How to Set Up Private DNS on Android (Faster, Private Browsing in 2 Minutes)
Every time you open a website or an app on your phone, Android first asks a behind-the-scenes service to translate the site's name into a network address — that service is DNS. By default, your phone uses whatever DNS your internet provider assigns, and those requests travel unencrypted, meaning your ISP, your mobile carrier, or the operator of the coffee-shop Wi-Fi you're on can see and log every domain you visit. Android has a built-in fix for this called Private DNS, and it takes about two minutes to enable — no apps, no root, no VPN subscription. Here's what it does, which free provider to pick, and how to set it up on Samsung, Pixel, Xiaomi, and every other brand.

What Private DNS Actually Is
DNS (Domain Name System) is the internet's phone book: it converts readable names like auraz.online into IP addresses your phone can connect to. Normally these lookups are sent in plain text, and anyone between you and the internet — your ISP, your carrier, a public Wi-Fi operator — can read them. That's a detailed record of your browsing habits, even on HTTPS sites (where the page content is encrypted but the destination name is not).
Private DNS switches those lookups to DNS-over-TLS (DoT), an encrypted channel. The technical detail that matters: your lookups become unreadable to network snoopers, and you get to choose a reputable provider instead of being stuck with your ISP's servers. The feature has been built into Android since version 9 (2018), so virtually every phone sold in the last several years supports it.
What Changes on Your Phone Once You Enable It
- More privacy: your carrier and ISP can no longer see which websites and apps' domains you look up.
- Works everywhere: unlike per-Wi-Fi DNS settings, Private DNS applies to all connections — mobile data and every Wi-Fi network, including public hotspots.
- Often faster: big providers like Cloudflare and Google answer DNS queries from edge servers worldwide, frequently beating your ISP's slower, overloaded servers — pages can feel noticeably snappier.
- Optional ad/malware blocking: providers like AdGuard block ad, tracker, and malicious domains at the DNS level, system-wide — in every app, not just the browser, with zero battery cost beyond a lookup.
- Better reliability: if your ISP's DNS has an outage or censors certain sites, a third-party provider usually routes around it.
One honest caveat: Private DNS encrypts your lookups, not your traffic. Your ISP still sees the IP addresses you connect to (which it can often map to major services), and your carrier always knows your phone is online. It's a meaningful privacy upgrade, not a cloaking device — we'll compare it with a VPN later.
The Best Free Private DNS Providers (Pick One)
You enter the provider as a hostname (a domain name, not an IP address) in Settings. These are the four we recommend — all free, all reliable, each with a different strength:
1. Cloudflare — one.one.one.one (best all-rounder)
Cloudflare's 1.1.1.1 is one of the fastest public DNS services on the planet, and it commits to deleting all query logs within 24 hours. Enter one.one.one.one (their DNS-over-TLS hostname) and you get speed plus privacy, no filtering. Families may prefer one.one.one.one vs security.cloudflare-dns.com for malware blocking or family.cloudflare-dns.com for malware + adult-content filtering.
2. AdGuard — dns.adguard.com (best for ad blocking)
Want system-wide ad blocking without an app? Enter dns.adguard.com. AdGuard's default DNS filters ad and tracker domains across every app — noticeably fewer ads in games and free apps. It's the closest thing to a network-wide ad blocker you can get for free. (Some sites detect this and nag you; that's the trade-off.)
3. Google — dns.google (best compatibility)
Google Public DNS at dns.google is fast and essentially never down. Privacy purists note Google keeps anonymized logs, so pick Cloudflare if Google's data collection bothers you — but for sheer reliability and compatibility, Google's hostname is rock solid.
4. Quad9 — dns.quad9.net (best security focus)
Quad9 at dns.quad9.net blocks lookups to known malicious domains (phishing, malware, botnets) using threat intelligence from multiple security vendors. If your main worry is staying safe on sketchy links, Quad9 is the set-and-forget choice.
Our recommendation: most people should start with one.one.one.one (Cloudflare). If ads annoy you everywhere, switch to dns.adguard.com. Both are free forever and take seconds to change later.
How to Enable Private DNS (Universal Steps)
The setting lives in a slightly different place on each brand, but the pattern is identical:
- Open Settings.
- Find Private DNS — easiest is to type "Private DNS" into the Settings search bar at the top.
- Tap Private DNS and select Private DNS provider hostname.
- Type the hostname (e.g., one.one.one.one) — no http://, no spaces — and tap Save.
That's it. No reboot needed; the change takes effect immediately across all your connections.
Samsung Galaxy (One UI)
Settings > Connections > More connection settings > Private DNS. Choose "Private DNS provider hostname," enter your provider, and tap Save. On older One UI versions the path is Settings > Connections > More connection settings — if you can't find it, the Settings search bar gets you there instantly.
Google Pixel (Stock Android)
Settings > Network & internet > Private DNS. Pick "Private DNS provider hostname," enter the hostname, Save. Pixels apply it instantly — this is also where the toggle lives if you ever need to turn it off for a specific network.
