How to Set Up Private DNS on Android
Every website and app you open starts with a question your phone asks in the background: “what is the IP address of this server?” The system that answers is called DNS (Domain Name System) — the internet’s phone book. By default, your phone uses whatever DNS your Wi-Fi router or mobile carrier provides, and those DNS queries travel in plain text. That means your internet provider — and anyone on the same network — can see every site you look up.
Android has a built-in feature called Private DNS that encrypts these lookups using a standard called DNS-over-TLS. It takes about a minute to turn on, works on both Wi-Fi and mobile data, and can also block ads and trackers if you point it at a filtering DNS provider. This guide explains what Private DNS does, shows you exactly where the setting lives on Pixel, Samsung, and Xiaomi phones, lists the real DNS hostnames you can use, and helps you fix the problems that sometimes appear after switching.
What Private DNS Actually Does (and Doesn’t Do)
When you type a web address, your phone sends a DNS query — “where is example.com?” — and gets back an IP address like 93.184.216.34. Traditionally, that question travels unencrypted (plain DNS, port 53). On an open coffee-shop Wi-Fi network, anyone with basic tools can see the list of domains you request. Your mobile carrier sees them too, by default.
Private DNS changes the transport, not the destination:
- Your queries are encrypted with TLS (the same encryption that protects HTTPS websites) before they leave your phone.
- They go to a DNS provider you choose instead of your carrier’s or router’s default.
- The provider still sees your queries — it has to, to answer them — so choosing a provider you trust matters.
What Private DNS does not do:
- It is not a VPN. Your carrier still sees which IP addresses you connect to, and websites still see your real IP. If you need location privacy or full traffic encryption, use a VPN in addition to Private DNS.
- It does not hide the sites you visit from your employer on a managed work phone — device-management software can see activity other ways.
- It does not encrypt the content of your browsing. That is HTTPS’s job (look for the padlock / “https://” in your browser).
Think of it this way: plain DNS is like mailing a postcard — anyone handling it can read the address. Private DNS is like putting that postcard in a sealed envelope addressed to a courier you chose. The courier still reads the address (they have to deliver it), but everyone in between cannot.
Why People Turn It On: The Three Real Benefits
- Privacy from snoops on the network. On public Wi-Fi, encrypted DNS stops casual eavesdropping on which domains you look up.
- A different DNS provider. Carrier DNS is sometimes slow, sometimes hijacked to show you ads or “helpful” error pages. Switching to Cloudflare, Google, or Quad9 can be faster and cleaner.
- System-wide ad and tracker blocking. This is the benefit most people notice first. Providers like AdGuard DNS filter out known ad and tracking domains at the DNS level — before anything downloads. Ads inside apps, banner ads in browsers, and many trackers simply stop loading, on every app on your phone, with no ad-blocker app running.
That third benefit is why this guide exists for most readers. Private DNS with a filtering provider is the simplest, battery-friendliest ad blocker on Android — no VPN slot used, no extra app running, no root required.
Where the Private DNS Setting Lives
Private DNS is available on Android 9 (Pie) and newer. The setting is in the same logical place on every brand, but the path differs slightly.
On Google Pixel and stock Android
- Open Settings.
- Tap Network & internet.
- Tap Private DNS.
- You will see three options: Off, Automatic, and Private DNS provider hostname. Select Private DNS provider hostname and type the hostname of the provider you want (the list below).
- Tap Save. The change applies immediately — no restart needed.
On Samsung Galaxy
- Open Settings.
- Tap Connections.
- Tap More connection settings.
- Tap Private DNS.
- Choose Private DNS provider hostname, enter the hostname, and tap Save.
On Xiaomi / Redmi / POCO
- Open Settings.
- Tap Connection & sharing (on older MIUI it is inside SIM cards & mobile networks > Advanced — if you cannot find it, use the Settings search bar and type “Private DNS”).
- Tap Private DNS, select Private DNS provider hostname, enter the hostname, and save.
About “Automatic”: the Automatic option uses encrypted DNS only if your network advertises support for it — most networks do not, so Automatic usually behaves like Off. If you want the benefits described in this guide, enter a provider hostname explicitly.
