Your Android phone leaks every DNS query in plaintext by default — every domain looked up by every app is visible to your ISP, your carrier, and anyone capturing packets on the same Wi-Fi. DNS over TLS (DoT) encrypts those lookups using TLS on port 853, the same protocol securing HTTPS. Android has supported this natively since Android 9 Pie through a setting called Private DNS, but it is buried differently on every manufacturer's firmware, and silently falls back to cleartext when it fails. This guide gets it working and verifiable.

What DNS over TLS Does — and What It Does Not

Standard DNS runs over UDP port 53. Every query your phone sends — every app phoning home, every URL you visit — leaves in cleartext. DNS over TLS wraps those queries in a TLS 1.3 tunnel to TCP port 853, making them unreadable to anyone between your device and the resolver. The resolver itself still sees your queries; the encryption is transport-layer only, not end-to-end anonymisation.

Android's Private DNS mode bootstraps the connection by resolving the DoT provider's hostname once via the existing unencrypted resolver, verifying the TLS certificate, then routing all subsequent queries through the encrypted session. That single plaintext bootstrap lookup is a documented architectural trade-off — it reveals the resolver hostname once, not ongoing query content. For a thorough explanation of the protocol, the Cloudflare DNS over TLS overview covers the spec in detail.

Tip: Before and after enabling Private DNS, use our DNS Propagation Checker to confirm which resolver IP your device is actually hitting. If the responses change to your chosen DoT provider's address range, the tunnel is live.

Android Version Support and 2026 Behaviour Changes

Any device running Android 9 or later supports DoT natively — no third-party app required. The menu location has shifted across Android releases:

  • Android 9–10: Settings → Network & Internet → Advanced → Private DNS
  • Android 11–12: Settings → Network & Internet → Private DNS (promoted out of Advanced)
  • Android 13–14: Settings → Network & Internet → Private DNS
  • Android 15 (most 2025–2026 devices): Settings → Network & Internet → Connectivity preferences → Private DNS

Android 15 changed fallback behaviour: when the DoT server fails to respond within its timeout, Android 15 logs the failure visibly in the Private DNS status rather than silently continuing with cleartext DNS. This makes debugging easier — if you see repeated status cycling between connected and disconnected, the tunnel is degraded, not just slow.

Enabling Private DNS on Stock Android and Pixel Devices

Pixel phones and Android One devices running Android 12 through 15 use these steps:

  1. Open Settings
  2. Tap Network & Internet
  3. Tap Private DNS
  4. Select Private DNS provider hostname
  5. Enter the DoT hostname of your chosen provider (see the provider list below)
  6. Tap Save

The status indicator changes from Off to the hostname you entered. A status of Can't connect immediately after saving means the hostname either does not resolve, lacks a valid TLS certificate on port 853, or your network blocks port 853 outright — which is common on corporate networks, school Wi-Fi, and some hotel networks.

Samsung OneUI (Galaxy S and A Series)

Samsung's OneUI buries Private DNS inside a secondary connections menu. On OneUI 6 and 6.1 running on 2024–2026 Galaxy devices:

  1. Open Settings
  2. Tap Connections
  3. Tap More connection settings
  4. Tap Private DNS
  5. Select Custom and enter your DoT hostname
  6. Tap Save

Samsung kept this path consistent from OneUI 4 onward. If the menu is missing on an older OneUI build, open Settings search and type private dns — the system search surfaces it directly.

OnePlus and OxygenOS 14 / 15

  1. Settings → Wi-Fi & Network
  2. Tap Private DNS
  3. Choose Private DNS provider, enter the hostname, save

Xiaomi MIUI 14 and HyperOS

  1. Settings → Connection & sharing
  2. Scroll to Private DNS near the bottom of the list
  3. Tap the field, enter the hostname, tap Save

On MIUI 13 and some early MIUI 14 builds, there is a known bug where Private DNS silently falls back to cleartext on mobile data while working correctly on Wi-Fi. This was patched in the January 2024 security update cycle. If you see split behaviour between Wi-Fi and LTE, verify your firmware version and update if a patch is available.