Xiaomi / Redmi / Poco (HyperOS / MIUI)
Xiaomi buries it deeper: Settings > Connection & sharing > Private DNS (on older MIUI, check Settings > More connectivity options). Enter the hostname and confirm. Xiaomi phones also respect this on the second SIM's mobile data, which is handy for dual-SIM users.
OnePlus / Oppo / Realme
Settings > Mobile network (or Wi-Fi & network on older ColorOS) > Private DNS. Select "Designated private DNS," enter the hostname, and save. Oppo and Realme fold it under the same menu as Wi-Fi calling, so don't give up if you don't see it at first glance.
How to Verify It's Actually Working
Don't just trust the toggle — verify with a 30-second check:
- Cloudflare users: visit 1.1.1.1/help in your browser. The page reports whether you're connected to their resolver and whether DNS-over-TLS is active.
- AdGuard users: visit welcome.adguard.com — it confirms AdGuard DNS is filtering your traffic.
- Any provider: search "what is my DNS" and use an online DNS-leak test; the results should name your chosen provider, not your ISP or carrier.
- Quick sanity check: browse a few sites. If pages load normally, DNS is resolving — the setting failed loudly (no internet) rather than silently in almost every broken-config case.
When Private DNS Causes Problems (and How to Fix Them)
Private DNS is trouble-free 95% of the time, but these are the known exceptions:
- Captive portals (hotel/airport/mall Wi-Fi sign-in pages): the sign-in page may refuse to load because the portal expects the network's own DNS. Fix: temporarily set Private DNS to Off, complete the sign-in, then re-enable. Some Pixels handle this automatically; most phones don't.
- Work or school networks: corporate networks sometimes block encrypted DNS entirely (they need to filter traffic). If apps work on mobile data but not on office Wi-Fi, toggle Private DNS to Automatic or Off on that network.
- Banking apps complaining: rare, but a few banking and payment apps detect non-ISP DNS and refuse to connect. The fix is the same temporary toggle — or whitelist the app if your DNS provider offers per-app settings (AdGuard's app does).
- Typo in the hostname: if you mistype the hostname, you'll get "Couldn't connect" errors everywhere. Double-check spelling: one.one.one.one, dns.adguard.com, dns.google, dns.quad9.net.
- Parental controls on the router: encrypted DNS bypasses router-level filtering (that's partly the point), which can annoy whoever set the filters — and some routers fight back by blocking the connection. Expect this on shared family networks.
The beauty of the fix is always the same: Settings > Private DNS > Automatic restores the old behavior instantly, no reboot required.
Private DNS vs. VPN vs. Browser DNS: What's the Difference?
- Private DNS: encrypts only DNS lookups, system-wide, free, zero speed cost (often faster). Hides which domains you look up from your ISP but not your IP or traffic patterns.
- VPN: encrypts all traffic and hides your IP behind the VPN server. Stronger privacy, but costs money for a good one, adds latency, and drains more battery. A VPN usually applies its own DNS anyway.
- Browser DNS-over-HTTPS (Chrome's "Use secure DNS"): encrypts DNS but only inside Chrome — your apps, games, and other browsers still leak lookups. Android's Private DNS covers everything, so it's the better single switch.
Bottom line: enable Private DNS on every Android phone you own — it's free and strictly better than the default. Add a reputable VPN only if you also want IP masking or geo-unblocking. The two stack perfectly.
Related Guides
- Wi-Fi Won't Connect? 13 Fixes That Actually Work — for connection issues beyond DNS.
- Hidden Android Features You Probably Never Knew Existed — more built-in settings worth flipping.
- 11 Proven Ways to Increase Android Battery Life — because every setting tweak deserves a battery check.
FAQ
Is Private DNS on Android free?
Yes. It's a built-in Android feature (Android 9 and newer), and the popular providers — Cloudflare, Google, AdGuard, Quad9 — all offer free hostnames you enter directly in Settings. No app, no subscription.
Will Private DNS block ads?
With an ad-blocking provider like AdGuard (dns.adguard.com), yes — most in-app and in-browser ads are blocked at the DNS level, system-wide. Cloudflare's standard one.one.one.one does not block ads; their security.cloudflare-dns.com variant blocks malware, and family.cloudflare-dns.com adds adult-content filtering.
Does Private DNS work on mobile data as well as Wi-Fi?
Yes. Unlike Wi-Fi-only DNS settings, Android's Private DNS applies to every connection — mobile data and all Wi-Fi networks — so you get the same protection on hotel and public Wi-Fi as at home.
Can Private DNS cause internet problems?
Rarely, but it can: some captive portals (hotel/airport Wi-Fi sign-in pages), corporate networks, and strict parental-control routers conflict with encrypted DNS. If pages stop loading after enabling it, switch Private DNS back to Automatic temporarily.
Do I still need a VPN if I use Private DNS?
For many people, no — but they solve different problems. Private DNS encrypts only your domain lookups; a VPN encrypts all traffic and hides your IP. Use both if you want maximum privacy; they work together fine.