How to Set Up Private DNS on Android for Encrypted DNS and Ad Blocking

10 min read Learn how to enable Android's Private DNS feature to encrypt your DNS traffic and block ads without rooting your device. Step‑by‑step guide with troubleshooting tips. October 02, 2026 10:30 How to Set Up Private DNS on Android for Encrypted DNS and Ad Blocking (No Root)

Every time your phone looks up a website, it asks a DNS server to translate the domain name into an IP address. By default Android uses the DNS servers supplied by your carrier or Wi‑Fi network, which are often unencrypted and can be intercepted or used to serve unwanted ads. Enabling Private DNS (also known as DNS‑over‑TLS or DNS‑over‑HTTPS) encrypts those queries, hides them from prying eyes, and lets you pick a provider that blocks known ad‑serving domains.

Before you start

  • Android version: Private DNS is built‑in from Android 9 (Pie) onward. Devices on Android 8 can still use a third‑party DoH app.
  • Internet connection: Make sure you are connected to Wi‑Fi or mobile data that can reach the DNS provider you intend to use.
  • Choose a DNS provider: You need a provider that supports DoT/DoH and, optionally, offers built‑in ad‑blocking. Common choices are:
    ProviderHostname (DoT/DoH)Notes
    Cloudflare1dot1dot1dot1.cloudflare-dns.comFast, privacy‑focused, optional family mode blocks adult content.
    Googledns.googleReliable, no built‑in ad block.
    Quad9dns.quad9.netBlocks known malware domains.
    AdGuard DNSdns.adguard.comProvides ad‑blocking out of the box.
  • Backup your network settings: If you rely on a corporate or school Wi‑Fi that uses custom DNS, note the original settings so you can revert if needed.

Step‑by‑step: Enabling Private DNS on stock Android (9+)

1. Open the Settings app

Tap the gear icon from the app drawer or pull‑down notification shade and select Settings. The exact wording may vary – on Samsung devices it appears as Connections → More connection settings.

2. Navigate to Network & internet

On most Pixel‑style Android builds the path is Settings > Network & internet. On some OEM skins it may be called Connections or Wi‑Fi & internet. Look for a section that groups Wi‑Fi, mobile data, and VPN.

3. Open Advanced settings

Scroll to the bottom of the screen and tap Advanced. If you don’t see this option, the device may already expose the Private DNS entry directly in the main screen.

4. Select Private DNS

You will see three options:

  • Off – default, unencrypted DNS.
  • Automatic – lets the system use DNS‑over‑TLS if the network advertises it.
  • Private DNS provider hostname – manual entry.
Choose Private DNS provider hostname.

5. Enter the provider hostname

Type the hostname you selected earlier (e.g., 1dot1dot1dot1.cloudflare-dns.com) and tap Save. Android will immediately test the connection. If the test succeeds you’ll see a small toast that reads “Private DNS mode set to hostname”.

6. Verify the configuration

Open a browser and visit https://1.1.1.1/help (or the equivalent test page for your provider). The page should report that DNS‑over‑TLS is active. You can also run a DNS‑leak test at dnsleaktest.com – the displayed resolver should match the hostname you entered.

Alternative: Using a DoH app on Android 8 or when the built‑in option is hidden

If your device runs Android 8 or a heavily customized OEM skin that hides Private DNS, a lightweight DoH client can fill the gap. Intra by Jigsaw is a popular, no‑root solution.

1. Install Intra from the Play Store

Search for Intra – DNS over HTTPS, install, and open the app.

2. Choose a DNS provider inside the app

The app ships with Cloudflare, Google, Quad9, and a custom entry field. Select the one you prefer or paste a custom hostname.

3. Enable the system‑wide VPN mode

Tap the toggle labeled Enable. Intra creates a local VPN interface that routes all DNS queries through the chosen DoH endpoint, effectively giving you Private DNS without modifying system settings.

4. Test the setup

As with the built‑in method, visit the provider’s help page or run a DNS‑leak test. The result should show the DoH provider you selected.

Why Private DNS also blocks ads

Some DNS providers maintain blocklists that resolve known ad‑serving domains to 0.0.0.0 or NXDOMAIN. When your phone asks for ads.example.com, the provider simply says “no such address”, preventing the app or browser from loading the ad. This works at the network level, so it affects all apps without needing per‑app ad‑blockers.

Common pitfalls and troubleshooting

  • “Private DNS failed” toast: The hostname may be mistyped, or the provider’s DoT server is unreachable from your network. Double‑check the spelling and try a different network (e.g., mobile data vs. home Wi‑Fi).
  • No internet after enabling Private DNS: Some captive‑portal Wi‑Fi networks (airports, hotels) intercept DNS traffic. Disable Private DNS temporarily, connect to the portal, then re‑enable it.
  • VPN conflicts: If you run a VPN app, it may override Private DNS. Most VPNs use their own DNS; you can either let the VPN handle DNS or disable the VPN while testing Private DNS.
  • App‑specific DNS failures: Certain apps (e.g., banking apps) perform DNS pinning and may reject TLS‑wrapped DNS. If an app stops working, add an exception by switching Private DNS back to Automatic for that network.

Advanced tip: Combine Private DNS with a hosts‑file blocker

For power users who want granular control, you can use dnscrypt-proxy on a rooted device or via Termux to run a local DNS resolver that merges a custom hosts file with the upstream DoH server. This approach lets you add personal block entries (e.g., exampletracker.com) while still benefiting from encrypted DNS. The setup is beyond the scope of this article, but the principle is the same: all DNS queries are encrypted and filtered locally before leaving the phone.

What to expect after enabling Private DNS

  • Encrypted DNS queries: Your DNS traffic is now wrapped in TLS, making it unreadable to your ISP or anyone on the same Wi‑Fi.
  • Potential ad reduction: If you chose a provider with an ad‑blocking list, you’ll notice fewer banner ads in browsers and some apps.
  • Minor latency change: DNS lookups may be slightly slower or faster depending on the provider’s server proximity.

When to revert the change

If you encounter persistent connectivity issues, captive‑portal prompts that never appear, or an app that refuses to start, switch the Private DNS setting back to Off or Automatic. Remember the original DNS configuration (often “Automatic”) so you can restore it quickly.

Summary

Configuring Android’s Private DNS gives you a simple, no‑root way to encrypt your DNS traffic and optionally block ads at the network level. By following the steps above you can choose a reputable provider, verify the connection, and troubleshoot the most common hiccups. The result is a more private browsing experience that works across all apps on your device.

User Comments (0)

Add Comment
We'll never share your email with anyone else.