Mullvad DNS Shutdown:
What to Change Before
2 November 2026

TL;DR: Mullvad kills its public encrypted DNS servers on 2 November 2026 and funds Quad9 instead. Typed dns.mullvad.net into a router, a phone or a browser yourself? You have eight weeks to change it.
Never touched a DNS setting? Nothing to do. Mullvad Browser on its defaults gets moved across for you.
Then there is the bit nobody else has printed about the Mullvad DNS shutdown. Quad9 blocks malware and phishing, and that is the whole list. No ads, no adult content, no gambling filter. Anyone sitting on family.dns.mullvad.net is being handed something narrower than what they had, and this guide covers what to do about it.
Jump to
When does the Mullvad DNS shutdown take effect?
2 November 2026. After that, the servers stop answering.
News went up on 3 September, and Mullvad dropped a discontinuation banner onto its own DNS help page the same afternoon, closing off something that had run since 2022 across six hostnames, free to anybody at all who pointed a device at it.
The Mullvad DNS shutdown explanation runs to about four sentences and pads none of them.
On the VPN, public encrypted DNS was always redundant. Tunnel encrypts the query, VPN server resolves it, done.
Off the VPN it earned its keep two ways. Because Mullvad Browser used the service by default, domain names stayed away from your internet provider, and anyone else, customer or not, could point a device at it for nothing.
Running a privacy-focused public resolver is, in Mullvad’s own phrase, a highly specialised undertaking, and it rates the Quad9 Foundation as the undisputed leader in that particular field. So rather than duplicate half of what Quad9 already does, the money goes to Quad9 and the servers go dark.
The announcement tells you when the servers die. It does not tell you what dies with them.
Six hostnames. Six IPv4 addresses, six IPv6 addresses, DoH on port 443 and DoT on 853 across the lot. All of it stops on the same Monday.
| Retired hostname | IPv4 | What it filtered |
|---|---|---|
dns.mullvad.net | 194.242.2.2 | Nothing. Encryption only. |
adblock.dns.mullvad.net | 194.242.2.3 | Ads, trackers |
base.dns.mullvad.net | 194.242.2.4 | Ads, trackers, malware |
extended.dns.mullvad.net | 194.242.2.5 | Ads, trackers, malware, social media |
family.dns.mullvad.net | 194.242.2.6 | Ads, trackers, malware, adult, gambling |
all.dns.mullvad.net | 194.242.2.9 | Everything above combined |
2a07:e340::2 through ::9 on the same pattern. Every one of these dies on 2 November 2026.Table scrolls sideways on a phone.

Who actually has to do something before 2 November?
The Mullvad DNS shutdown splits people into three groups. Only one of them has any work to do.
Mullvad VPN users who never opened the DNS settings. Nothing changes for you. Queries go down the WireGuard tunnel and get resolved by whichever server you connected to, and that is a different system from the public resolvers being retired.
The app’s own DNS content blockers run on those same VPN servers, so they survive the Mullvad DNS shutdown untouched.
Mullvad Browser on its defaults. Also nothing. Left the DoH setting alone, or picked the built-in ad-blocking option? Mullvad moves you to Quad9 without asking. Pointed the browser at some third party instead? Your choice gets left alone, which is decent of them.
A trap sits inside that second group, though.
Type one of Mullvad’s own hostnames into the browser’s custom DoH box, base or extended or family, and the automatic migration skips straight past you. Setting that field back to the default is what Mullvad asks for, and doing it in September beats discovering the problem on the last weekend of October.
Everyone who configured it by hand. Router. Windows 11 network settings. Android Private DNS. A custom resolver typed into Firefox or Chrome. An Apple configuration profile.
Every one of those is what the Mullvad DNS shutdown breaks. They keep pointing at an address that stops answering, and since nothing pops up a warning on the day, the first sign of trouble is name resolution quietly falling over.
Apple profiles are the worst of it. Any Mullvad DoH or DoT profile on iOS, iPadOS or macOS stops working outright, and Mullvad’s advice is to go and fetch Quad9’s replacements.
What does Quad9 give you, and what does it not?
Switzerland is where Quad9 runs, as a non-profit foundation. The resolver is free, it blocks domains tied to malware and phishing, and the foundation says it never logs end-user IP addresses. Swiss privacy law sits behind that claim rather than a promise on a marketing page.
