Mullvad 4 min read

Who Pays for the Internet’s Privacy Layer?

A privacy company is shutting down one of its own services and funding another provider to do the job. Mullvad’s decision is more than the loss of a free DNS option. It raises a harder question: who should pay for the infrastructure that keeps the internet private?

Encrypted DNS Changes Who You Trust

DNS is the internet’s address book. Enter a domain name, and a DNS resolver finds the IP address needed to reach it.

Traditional DNS traffic commonly travels unencrypted over port 53. That can expose the domains you look up to your internet provider or anyone monitoring the same network.

Encrypted DNS protects those requests in transit. DNS over HTTPS, or DoH, wraps them in HTTPS traffic. DNS over TLS, or DoT, uses a dedicated encrypted connection. Both make casual surveillance and interception much harder.

Neither provides complete anonymity. The resolver still handles the request and may see which domain you are trying to reach. You are not eliminating trust. You are moving it from your ISP to a DNS provider.

Running Free Infrastructure Gets Expensive Fast

Mullvad is ending its free public encrypted DNS service and supporting Quad9, a nonprofit DNS provider, instead. The publicly available details do not establish the size or terms of that support.

From the outside, this looks like a retreat. Operationally, it looks more like specialization.

A reliable global DNS service takes more than a few servers and a status page. Providers need infrastructure across multiple regions, constant monitoring, security patches, capacity planning, and defenses against distributed denial-of-service attacks. Bandwidth bills do not disappear because the product is free.

The economics become less forgiving as adoption grows. More users mean more traffic, more infrastructure, and a larger attack surface, without a corresponding increase in revenue.

Mullvad appears to have concluded that duplicating a mature DNS network was a poor use of its resources. Funding a specialist can deliver more privacy infrastructure per dollar than maintaining a parallel service.

Quad9 Offers a Practical Division of Labor

Quad9 operates a public recursive DNS service that can block domains associated with malware and other known threats. It also supports encrypted protocols including DoH and DoT.

The interesting part of Mullvad’s move is its embrace of division of labor. Mullvad can focus on running a VPN network. Quad9 can focus on DNS resolution, threat filtering, and global availability.

That reduces duplicated engineering and operating costs. A larger Quad9 network can justify more locations, stronger redundancy, and a deeper incident-response bench. Privacy infrastructure, inconveniently enough, benefits from economies of scale too.

Financial support also gives privacy services an alternative to advertising and data monetization. Free at the point of use does not mean free to operate. Someone still pays for servers, transit, engineers, and the 3 a.m. response when the network comes under attack.

Sustainability Comes With a Centralization Tax

Consolidation creates its own risk. When smaller providers disappear and users concentrate around a few large resolvers, operations may become more efficient. Outages and policy changes also gain a much larger blast radius.

Trust becomes concentrated as well. Quad9’s nonprofit structure and privacy commitments matter, but they do not change the underlying architecture: more DNS queries flow through fewer organizations.

The alternative is not automatically safer. A fragmented ecosystem of small resolvers may look decentralized while falling behind on patches, monitoring, and attack mitigation. A poorly maintained independent service can be more dangerous than a professionally operated centralized one.

That leaves the privacy industry with an awkward choice. It can distribute trust across many potentially fragile operators, or concentrate it in a smaller number of better-funded specialists. There is no clean answer, only tradeoffs that should be made visible.

Mullvad is not abandoning privacy infrastructure so much as choosing how to sustain it. But as that infrastructure consolidates, transparency and independent scrutiny must grow with it. The real question is not whether privacy services should specialize, but how much trust the internet can safely place in the specialists.

Mullvad Quad9 DNS Privacy

Comments

    Loading comments...