DNS over HTTPS (DoH) support for Custom DNS
The current Custom DNS feature only allows IPv4 and IPv6 servers. It does not allow DoH even though it is more secure and more private. Please add support for it as it would greatly improve the experience for me and probably many other people who want to use custom filtering tools like NextDNS.
-
Wilson josh
commented
Custom DNS configuration would benefit from native DoH support, particularly for users who use services like NextDNS for privacy and content filtering. Traditional resolver addresses do not provide the same configuration flexibility as encrypted DNS endpoints. Allowing users to enter and manage DoH URLs directly could simplify setup while giving them more control over their DNS preferences. This would be a useful https://tiranga.de.com/ addition for privacy-focused users. I also found while exploring related privacy tools
-
Maria Sydor commented
DoH support would definitely make custom DNS configuration more flexible, especially for users who rely on services such as NextDNS for filtering and privacy controls. Having to enter traditional IPv4 or IPv6 resolver addresses limits the options for people who specifically want encrypted DNS transport. It would be great to see DoH endpoints supported alongside the existing custom DNS options, ideally with an easy way to enter and manage the endpoint. This seems like a useful improvement for both privacy-conscious users and anyone who wants more control over their DNS filtering. While looking into privacy-focused tools, I also came across https://on-luck.net.
-
B9
commented
This is desperately needed and long overdue!
Proton VPN needs to:
1. Add support for DoH/DoT/DoQ addresses in the custom DNS field/settings
And -
2. Add pre-set blocklist packs like basic, medium and advanced AND individual lists like Hagezi light, normal and pro etc like IVPN has
3. Allow users to choose multiple blocklists from a preset/curated list of the best and most popular lists like Hagezi, Hagezi TIF, Easylist, OISD etc
Currently frying my brain trying to find a way to have a VPN to hide my IP address AND custom DNS (DNS where I choose the blocklists like Hagezi!) AND encrypted DNS like DoH/DoQ etc.
IVPN has it all. A great VPN and blocklists users can choose. They have 3 predefined lists that they configured and also allow users to choose lists like Hagezi Light etc.
Proton VPN has to do this too! At least make it on par with IVPN. Allow users to use custom encrypted DNS (DoH, DoQ etc) from an external DNS service like NextDNS AND allow user to choose which lists they use, with predefined lists like basic, medium and advanced, and include others like Hagezi in a list for users to choose from. Like Hagezi Normal and TIF!
All I want is to be able to use Proton VPN with encrypted DNS using Hagezi Light/Normal or Pro and Hagezi's TIF blocklists.
-
JJ
commented
I appreciate the progress and being able to use custom DNS so thank you for that. I do think that not being able to use encryption defeats the purpose of this entire endeavor.
-
Nelmech
commented
Absolutely agree as well as a user of NextDns as well
-
MShaw
commented
As a Proton Unlimited subscriber and a NextDNS user, I totally agree. Having the alternate option to use a template rather than IPv4/IPv6 addresses would be an improvement. That way I can also flag the VPN connections with:
https://dns.nextdns.io/<ID>/ProtonVPN
..which makes tracking connections clearer.
Besides, DoH, like a VPN, is a security thing, so it makes perfect sense that ProtonVPN should support it out of the box.
-
Robin Sundin
commented
Absolutely Critical!!! This is a must for me for sure! Windows, Linux, Android and IOS
-
Łukasz
commented
I would really like to be able to specify my own DoH DNS server instead of the default one. I use NextDNS and would like to be able to use my own DNS server instead of the default one.
-
Elucidor Bramwell
commented
I wonder when this will be integrated to Proton VPN mobile apps :/
-
John Doe
commented
Strong support for this feature!
Encrypted DNS (DoH / DoQ) would be especially valuable when using Quad9, which I am already using anyway. Native support in the macOS and iOS apps would greatly improve usability and ensure DNS privacy truly aligns with Proton’s privacy-by-default approach.