Nothing OS and Other Near-Stock Builds

Nothing OS 2.6 and later follows stock Android paths: Settings → Network & Internet → Private DNS. No additional wrapping.

Choosing a DNS over TLS Provider

The Private DNS field expects a strict DoT hostname — not an IP address, not a URL. Entering an IP like 1.1.1.1 will fail because Android needs a hostname to validate the TLS certificate against.

  • Cloudflare: 1dot1dot1dot1.cloudflare-dns.com — fast, privacy-focused, no persistent query logging, supports DNSSEC validation
  • Google Public DNS: dns.google — extremely reliable, DNSSEC-validating, integrated into Google's global anycast network
  • Quad9: dns.quad9.net — blocks known malicious domains via threat intelligence feeds, non-profit operator, no logging
  • NextDNS: your-id.dns.nextdns.io — per-device filtering rules, free tier, useful for households wanting parental controls via DoT
  • AdGuard DNS: dns.adguard-dns.com — built-in ad and tracker blocking at the DNS level

For most users, dns.google or 1dot1dot1dot1.cloudflare-dns.com are the lowest-friction choices: both are globally anycasted, reliably answer within single-digit milliseconds on most networks, and perform DNSSEC validation before returning results.

Verifying DNS over TLS Is Actually Active

The Settings UI showing a hostname does not prove the tunnel is working — Android can silently fall back to cleartext DNS if port 853 is filtered and the fallback threshold is crossed. Verify with these methods ranked from easiest to most thorough:

Cloudflare's Built-In Check

If you set 1dot1dot1dot1.cloudflare-dns.com as your provider, open a browser on your phone and navigate to https://1.1.1.1/help. The page shows a live check — look for Using DNS over TLS (1.1.1.1): Yes. A No result with the hostname showing in Settings means port 853 is being blocked by the network.

DNS Leak Testing via Browser

Visit a DNS leak test site from your phone's browser. It will show which resolver IP handled your query. Cross-reference the listed IP against your provider's known address ranges. If it shows your ISP's DNS servers, fallback is occurring.

ADB Shell Verification

With USB debugging enabled on the device:

adb shell dumpsys connectivity | grep -i "private dns" # Expected output includes: privateDnsMode=HOSTNAME # and the hostname you configured adb shell getprop net.dns1 adb shell getprop net.dns2 # Cross-reference returned IPs with your provider's published address ranges

Packet Capture (No Root Required)

Apps such as PCAPdroid work on Android 10 and later without root by using a local VPN interface to intercept traffic. Filter for the phone's own DNS traffic. You should see no UDP traffic on port 53 from system processes when DoT is working. All DNS exits as TCP on port 853 to your resolver's IP.

Tip: Want to see exactly what DNS records the resolver is returning for a domain? Run a query through our DNS Lookup tool and compare the authoritative results to what your phone resolves — a mismatch can reveal DNS hijacking on the network.

Port 853 Blocked: Workarounds

Corporate networks, school Wi-Fi, hotels, and some mobile carriers block TCP port 853 to enforce their own DNS resolvers for content filtering, compliance logging, or split-horizon internal routing. Symptoms: Private DNS immediately shows Can't connect after saving, or the status cycles between connected and disconnected repeatedly.

Ranked workarounds from most to least comprehensive:

  1. Use the Cloudflare WARP app or NextDNS app: Both run a local VPN interface on the device and tunnel DNS over HTTPS (port 443) rather than DoT (port 853). Port 443 is almost never blocked. WARP covers all apps system-wide. NextDNS offers the same with customisable filtering rules.
  2. Use a VPN: A trusted VPN encrypts all traffic including DNS. Reputable VPN clients on Android enforce DNS leak protection, routing resolver queries through the VPN tunnel regardless of what port the exit network blocks.
  3. Configure DoH in Chrome only: In Chrome, Settings → Privacy and Security → Use secure DNS → With a custom provider. This encrypts DNS within Chrome but not for other apps — a partial solution, not system-wide.