DoH, DoT and DNSCrypt are all supported. Donations cover a good chunk of the running costs, and Mullvad’s money now lands in that pot.
Four variants exist. Picking between them is a real decision rather than a formality.
| Quad9 service | IPv4 / IPv6 | Use it when |
|---|---|---|
9.9.9.9 (Secure)dns.quad9.net | 9.9.9.9, 149.112.112.112 2620:fe::fe, 2620:fe::9 | Default choice. Threat blocking on, no client subnet sent. |
9.9.9.10 (No blocking)dns10.quad9.net | 9.9.9.10, 149.112.112.10 2620:fe::10 | You want encryption only, and filter elsewhere. |
9.9.9.11 (Secure + ECS)dns11.quad9.net | 9.9.9.11, 149.112.112.11 2620:fe::11 | CDNs keep sending you to the wrong country. |
9.9.9.12 (No blocking + ECS)dns12.quad9.net | 9.9.9.12, 149.112.112.12 2620:fe::12 | Both of the above at once. |
https://dns.quad9.net/dns-query, dns10, dns11, dns12. Verified against Quad9 documentation on 8 September 2026.Scroll the table across for the third column.
Now the important part, and the reason this article exists at all.
Whatever will hurt you gets blocked. Whatever merely irritates you is left alone. Nowhere in the Quad9 catalogue will you find a tracker list, an adult content list, a gambling list or a social media list.
Mullvad’s announcement does not mention that once.
Five terms this guide keeps using
- DoH (DNS over HTTPS)
- Your device sends name lookups inside an HTTPS request on port 443, so they look like ordinary web traffic and your internet provider cannot read them.
- DoT (DNS over TLS)
- Same encryption, on its own dedicated port 853. Easier for a network to spot and block. Easier for a router to implement.
- Recursive resolver
- The server doing the actual looking up on your behalf. Quad9 is one. The old Mullvad service was one. So is your internet provider’s, and that is the one you were avoiding.
- Anycast
- One IP address announced from many locations at once, so your query lands at whichever is nearest in network terms. Nearest is not always near.
- ECS (EDNS Client Subnet)
- A slice of your IP address passed on to the site’s nameservers so content delivery networks can guess your location. Useful for speed, small privacy cost.
Which Quad9 address replaces which Mullvad hostname?
This is the table the Mullvad DNS shutdown announcement should have carried, and did not.
| You were on | Closest Quad9 | What you lose |
|---|---|---|
dns.mullvad.net | 9.9.9.10, or 9.9.9.9 for a free upgrade | Nothing. You gain threat blocking if you take 9.9.9.9. |
adblock.dns.mullvad.net | 9.9.9.9 | Ad and tracker blocking. |
base.dns.mullvad.net | 9.9.9.9 | Ad and tracker blocking. Malware cover stays. |
extended.dns.mullvad.net | 9.9.9.9 | Ads, trackers and social media blocking. |
family.dns.mullvad.net | No equivalent | Ads, trackers, adult content and gambling. |
all.dns.mullvad.net | No equivalent | Everything except the malware blocking. |
Swipe left on the table for the third column.
Read that right-hand column before you copy an address across. Four of the six retired hostnames did something Quad9 will not do for you.

How to switch from Mullvad DNS to Quad9
Finding every copy is the hard part of any Mullvad DNS shutdown migration. Typing the new values takes about thirty seconds.
Most people caught by the Mullvad DNS shutdown set it in two or three places over the years and have forgotten at least one. Browser, then operating system, then router, then any VPN client with a custom DNS box.
A laptop that resolves fine on the home Wi-Fi and dies on a phone hotspot has two configurations, and you have updated one.
Then the values themselves. For standard threat blocking: 9.9.9.9 and 149.112.112.112 on IPv4, 2620:fe::fe and 2620:fe::9 on IPv6, dns.quad9.net for DoT, and https://dns.quad9.net/dns-query for DoH.

Android
Settings, then Network and internet, then Private DNS, then Private DNS provider hostname. Type dns.quad9.net and save.
That is DoT sorted, and nothing else on the phone needs touching.
Windows 11
Windows wants two things, and will quietly do nothing useful if you give it only one.
Put 9.9.9.9 in the preferred DNS field. Then set DNS over HTTPS to On with a manual template, and paste https://dns.quad9.net/dns-query into the template box.