Important formatting rule: enter only the hostname — for example dns.adguard.com. Do not enter an IP address like 94.140.14.14, and do not add https:// in front. Android will reject anything that is not a valid hostname, and the setting will silently fail.
Real DNS Providers You Can Use (With Exact Hostnames)
Here are the providers people actually use, with the exact hostname to type. All of these support DNS-over-TLS on Android’s Private DNS.
AdGuard DNS — blocks ads and trackers (most popular choice)
- Default (blocks ads, trackers): dns.adguard.com
- Family protection (blocks ads + adult content): dns-family.adguard.com
- No filtering (plain fast DNS): dns-unfiltered.adguard.com
AdGuard’s default servers block known advertising, tracking, and phishing domains. This is the hostname to use if your goal is system-wide ad blocking. AdGuard also publishes its filtering policy publicly and is based outside the major surveillance alliances, which is part of why privacy-minded users pick it.
Cloudflare — fast and privacy-focused
- Standard: one.one.one.one
- Malware blocking: security.cloudflare-dns.com
- Malware + adult content blocking: family.cloudflare-dns.com
Cloudflare (1.1.1.1) is consistently among the fastest DNS providers worldwide and promises not to sell query data, with independent audits of that claim. Note that the standard one.one.one.one hostname does not block ads — use it for speed and privacy, not ad blocking.
Google Public DNS — simple and reliable
- Hostname: dns.google
Google’s DNS is fast and extremely reliable. The privacy trade-off is obvious: you are handing your query log to Google, which already has plenty of your data. Choose it for reliability, not for privacy from Google.
Quad9 — security-focused
- Hostname: dns.quad9.net
Quad9 blocks known malicious domains (malware, phishing) using threat intelligence feeds, and is run by a nonprofit. A good middle ground if you want security filtering without full ad blocking.
Which one should you pick?
- Want ad blocking with zero apps? dns.adguard.com
- Want maximum speed and a privacy promise? one.one.one.one
- Want malware protection? dns.quad9.net or security.cloudflare-dns.com
- Just want it to work reliably? dns.google
You can switch providers any time by returning to the same setting and typing a different hostname. Try one for a few days and see how it feels.
How to Verify Private DNS Is Working
After saving the hostname, confirm it is actually active:
- Go back to Settings > Network & internet > Private DNS (or your brand’s path) and confirm your hostname is still selected. If the setting reverted to Off, the hostname was invalid — retype it carefully.
- Test ad blocking (if you chose AdGuard): open your browser and visit a site that normally shows banner ads. The ad slots should be empty or gone. Also open an ad-supported free app — in-app banner ads should disappear.
- Check for the “couldn’t connect” symptom: if websites suddenly fail to load entirely, Private DNS may be failing (see troubleshooting). The quickest test is to temporarily set it back to Off — if sites load again, the problem is the Private DNS connection, not your internet.
- Some providers offer a test page: AdGuard has a test page that confirms whether you are using their DNS (search “AdGuard DNS test page” — it checks your connection and reports which AdGuard server answered).
Give it 10–15 minutes of normal use before judging. DNS results are cached, so the full effect (especially ad blocking) appears gradually as cached entries expire.
What Changes in Daily Use (and What Breaks)
Most of the time, nothing visibly changes except fewer ads. But Private DNS can interact with a few things:
- Captive portals (hotel / airport / cafe Wi-Fi login pages). This is the most common hiccup. The login page needs plain DNS to redirect you, but your phone is encrypting DNS to an outside server. If a Wi-Fi login page will not load, temporarily set Private DNS to Off, complete the login, then turn it back on. Some Android versions handle this automatically; many do not.
- Parental-control or school/work network filtering. If your home router or workplace filters DNS to block certain sites, Private DNS bypasses that filtering (your queries go to your chosen provider instead). On a child’s phone, that may defeat parental controls — something to be aware of, not a bug.
- Carrier-specific services. A few carriers run services that depend on their own DNS (visual voicemail on some networks, carrier billing pages). If something carrier-specific stops working, test with Private DNS off.
