DNS resolver registry · Mullvad VPN AB

Mullvad DNS DNS servers

Mullvad DNS is run by Mullvad VPN AB and offers 6 service variants with different filtering, reachable over DoT, DoH. Every address and endpoint below is taken from the operator's documentation; the behaviour is what we measured on 2026-09-24.
194.242.2.2
primary address
12
addresses in 6 variants
Validates
DNSSEC in our test
Encrypted only
no public plain DNS

Addresses

Mullvad DNS DNS addresses by variant

The operator documents this service over DNS-over-HTTPS and DNS-over-TLS, and plain DNS on port 53 did not answer our probe. Use the encrypted endpoints; the addresses are what those hostnames point to.

Mullvad dns

None

IPv4
194.242.2.2
IPv6
2a07:e340::2
DoH
https://dns.mullvad.net/dns-query
DoT
dns.mullvad.net

Mullvad adblock

Ads and trackers

IPv4
194.242.2.3
IPv6
2a07:e340::3
DoH
https://adblock.dns.mullvad.net/dns-query
DoT
adblock.dns.mullvad.net

Mullvad base

Ads, trackers and malware

IPv4
194.242.2.4
IPv6
2a07:e340::4
DoH
https://base.dns.mullvad.net/dns-query
DoT
base.dns.mullvad.net

Mullvad extended

Ads, trackers, malware and social media

IPv4
194.242.2.5
IPv6
2a07:e340::5
DoH
https://extended.dns.mullvad.net/dns-query
DoT
extended.dns.mullvad.net

Mullvad family

Ads, trackers, malware, adult content and gambling

IPv4
194.242.2.6
IPv6
2a07:e340::6
DoH
https://family.dns.mullvad.net/dns-query
DoT
family.dns.mullvad.net

Mullvad all

Ads, trackers, malware, adult content, gambling and social media

IPv4
194.242.2.9
IPv6
2a07:e340::9
DoH
https://all.dns.mullvad.net/dns-query
DoT
all.dns.mullvad.net

Measured

What we observed

Measured 2026-09-24 from one vantage point, three rounds per address, majority result. Anycast resolvers can behave differently from other networks. How we test

DNSSEC validation Validates

Returned SERVFAIL for dnssec-failed.org, rhybar.cz and badsig.go.dnscheck.tools on every address that answered, while resolving example.com. Tested over the encrypted endpoint.

Client subnet (ECS)

Not measured: this probe used plain DNS, which the operator does not offer publicly.

Plain DNS and NXDOMAIN

The operator documents encrypted service only.

Encrypted endpoints

  • DoH https://dns.mullvad.net/dns-queryAnswered
  • DoH https://adblock.dns.mullvad.net/dns-queryAnswered
  • DoH https://base.dns.mullvad.net/dns-queryAnswered
  • DoH https://extended.dns.mullvad.net/dns-queryAnswered
  • DoH https://family.dns.mullvad.net/dns-queryAnswered
  • DoH https://all.dns.mullvad.net/dns-queryAnswered
  • DoT dns.mullvad.netAnswered
  • DoT adblock.dns.mullvad.netAnswered
  • DoT base.dns.mullvad.netAnswered
  • DoT extended.dns.mullvad.netAnswered
  • DoT family.dns.mullvad.netAnswered
  • DoT all.dns.mullvad.netAnswered

Networks

Which networks carry it

The announcing network comes from RIPEstat routing data for each documented address. The query network is where the resolver sent its own lookups during our probe, which a DNS leak test reports.

Announcing the service addresses

  • AS57138 DOH-MULLVAD LOCIX LIMITED

Queried from, in our probe

Not published: encrypted-only service was not part of this test.

In the operator's words

Operator statements

Quoted from the operator's pages and checked word for word. We have not audited these practices.
“Mullvad VPN AB Box 53049 400 14 Gothenburg Sweden”
mullvad.net
“A limited DNS resolver is listening on port UDP/TCP 53 only to aid with resolving hostnames related to this service”
mullvad.net

Check it

Confirm your device is using Mullvad DNS

Changing a DNS setting does not guarantee your lookups reach that resolver: a VPN, a browser's own secure DNS or a proxy can send them elsewhere. Our DNS leak test shows which resolvers actually received your queries.

From a terminal

# Which address did the resolver query from?
dig +short whoami.akamai.net @194.242.2.2

# Does it pass your subnet on (ECS)?
dig +short TXT o-o.myaddr.l.google.com @194.242.2.2

# Does it validate DNSSEC? SERVFAIL means yes
dig dnssec-failed.org @194.242.2.2

Behind a proxy

With an HTTP proxy, or a client set to socks5h://, the proxy side resolves hostnames, so your own resolver setting does not apply to that traffic. With socks5:// in curl or Python requests, your device resolves names first. The SOCKS5 vs SOCKS5h guide shows how to check which one you have.

Questions

Mullvad DNS questions

What are Mullvad DNS's DNS server addresses?

Mullvad dns: 194.242.2.2, 2a07:e340::2. Mullvad adblock: 194.242.2.3, 2a07:e340::3. Mullvad base: 194.242.2.4, 2a07:e340::4. Mullvad extended: 194.242.2.5, 2a07:e340::5. Mullvad family: 194.242.2.6, 2a07:e340::6. Mullvad all: 194.242.2.9, 2a07:e340::9.

Does Mullvad DNS validate DNSSEC?

Yes. On 2026-09-24 every Mullvad DNS address that answered returned SERVFAIL for three deliberately mis-signed domains while resolving ordinary names.

Does Mullvad DNS support DNS over HTTPS or DNS over TLS?

DoH: https://dns.mullvad.net/dns-query, https://adblock.dns.mullvad.net/dns-query, https://base.dns.mullvad.net/dns-query, https://extended.dns.mullvad.net/dns-query, https://family.dns.mullvad.net/dns-query, https://all.dns.mullvad.net/dns-query. DoT: dns.mullvad.net, adblock.dns.mullvad.net, base.dns.mullvad.net, extended.dns.mullvad.net, family.dns.mullvad.net, all.dns.mullvad.net. 12 of 12 answered our test query on 2026-09-24.

How can I check that I am using Mullvad DNS?

Run a DNS leak test and compare the network it reports. On the command line, dig +short whoami.akamai.net @194.242.2.2 returns the address the resolver used to query Akamai.

Sources

Sources and dates

Documentation checked 2026-09-24. Measured 2026-09-24. Registry reviewed 2026-09-24.