If your provider hands out an IPv6 address, do the whole thing again on the IPv6 tab. And again on the other adapter if you move between Wi-Fi and Ethernet, because Windows keeps those settings apart.
Browsers
Firefox, Chrome, Brave and Edge all accept the DoH URL in a custom provider field, though it hides under privacy settings in some of them and security settings in others, so give yourself a minute to go hunting.
iOS and macOS
Delete the Mullvad profile first, then install Quad9’s. Two DNS profiles sitting on the same machine is a support ticket in waiting, and macOS 13 and earlier handle it especially badly.
Linux
On systemd-resolved, this goes in resolved.conf, followed by a restart of both systemd-resolved and NetworkManager.
[Resolve]
DNS=9.9.9.9#dns.quad9.net
DNSOverTLS=yes
Domains=~.
Refuses to come up? Drop DNSOverTLS to opportunistic, confirm resolution works again, then go and find whatever is eating port 853.
How do you confirm the switch to Quad9 worked?
Do not assume your Mullvad DNS shutdown migration took. Open on.quad9.net, which takes a second and satisfies most people.
For an answer that tells you something, run a TXT lookup against proto.on.quad9.net. Back comes the protocol your query arrived on: doh, dot, dnscrypt-udp, do53-udp.
That last one is the one to dread. Configure DoH on the Tuesday, see do53-udp on the Friday, and you have spent three days posting your lookups in the clear.
# Which protocol did Quad9 receive the query on?
dig +short txt proto.on.quad9.net.
# Is your ISP hijacking port 53 lookups?
dig +short ch txt id.server. @9.9.9.9
# Blocked by Quad9, or does the domain simply not exist?
dig @9.9.9.9 example-domain.test | grep -E "status|AUTHORITY"
A third check catches something worse than a misconfiguration.
Certain internet providers quietly redirect anything aimed at a public resolver back to their own boxes. Ask Quad9 which server answered, using the CHAOS-class TXT record for id.server. A healthy reply looks like res860.qfra3.rrdns.pch.net.
Get something else, or get nothing back at all, and your provider is intercepting port 53. Encrypted DNS is the cure for exactly that, and a decent argument for finishing the job properly rather than half way.
One more thing worth knowing: how to read a Quad9 block.
Blocked domains come back NXDOMAIN, exactly like domains nobody ever registered, so the difference you are looking for sits in the AUTHORITY count of the response header. Zero means Quad9 blocked it. One means the domain genuinely is not there. A SERVFAIL is neither, and points at DNSSEC.
Four Quad9 quirks the setup guides skip
Four of them, and the first has been quietly breaking routers since last December, long before the Mullvad DNS shutdown was announced.
HTTP/2 or nothing. On 15 December 2025 Quad9 began switching off HTTP/1.1 support for DoH. Clients that speak only HTTP/1.1 cannot use Quad9 over DoH at all, and Quad9 names MikroTik RouterOS, every version, as a confirmed case.
Running a MikroTik? Use DoT, or put unbound, dnsdist, dnscrypt-proxy or AdGuard Home in front of it.
ECS is a choice, not a default. Standard 9.9.9.9 forwards no fragment of your address to authoritative nameservers. Better for privacy, occasionally worse for a content delivery network trying to work out where you are.
Getting routed to another continent by a big site? 9.9.9.11 keeps the threat blocking and turns ECS on. Decide that deliberately rather than by accident.
Anycast is still anycast. Mullvad’s own known-issues section admitted its routing sometimes threw queries at a server on the wrong side of the planet, and that Android would give up rather than wait.
So does Quad9. Whether your new path beats the old one comes down entirely to how your provider peers with each network, and I have no honest idea which way that falls on your line, so go and time it yourself.
Two things that simply are not there. No Oblivious DoH, with none planned. No public cache flush tool either, and support will not flush a record on request.
Neither absence has anything to do with the Mullvad DNS shutdown. Both will be news to anybody arriving from it.
What the Mullvad DNS shutdown takes away that Quad9 does not replace
Six things go missing in the Mullvad DNS shutdown. The first four are the ones people will notice within a week.
- Ad blocking at the resolver. Quad9 does not do it and never has.
- Tracker blocking. Same answer. Your browser extension now carries the whole load, and your smart TV carries none of it.
- Adult content filtering. No Quad9 equivalent to
family.dns.mullvad.netexists. - Gambling filtering. Gone as well, and rarely available anywhere free.