- VPN apps. Private DNS and VPNs can coexist, but behavior varies: some VPN apps route DNS through the VPN tunnel (ignoring Private DNS), others let Private DNS keep working. If you run a VPN and ads reappear, your VPN is handling DNS — check the VPN app’s own DNS or ad-blocking settings.
- Banking apps. Very occasionally, a banking or payment app refuses to work with third-party DNS. This is rare, but if one specific app fails while everything else works, Private DNS is worth testing as the cause.
Battery, Speed, and Data Impact
- Battery: negligible. DNS-over-TLS adds a tiny amount of encryption overhead per lookup — far less than keeping a VPN app or ad-blocker app running. You will not notice it in battery stats.
- Speed: often slightly faster, because providers like Cloudflare and Google answer queries faster than many carrier DNS servers. The TLS handshake adds a few milliseconds on the first query to a new domain, then connection reuse keeps it fast.
- Mobile data: no meaningful difference. DNS queries are tiny.
Troubleshooting
- “Websites won’t load after I turned it on.” The hostname is probably mistyped, or the provider is temporarily unreachable. Go back to the Private DNS setting, retype the hostname exactly (no spaces, no https://, no IP address), and save. If it still fails, try a different provider’s hostname to isolate the problem.
- “The setting keeps reverting to Off.” Android rejects invalid hostnames by reverting. Double-check every character — dns.adguard.com is easy to mistype as dns.adgaurd.com. Also confirm you are on Android 9 or newer (Settings > About phone > Android version).
- “Ads are still showing.” First, wait 15 minutes for DNS caches to clear, then fully close and reopen the app or browser tab. Some apps (notably YouTube and some social apps) serve ads from the same domains as their content, which DNS filtering cannot separate — DNS blocking removes banner and pop-up ads, not every ad format. Also check you did not leave a VPN running that overrides DNS.
- “Hotel Wi-Fi login page won’t open.” Set Private DNS to Off, join the Wi-Fi and complete the login, then re-enable it. Consider this a routine travel step.
- “My carrier’s visual voicemail broke.” Some carriers tie voicemail to their DNS. Either leave Private DNS off, or switch to a provider and test voicemail before committing.
- “Some sites load slowly now.” Your chosen provider may be slower from your location than your carrier’s DNS. Try one.one.one.one (Cloudflare optimizes aggressively for speed) or dns.google and compare.
Private DNS vs. a VPN vs. an Ad-Blocker App
People often ask which one they need. They solve different problems:
- Private DNS: encrypts DNS lookups, optionally filters ads/trackers at the DNS level. Free, built-in, negligible battery cost. Does not hide your IP or location.
- VPN: encrypts all traffic and hides your IP/location from websites. Costs battery, usually costs money, and the VPN provider sees everything instead of your carrier.
- Ad-blocker app: filters ads in browsers (and sometimes apps) with fine-grained rules. More powerful against tricky ad formats than DNS filtering, but uses more battery and often occupies Android’s single VPN slot.
A sensible everyday setup for most people: Private DNS with AdGuard for always-on lightweight protection, plus a browser with a built-in ad blocker (like Brave, or Firefox with uBlock Origin) for the ads DNS cannot catch. Add a VPN only when you specifically need location privacy or untrusted-network protection beyond DNS.
Quick Checklist
- Confirm your phone runs Android 9 or newer.
- Open the Private DNS setting via your brand’s path (Pixel: Settings > Network & internet > Private DNS; Samsung: Settings > Connections > More connection settings > Private DNS).
- Select Private DNS provider hostname and type a real hostname — dns.adguard.com for ad blocking, one.one.one.one for speed, dns.quad9.net for security.
- Remember: hostname only — no IP addresses, no https://.
- Verify with a few minutes of browsing and an ad-heavy test page.
- Know the captive-portal trick: set it to Off to log in to hotel Wi-Fi, then turn it back on.
One minute of setup, no app to install, no battery drain — Private DNS is one of the best effort-to-reward tweaks on Android.

Facebook comments