Common Misdiagnoses

"I enabled Private DNS but my browsing doesn't feel private." DoT encrypts the DNS query only. Your ISP can still see the IP addresses you connect to. In TLS connections, the SNI field in the handshake historically revealed the hostname — though Encrypted Client Hello (ECH), increasingly deployed by Cloudflare, Google, and Fastly in 2026, addresses this. DoT is one privacy layer among several needed for meaningful traffic confidentiality.

"It works on Wi-Fi but not on mobile data." Private DNS applies to both Wi-Fi and mobile data interfaces. When behaviour differs, suspect carrier-level DNS interception — some carriers in specific regions intercept port 53 traffic and return their own responses, while simultaneously blocking port 853 to prevent DoT bypass. The WARP or NextDNS app approach resolves this since it uses port 443.

"Latency increased after enabling Private DNS." The first connection to the DoT server requires a TLS handshake. Subsequent queries reuse the session. If elevated latency persists past the first few queries, try a geographically closer provider. Cloudflare and Quad9 anycast their endpoints globally, so dns.quad9.net and 1dot1dot1dot1.cloudflare-dns.com should automatically route to the nearest node. Google's dns.google is similarly anycasted.

"I set it on one phone and expected it to apply to my other devices." Private DNS is a per-device setting. It does not sync via Google account backup. Each device requires individual configuration. Google Workspace MDM can pre-configure it fleet-wide, but that requires enterprise device enrollment.

Enterprise MDM and Locked Devices

If your Android device is enrolled in Google Workspace endpoint management, Microsoft Intune, or VMware Workspace ONE, the IT administrator may have locked Private DNS to a corporate resolver or disabled the setting entirely. The menu entry will be greyed out or absent. This is intentional — corporate DNS servers resolve internal hostnames that public resolvers cannot, and bypassing them would break access to internal applications.

On Android 11 and later with a work profile, MDM-enforced DNS typically applies only to the work profile. Your personal profile's DNS is usually still user-configurable. Check both profiles independently if you are on a work-managed device and need DoT in your personal profile.

DNSSEC, IPv6, and ECH in 2026

DoT encrypts the query in transit but does not by itself validate that the answer is authentic — that is DNSSEC's role. Both Cloudflare (1dot1dot1dot1.cloudflare-dns.com) and Google (dns.google) perform DNSSEC validation server-side before returning results, so you benefit from spoofing protection without client-side DNSSEC implementation as long as you trust those resolvers. Quad9 (dns.quad9.net) validates DNSSEC and additionally cross-references responses against threat intelligence to block known malicious domains before they reach your apps.

On dual-stack networks, Android will prefer IPv6 when connecting to DoT endpoints that have AAAA records — both Cloudflare and Google support this. If you are using tcpdump or Wireshark to verify DoT traffic and filtering only IPv4, you may miss the actual encrypted tunnel running over IPv6. Filter by port 853 regardless of IP version.

Encrypted Client Hello (ECH) is being progressively rolled out in 2026 at the TLS layer by Cloudflare, Google, and other CDNs. ECH encrypts the SNI field in TLS handshakes so network observers cannot read the target hostname from HTTPS connections. Combined with DoT, ECH closes the two remaining major plaintext leaks in typical web browsing — the DNS query and the SNI field. ECH is handled automatically by the browser when the server supports it; it requires no separate Android configuration.

Confirming the Fix and Preventing Regression

Private DNS persists across reboots, network switches, and airplane mode cycles. Three scenarios warrant rechecking:

  • Factory reset or new device setup: Private DNS is not included in Google's cloud backup. Reconfigure manually after any reset or device migration.
  • Major OS upgrade: Android upgrades very occasionally reset network settings. Verify Private DNS status after upgrading from one major Android version to another.
  • MDM enrollment: Enrolling a device in enterprise management may push a DNS policy that overwrites your setting. Check Private DNS immediately after enrollment completes.

For households wanting network-wide DoT without per-device configuration, enable DoT at the router instead. Routers running AsusWRT Merlin, pfSense, OPNsense, or Unifi Gateway firmware support upstream DoT forwarding — all client DNS queries, including those from IoT devices that have no Private DNS capability, get encrypted at the gateway. Per-device configuration remains a fallback for mobile devices on external networks where the home router is unavailable.