-
Johan Smith commented
that is so informative and i would love to see that\
-
Privacy Advocate
commented
I already wrote a similar response on the iOS thread, and I'm adding roughly the same comment here for the mac thread.
Privacy and Security Problems with Plaintext DNS on macOS
DNS visibility beyond the VPN tunnel
Even though ProtonVPN encrypts traffic between the device and the VPN server, the DNS queries from the exit server to the resolver remain unencrypted. This allows the exit server’s ISP or any intermediate network to see the domains users visit.Exposure to interception and tampering
Plaintext DNS can be intercepted or modified. Without encryption, a malicious or compromised network could redirect traffic or block specific domains.Loss of end-to-end privacy
DNS queries reveal browsing activity. Without encryption between the exit node and the resolver, ProtonVPN users still leak metadata to third parties, which undermines the purpose of using a privacy-first VPN.Inconsistency with Proton’s “Privacy by Default” principle
Proton promotes complete user privacy and minimal trust in intermediaries. However, unencrypted DNS between the exit server and resolver contradicts that mission, especially for users who rely on privacy-centric resolvers like NextDNS or self-hosted DoH services.Specific Feature Requests for ProtonVPN macOS
Support DNS-over-HTTPS (DoH, RFC 8484)
Allow users to specify custom encrypted DNS resolvers via DoH endpoints, ensuring DNS queries remain private beyond the VPN tunnel.Support DNS-over-QUIC (DoQ, RFC 9250)
Add support for DoQ to provide faster, connectionless, and fully encrypted DNS resolution.Support IPv4 and IPv6
Enable both IPv4 and IPv6 addresses or hostnames for custom encrypted resolvers instead of IPv4-only input.Maintain end-to-end encryption
Ensure DNS queries are encrypted from the user’s device through the VPN tunnel and continue encrypted all the way to the resolver.Add transparency for DNS status and fallbacks
Inform users when ProtonVPN is using encrypted DNS and warn if a fallback to plaintext occurs, so users understand their privacy posture in real time.Why This Matters for ProtonVPN macOS Users
Eliminates plaintext DNS exposure and prevents metadata leaks.
Protects against DNS interception, manipulation, and censorship.
Aligns ProtonVPN’s macOS client with Proton’s broader privacy-by-design philosophy.
Makes the “Custom DNS” feature genuinely privacy-enhancing for advanced users.
Supporting encrypted DNS (DoH and DoQ) would close one of the few remaining privacy gaps in ProtonVPN’s macOS app and strengthen Proton’s claim to full end-to-end protection for its users.
-
Privacy Advocate
commented
I’m glad ProtonVPN iOS now supports custom DNS (as mentioned in the original post), but the fact it currently only supports plaintext UDP DNS introduces several real risks. Below are what I see as the drawbacks, followed by clear feature-requests that I hope Proton will prioritize.