- Social media filtering. The
extendedandalllists are not coming back in another form. - Pick-your-own tier by hostname. Mullvad let you change filtering level by typing a different address. Quad9’s four variants are about threat blocking and ECS, not content categories.
None of this makes Quad9 worse than what it replaces, and anyone running plain dns.mullvad.net comes out ahead of where they started, since threat blocking arrives that was never there before.
Families are the ones who lose. Their service is ending, and the named successor does a different job.
Want the ad and tracker blocking back without standing up something new? Then you want the filtering happening inside a tunnel rather than at a public resolver.
Proton VPN Plus does that with NetShield: malware only, or malware plus ads and trackers, applied across the whole device rather than one browser. Of everything surviving the Mullvad DNS shutdown, that is the nearest match to base.dns.mullvad.net which does not involve opening an account and reading another logging policy.
If you wanted filtering, these are the real replacements
For a lot of people Quad9 answers the Mullvad DNS shutdown completely. For everyone whose filtering mattered, four options.
NextDNS and Control D. Per-profile filtering with proper categories, the closest structural match to Mullvad’s tiered hostnames. Both need an account, and the account is the price.
You would be trading an anonymous public resolver for a configured one with your preferences bolted to it, so read the retention settings properly before you put a whole household on either of them.
Cloudflare 1.1.1.3. Malware and adult content, free, no sign-up. Quickest route back to something resembling family.dns.mullvad.net.
It is also Cloudflare, and a fair few readers here left Google specifically to stop feeding one enormous company everything.
DNS4EU. EU-funded, filtering tiers included. Also carrying the same French court orders Quad9 is, covered further down.
Run your own. AdGuard Home or Pi-hole with an encrypted upstream pointed at Quad9 buys you Mullvad’s flexibility and Quad9’s threat feed together. The price is a small computer you now have to keep alive.
Is public encrypted DNS even the right tool?
Mullvad’s help page has said for years that public encrypted DNS is close to pointless while you are connected to Mullvad VPN, and slower into the bargain. A company talking down its own free product is rare enough to be worth quoting, and they happen to be right.
On its own, encrypted DNS buys you one specific thing. Your provider can no longer read the domain names you look up.
It does not hide the address your traffic then travels to. The site still sees your IP. And nothing about it stops a profile being assembled out of the accounts you log into.

Which leaves a fork after the Mullvad DNS shutdown, and it is a fairly clean one.
Set up DoH purely to keep your provider out of your browsing history? Quad9 carries on doing that for free, and you should take it.
Wanted filtering as well? You are now maintaining two things where a tunnel would cover both.
Proton VPN handles every lookup on its own servers inside the tunnel and keeps no record of them, with NetShield sitting on top for paid plans. Proton VPN Plus is what BAIZAAR pays for, chosen on Swiss jurisdiction and five consecutive annual no-logs audits by Securitum, the latest in May 2026. Configuration detail lives in our Proton VPN setup guide.
Custom DNS comes with paid plans as well, so you can aim the tunnel at Quad9 if you would rather Proton never saw your lookups. Doing that switches NetShield off, since NetShield can only filter queries Proton resolves itself.
Two things to know before anyone reaches for a card. NetShield is absent from the free plan. And Proton VPN appears on the same French blocking list as Quad9, which gets a section of its own rather than a footnote.
Why a non-profit resolver is a bigger legal target than Mullvad was
Now the half of the story the Mullvad DNS shutdown announcement left out, and it does not point in one direction.
The foundation has been in court since 2021, ever since Sony Music got an injunction out of Hamburg ordering it to block a single domain that linked to pirated music.
Quad9 objected, lost at first instance, appealed. In December 2023 the Higher Regional Court in Dresden ruled that it enjoys liability privileges as a mere conduit. Final decision, no further appeal, blocks removed.
Then it happened again. And again.
Italian rightsholders demanded blocks, and Quad9 complied while saying openly that a non-profit can only afford so many legal fronts at once. Over in France, Canal+ won orders Quad9 ended up applying worldwide, having found no workable way to apply them to French users alone.
The July round deserves a slow read. On 17 July 2026 the Paris Judicial Court signed fourteen blocking orders covering the 2026/2027 Premier League and Champions League seasons.
On the list: France’s biggest internet providers, Cloudflare across resolver and CDN, Google Public DNS, Quad9, DNS4EU, Proton VPN, CyberGhost, ExpressVPN, Google Search and Bing.
