Turning on encrypted DNS, and what it hides
Every time your phone visits a site it first asks a DNS server for the address. Traditionally that question travels in plain text, so your network operator, and anyone on the same WiFi, can read a list of everything you look up. Android has supported encrypting it since version 9, under the name Private DNS, and it is off unless you turn it on.
Turning it on
- Open network settings Settings, Network and internet, then Private DNS. Some manufacturers bury it one level deeper under Advanced.
- Choose the hostname option Not Automatic, which only encrypts if your current DNS server happens to support it.
- Enter a provider's hostname For example dns.adguard-dns.com for filtering, or one.one.one.one for a plain resolver.
- Save and test Open a couple of sites. If nothing loads, the hostname is wrong, and clearing the field restores the previous behaviour immediately.
Реклама
Choosing a provider
| Provider hostname | What it does |
|---|---|
| one.one.one.one | Plain fast resolver, no filtering |
| dns.adguard-dns.com | Blocks advertising and tracking domains system-wide |
| dns.quad9.net | Blocks known malicious domains, run by a nonprofit |
| dns.google | Plain resolver, no filtering |
| Your own resolver | Whatever you configure, and nobody else sees it |
The filtering providers are the interesting ones on a phone, because they block advertising inside apps as well as in the browser, which nothing else does without a local VPN slot.
What it does and does not hide
- Which domains you look up
- That lookup from anyone on the same WiFi
- Lookups from your network operator
- The IP addresses you connect to
- The server name in the connection itself, on most sites
- Anything an app sends after connecting
- Your identity to sites you sign into
So it is a real improvement and not a cloak. An observer can still see that you connected to a particular address, which usually implies the site. What changes is that the complete, easily readable list of everything you looked up is no longer sitting in plain text on the network.
Two things to know
Captive portals, the sign-in pages on hotel and airport WiFi, sometimes break with strict Private DNS, because they depend on intercepting lookups. If a network will not let you sign in, switch Private DNS off, connect, and switch it back on.
Filtering resolvers occasionally block something you wanted. If a specific app or site stops working right after you turn this on, that is the first thing to test, by temporarily switching to a plain resolver.
Settings, Private DNS, hostname of a provider you trust. It covers every app and takes two minutes.
Frequently asked questions
Does Private DNS slow the phone down?
Marginally at worst, and a good resolver is often faster than a network operator's default.
Is it the same as a VPN?
No. It encrypts lookups only. A VPN moves all of your traffic to a different operator.
Does it block ads?
With a filtering provider, a good proportion of them, including inside apps. It cannot block advertising served from the same domain as the content.
Read next
This is not a rivalry. Each does something the other cannot.
You are not buying encryption. You are buying an operator whose income does not depend on you.
For a plain ZIP either works. For a split, password-protected archive, only one does.