Negative Consequences of Not Supporting Encrypted DNS (DoH / DoQ)
Exit-node exposure
DNS queries from Proton’s VPN server to the resolver remain unencrypted. That means the VPN host’s ISP or any network between Proton’s server and the DNS resolver can see which domains users are querying.Vulnerability to DNS manipulation or hijacking
Plaintext DNS is susceptible to MitM attacks: bad actors could intercept or modify DNS responses on that hop, redirecting users to malicious sites or injecting tracking.Metadata leakage & profiling
Even when content is encrypted and tunneled, unencrypted DNS reveals browsing patterns. Observers could see which domains you visited (or at least requested), undermining user privacy.Susceptibility to DNS-based attacks
Without integrity checks or encryption, DNS cache poisoning or spoofed responses become easier for adversaries on that plaintext path.Trust gap
Users choosing Proton expect “privacy by default.” The absence of end-to-end encrypted DNS for custom resolvers creates a discrepancy between Proton’s privacy marketing and its technical exposure.Clear & Specific Asks (in response to “Add DoH and DNS-over-QUIC Support for Custom DNS on iOS”)
Support DNS-over-HTTPS (DoH, RFC 8484)
Allow users to enter a DoH endpoint (URL or IP + path) as their custom DNS, with DNS-over-HTTPS traffic tunneled securely.Support DNS-over-QUIC (DoQ, RFC 9250)
As a next-generation encrypted DNS protocol optimized for performance, DoQ support ensures minimal latency and full confidentiality.Allow mixed IPv4 / IPv6
Accept both IPv4 and IPv6 custom DNS addresses (or DoH/DoQ endpoints), without forcing users to pick IPv4 only.Tunneled + end-to-end encrypted DNS
Ensure that when DoH/DoQ is selected, DNS queries are sent through the VPN tunnel and remain encrypted all the way to the resolver.Backward compatibility / fallback
If a custom encrypted resolver fails, Proton should fall back to its default DNS (or prompt the user), while warning that plaintext DNS is less secure.Expose diagnostics / logs
In debug mode (or with opt-in), show whether DNS is currently encrypted, which resolver is being used, and whether any fallback to plaintext occurred.By listing these pain points and concrete asks, I hope more Proton users will find this thread, vote it up, and help push this feature up the roadmap. If Proton implements this, it makes the “custom DNS” feature genuinely privacy-first.
-
rgnldo
commented
Fortunately, local DNS entries for custom DNS are possible in the Linux client. Why isn’t this possible in the Android client? In addition to the ability to add local DNS, support for DoT and DoH DNS addresses would be welcome as a feature.
-
C H
commented
For the love of God, can this be implemented please?
It seems odd that Proton VPN would only be limited to ipv4-based DNS resolvers when a lot of other lesser VPNs support proper Custom DNS.
-
Sergii Novosad commented
It's critical without a doubt. Not only does it limit us to primarily public DNS resolvers, it also limits us to only have unencrypted traffic, unless we use netshield. You can either implement DoT and DoH, or let us use system DNS (I refer to windows custom DNS, android custom dns config, iPhone .mobileconfig file, etc. ) I have to tear myself between using proton VPN and AdGuard DNS that supports DOH and DOT, but instead I have to use their public DNS, which is not bad, but I miss out on all logging for my DNS and precise ad blockers that I select myself, instead of AdGuard.) That is just an example of it being used with your vpn, but instead we have to rely on public ipv4 that doesn't provide the authentication that we need to truly stay anonymous online. Using your netshield shouldn't be the only option to secure our DNS traffic. Make it compatible with AdGuard-dns.io, as it covers all basis of possible connections to their server. But paying for reserving an ip shouldn't be the only option.
-
hermdog
commented
I whole heartedly agree!
-
Purple Dragon
commented
I agree. In the name of privacy, it just make sense to extend custom DNS support to support encrypted DNS (DoH, DoT, DoQ, etc) entries too rather than just IPv4 addresses that only support unencrypted DNS queries.
-
Purple Dragon
commented
I agree. In the name of privacy, it just make sense to extend custom DNS support to support encrypted DNS (DoH, DoT, etc) entries too rather than just IPv4 addresses that only support unencrypted DNS queries.
-
ProtonEnjoyer
commented
Currently, Proton VPN on macOS only allows custom DNS configuration via plaintext IPv4. This exposes DNS queries to interception and does not align with Proton’s privacy-first principles.
Please add support for encrypted DNS protocols—DNS-over-HTTPS (DoH, RFC 8484) and DNS-over-QUIC (DoQ, RFC 9250)—within the macOS app’s DNS settings.
Many providers, such as NextDNS, do not accept unencrypted IPv4 queries unless pre-authorized. This limits usability and reduces privacy.
Optional IPv6 support should also be respected where resolvers prefer or require it.
Adding encrypted DNS support would ensure stronger protection of user traffic beyond the VPN tunnel and reinforce Proton’s commitment to privacy by default.