Quad9 and DNS4EU filed no defence. Nor did Proton VPN. Blocks run to 30 May 2027 and 5 June 2027, and ARCOM can add fresh domains to the list at any point in the season without anybody going back to court.

Line those two facts up next to each other. Mullvad is handing its public DNS users from a Swedish company with no interest in defending a free side project, over to a Swiss foundation that has become the most litigated resolver on the internet.
Neither description is an insult. The foundation fights these things, wins a fair number of them, and publishes the outcomes either way, a habit that puts it well ahead of most infrastructure.
Every resolver big enough to matter is a named defendant somewhere. Quad9 is not the exception, and there is no exception to move to.
Should you move to Quad9, or somewhere else?
Four ways out of the Mullvad DNS shutdown, depending on which hostname you had.
Move to Quad9 if you were on plain dns.mullvad.net, or on base or adblock with uBlock Origin already running in the browser. Straight swap, threat blocking thrown in, nothing to pay.
Look elsewhere if you were on family or all. With no adult content filter and no gambling filter at Quad9, that leaves Cloudflare’s 1.1.1.3 for something free and immediate, or NextDNS and Control D if you want categories and will hold an account to get them.
Consider a tunnel if you set DoH up because your provider was watching your browsing. Encrypted DNS handles a third of that problem. A VPN handles most of the rest, and NetShield covers the filtering you are about to lose.
Do nothing if you use Mullvad VPN and never opened the DNS settings, or run Mullvad Browser on its default. You are already sorted.
Put the DNS back inside a tunnel
Proton VPN resolves every lookup on its own servers inside the encrypted tunnel and logs none of them. NetShield puts back the ad, tracker and malware filtering the Mullvad DNS shutdown removes with the base and adblock hostnames, across every device rather than one browser.
Swiss jurisdiction. Open-source apps. Five consecutive annual no-logs audits, and 30 days to get your money back if it does not suit you.
Already paying separately for encrypted mail or cloud storage? Proton Unlimited folds VPN, Mail, Drive, Pass and Calendar into one subscription. Affiliate links: we take a commission, your price does not change, and NetShield is not on the free plan.
The BAIZAAR verdict
Mullvad has handled this about as well as a shutdown gets handled. Eight weeks of warning. A named successor. Automatic migration for the people least likely to ever read a blog post. Money following the work. Industry standard is a status page edit on the morning of.
What bothers me is the omission.
Four of the six retired hostnames did content filtering Quad9 has never offered and has never pretended to offer. Read that announcement as a parent who set the family filter on the router two years ago, and you would reasonably conclude a straight swap exists. Some number of people are going to find out otherwise in November, in the least convenient way available.
On the sponsorship, two unknowns. Mullvad has not said what it is worth, and Quad9 had published nothing of its own about it when this went up.
A better funded Quad9 helps everybody. A better funded Quad9 is also a bigger target, and Mullvad’s users have just been moved behind an organisation that spends real money on lawyers.
Strip out the ceremony and it comes to this. Eight weeks to keep the encryption you already had. Eight weeks to work out what the filtering was worth to you.
Mullvad DNS shutdown FAQ
When exactly do Mullvad’s DNS servers stop working?
2 November 2026. Mullvad has given a date for the Mullvad DNS shutdown but no time of day, so write off that whole Monday and move before the weekend.
Do I need to do anything if I use Mullvad VPN?
No, as long as you never changed the DNS settings in the app. Your queries get resolved by the VPN server you are connected to, and that is a separate system from the public resolvers being retired. The app’s own content blockers keep working too.
Will Mullvad Browser stop protecting my DNS queries?
No. Browsers left on the default DoH setting, or on the built-in ad-blocking option, get migrated to Quad9 automatically. One exception worth checking: if you manually typed one of Mullvad’s other hostnames into the custom field, put it back to the default or the migration will skip you.
What replaces base.dns.mullvad.net?
Quad9’s 9.9.9.9 covers the malware half, and nothing free covers the rest. Ads and trackers were the other two categories on that hostname, so pair 9.9.9.9 with uBlock Origin in the browser, or shift the filtering into a VPN that blocks ads at DNS level.
Does Quad9 block ads?
