PART 05 · NETWORK · DNS · 🟡

Encrypted DNS & Cloudflare

DNS is the directory that turns a site name (example.com) into a machine address. The catch: by default your internet provider runs that directory, so it sees every site you visit, even when the page is HTTPS. Encrypting your DNS takes that list back from your ISP. It’s a quiet setting but one of the most effective.

Quad9

🟢 BeginnerMalware-blocking🇨🇭 non-profitFree

What it's for

An encrypted, Swiss, non-profit DNS resolver that also blocks known malicious domains.

Why it matters

Swiss jurisdiction, no retention of your IP address, protection against phishing and malware. An excellent “set and forget” choice.

For whom & when

Everyone, especially those who want simplicity and a good jurisdiction.

Install & use
  1. On Android: Settings > Network > Private DNS > enter dns.quad9.net.

  2. On iPhone/Mac: install the DoH profile from quad9.net. On PC: set DNS-over-HTTPS in the browser or the system.

Mullvad DNS · NextDNS

🟡 IntermediateNetwork filteringFree + paid plan

What it's for

Two encrypted resolvers that also block ads and trackers for the whole device.

Why it matters

Mullvad DNS (Sweden, no-log) is free and offers blocklists. NextDNS is highly customisable, with a dashboard and per-device profiles, but it’s US-based and logs by default (turn it off in settings).

For whom & when

Those who want system-wide ad-blocking without installing a per-browser extension.

Install & use
  1. Mullvad DNS: use the address shown at mullvad.net/help/dns as your private DNS (same method as Quad9).

  2. NextDNS: create a profile at nextdns.io, disable logging, then apply the config to your devices.

Cloudflare 1.1.1.1 (with nuance)

🟢 BeginnerFast but centralised🇺🇸Free

What it's for

Cloudflare’s 1.1.1.1 encrypted DNS and WARP app: fast, free, and a real upgrade over your ISP’s resolver.

Why it matters

It’s useful, with an audited no-logging pledge. But be clear-eyed: Cloudflare already sits in front of a huge share of the web (as a technical middleman, it can see plaintext traffic to those sites). Routing your DNS there too means concentrating even more of your footprint with one US company under US law.

For whom & when

Fine for everyday use and malware-blocking (1.1.1.1 for Families). Avoid or diversify for sensitive use: prefer Quad9 or Mullvad DNS instead.

Pi-hole · AdGuard Home

🔴 AdvancedWhole-network blocking🌍 · open-sourceFree

What it's for

An ad and tracker blocker that protects your whole network at once, installed on a small computer like a Raspberry Pi.

Why it matters

Where uBlock Origin protects one browser, Pi-hole filters every device in the home, including those where you can’t install an extension: phones, smart TVs, connected objects. Ads and trackers are blocked at the DNS level, before they even load. AdGuard Home is an alternative with a more modern interface.

For whom & when

Households that want to clean up all their devices at once, and who have (or want) a Raspberry Pi or small server.

Install & use
  1. On a Raspberry Pi (or a container), run Pi-hole’s official installer.
  2. In your router’s settings, set the Pi-hole’s address as the DNS server.
  3. From now on, every device on your network is filtered automatically.

Not sure where to start? Take the 12-question quiz →