear, or an app that refuses to start, switch the Private DNS setting back to Off or Automatic. Remember the original DNS configuration (often “Automatic”) so you can restore it quickly.
Configuring Android’s Private DNS gives you a simple, no‑root way to encrypt your DNS traffic and optionally block ads at the network level. By following the steps above you can choose a reputable provider, verify the connection, and troubleshoot the most common hiccups. The result is a more private browsing experience that works across all apps on your device.