No. What Quad9 blocks is malware and phishing. Advertising and tracking domains have never been on its list, and that single fact is the biggest thing the Mullvad DNS shutdown changes for anyone who was using a filtered hostname.
Does Quad9 have a family or adult content filter?
No, and this is the gap catching people out. Anyone on family.dns.mullvad.net or all.dns.mullvad.net has no Quad9 equivalent to move to. Cloudflare’s 1.1.1.3 is the closest free option. NextDNS and Control D give you proper category control, in exchange for holding an account.
Is Quad9 faster than Mullvad DNS was?
Nobody can answer that for you, and I am not going to pretend otherwise. Both services anycast, so latency comes down to how your internet provider peers with each network rather than to anything either one controls, which means the only number worth having is the one you measure at home. Time a few hundred lookups before and after.
Does Quad9 log my IP address?
Quad9 states it never logs or records end-user IP addresses, pointing at Swiss privacy law as the backstop. Treat that as a stated policy from a Swiss non-profit foundation, not as something an outsider can verify query by query, and weigh it the way you would weigh any provider claim.
Why is Mullvad shutting it down if the service works?
Focus, on Mullvad’s own account. It reckons a public privacy resolver is a highly specialised undertaking, that Quad9 does the job better, and that funding Quad9 beats running a partial version alongside. The service was free, and largely redundant for the paying customers.
Can I use Quad9 with Proton VPN?
Yes, through the Custom DNS setting on paid Proton VPN plans. Be aware it turns NetShield off, because NetShield filters the queries Proton resolves and cannot filter ones handed to somebody else. Inside the tunnel, your Quad9 traffic gets encrypted by the VPN rather than by DoH.
What happens if I do nothing after 2 November 2026?
Best case, name resolution fails loudly and you fix it on the spot. Worse case, and the likelier one, the device quietly falls back to your internet provider’s resolver, everything carries on looking normal, and the exact snooping you set encrypted DNS up to prevent resumes without so much as a notification. Plan around that second outcome.
Is Mullvad VPN itself shutting down?
No. The Mullvad DNS shutdown covers the free public encrypted DNS service only. Mullvad VPN, Mullvad Browser and the apps all carry on unchanged, and we have written up Mullvad’s other rough edges in our guide to YouTube blocking Mullvad VPN.
How we verified this
Every claim about the Mullvad DNS shutdown traces back to Mullvad’s announcement of 3 September 2026 and its own DNS help page. Both read on 8 September 2026.
Quad9 addresses, service variants, protocol support, the HTTP/1.1 retirement and every diagnostic command come from Quad9’s published documentation, checked the same day. Where Quad9 states a policy rather than a verifiable fact, this page says so.
Court orders come from published reporting and Quad9’s own press releases, dated so you can check them yourself.
Nothing here is a leak or a rumour. We benchmarked neither resolver and the article claims no speed difference. Mullvad has not disclosed what the Quad9 sponsorship is worth, so the verdict flags it as unknown rather than guessing.
Sources
- Shutting down our public encrypted DNS servers and sponsoring Quad9 instead, Mullvad VPN, 3 September 2026. Primary source for the Mullvad DNS shutdown.
- DNS over HTTPS and DNS over TLS, Mullvad VPN. Hostnames, IP addresses, ports, anycast notes. Updated 3 September 2026.
- Quad9 services. The four variants and their addresses.
- Quad9 FAQs. HTTP/1.1 retirement, ECS, protocol tests, block identification, ODoH and cache flushing.
- Quad9 overview. Swiss jurisdiction, logging policy, threat blocking scope.
- Quad9 turns the Sony case around in Dresden, Quad9. The mere conduit ruling and the Italian demands.
- Paris Court Kicks Off New Football Season with Multi-Intermediary Piracy Blocking Orders, TorrentFreak, 11 August 2026. The 17 July 2026 orders and who defended.
- How to use NetShield Ad-blocker and How to use custom DNS, Proton VPN. Filtering levels, plan availability, and the NetShield interaction.
Related BAIZAAR guides
More on the tools around the Mullvad DNS shutdown, and on what to run instead.
- Proton VPN 2026: the dependable privacy playbook
- YouTube blocking Mullvad VPN? What works instead
- The Google Incognito lawsuit: what it actually proved
- Netflix not working with a VPN? 8 fixes that work
- Google Workspace to Proton Mail: the secure 2026 blueprint
- StartMail review 2026: private email and unlimited aliases


