
Android Private DNS is a hostname you type in Settings so the phone sends DNS over TLS to that resolver instead of whatever the cafe DHCP handed you. It is not a browser checkbox. It is not a VPN. People mash them because both show up under privacy on a Pixel, and because both use the word encrypt. They are two envelopes. Private DNS is a locked bag for the question 'what IP is this name,' aimed at a machine you named. A system VPN is a truck to a node you chose. The truck can carry the question. The locked bag does not hide the house Mail and Slack later walk into.
A VPN is still that truck. Wikipedia's VPN page is the noun. RFC 8446 is TLS 1.3 on the website. HTTPS can hide page bodies and still leave destination IPs visible if the hop never entered a tunnel. Google's Private DNS help is the follow link for the Settings row. That page is a hostname, not a Klox SKU. We do not ship a public DoT resolver. We do not sell custom DNS. Klox routes DNS through the tunnel. That is a different sentence from 'type dns.google in Private DNS.'
This is not DNS-over-HTTPS vs a VPN: Two Envelopes, Two Jobs. That URL is browser DoH: Firefox and Chrome encrypting DNS for that browser only. This page is the Android OS row. System-wide for the question. Still not a wrap for Slack's session. I will not clone the browser essay. This is not What DNS Does on a VPN (Plain English). That piece is the resolver hop when Connect is up, as English. I will point. I will not rewrite the hop. This is not DNS Leak: Why It Matters and How to Test. That one is why leaks matter and how people test. This is not IPv6 Leak in Plain English: Two Addresses, One Laptop. Dual-stack leftovers live there. Private DNS does not eat v6 sessions either.
KloxVPN is WireGuard, OpenVPN, OpenConnect, and Shadowsocks, five devices, yearly from $2.83 a month, 7-day money-back on first purchase. Features lists all DNS through the VPN tunnel, IPv6 leak protection, WebRTC leak blocking. None of that is a Private DNS hostname you paste. Download is the apps. Pricing is the live number. Cookies: /cookie.
I have a bias. Let the VPN own names while you are connected. Use Private DNS when you are off a VPN and you do not want the cafe to read clear DNS. Do not stack them as vitamins. Do not treat a DoT hostname as a tunnel. Do not treat a tunnel as a public resolver you typed. Do not bypass school or work DNS policy because this article explained the Settings row.
Related reading: Antivirus: Not a VPN Setting and Aesni: Not a Mitigation Toggle. Linux aio_max_nr vs a VPN: Practical Notes and Linux aio_max_nr: Not a VPN Setting. What is a VPN? and VPN kill switch.
Looking for a reliable VPN?
KloxVPN — from $2.83/month. Apps for every device.
A hostname in Settings, not a browser checkbox
On Android 9 and later, Settings has a Private DNS row. Automatic tries opportunistic encryption to the network's resolver. Off is clear DNS. Provider hostname is the strict mode people mean when they search this: you type a name such as dns.google or one.one.one.one, and the phone must speak DNS-over-TLS to that host or DNS fails. That is a locked bag to a resolver. The cafe that was going to sniff UDP 53 sees a TLS session to that hostname instead, often on port 853. The resolver still sees the names. That is the trade. You moved the reader from the coffee shop to whoever runs the hostname you typed.
Browser DoH is a cousin, not this row. Firefox encrypting DNS for Firefox does not wrap Chrome, Mail, or the Play updater. Private DNS is OS-shaped. App DNS questions that go through the system stub can ride it. That is the distinction the DoH essay already flagged in one paragraph. This page is that paragraph as a full leftover. Celebrate the size. Then look at sessions. Mail still opens a TCP or QUIC path to a mail IP. Slack still opens a path to Slack. Those paths are not DNS. Private DNS does not wrap them. A system VPN does, from the cafe's chair, when the client is doing its job.
Farms will rank 'Private DNS vs VPN winner' until the cookie dies. There is no winner. There are two envelopes. You can use Private DNS off-VPN to stop clear DNS on a LAN. You can use a VPN to move the hop. You can use both and fight yourself. Crown neither.
Klox's envelope is the truck. WireGuard first. OpenVPN when the AP is rude. DNS through the tunnel is the documented default. I will not invent a consumer UI where you type a DoT hostname. If a white-label brand wanted custom DNS copy, that is a different article and a different chair. You are a consumer. There is no custom DNS SKU in this sentence.
- 1Download the app from klox.app/download — not a random APK site.
- 2Sign in with the account you paid for.
- 3Press WireGuard. Wait for the connected state.
- 4If it fails, try OpenVPN. Still failing: note the network (hotel, campus, home) before you write support.
First successful connect
| Envelope | Hides from cafe | Still shows | Who sees the names |
|---|---|---|---|
| Clear DNS, no VPN | Nothing about names | Names, IPs, often SNI, Mail and Slack sessions | ISP, cafe, whoever sits on the path |
| Private DNS (DoT), no VPN | The DNS question in the clear | Destination IPs of HTTPS, Mail, Slack; often SNI | The hostname you typed in Settings |
| VPN, tunnel DNS (Klox) | Names and inner IPs as a blob to the node | That you used the AP, volume, a VPN IP | The VPN resolver, not the ISP as a shopping list |
| Private DNS stacked on VPN | Depends who wins | A mess if the stub still talks off-tunnel | Whoever actually answered |
| Cookie on klox.app | Unrelated | Unrelated | See /cookie; neither envelope is a CMP |
Private DNS encrypts DNS to the hostname you typed. It does not wrap Mail, Slack, or the IP hop of HTTPS. A VPN wraps the hop.
— KloxVPN consumer notes
Cloudflare Learning: What is a VPN?
Wikipedia: Virtual private network
OS-wide question, not OS-wide hop
Private DNS can cover Mail's DNS question. It does not cover Mail's session to a mail IP. Browser DoH often covers neither. Different leftover. Same cafe still seeing IPs.
What this post is not
Not the browser DoH essay. Not the resolver-hop essay. Not a leak-test how-to. Not IPv6 physics. This URL is Android's hostname row versus tunnel DNS until you can say which leftover you meant.
What Private DNS encrypts
Private DNS hides clear DNS from the local path. The cafe that used to see 'bank.example' on port 53 sees a TLS session to your DoT host instead. On a network that logs classic DNS, that is a real change. On a network that already could not read port 53 because Automatic mode upgraded opportunistically, you may already have a quieter question without naming it. Strict hostname mode is louder as a choice: you picked the reader.
It also hides the shopping list from an ISP that was only watching UDP 53. The ISP can still see you spoke to the DoT host. They can still see you later spoke to website IPs, mail IPs, chat IPs. They often still see SNI. Encrypted Client Hello is uneven. Do not claim the shop sees nothing because Settings has a lock icon on DNS. The win is narrower than the marketing. Narrow can still be worth it when you are off a VPN and the leftover you care about is clear names.
The resolver you typed still gets every question the stub sends. Cloudflare, Google, Quad9, a 'privacy' hostname a blog ranked: that machine is the new reader. Famous is not the same as 'nobody has the list.' You moved the list. Say that. If you are fine with that reader, Private DNS did the job it actually has. If you wanted nobody to have the list, you wanted a different threat model, maybe not a consumer DNS row at all.
I will not rank hostnames. NordVPN's DoH post is a specimen of the genre. Use it as a specimen. Do not import their picker into Klox. We are not a public DoT app. We are a tunnel that already owns names while connected.
Clear port 53 is the thing DoT kills
That is the win. Celebrate it at that size. Then look at IPs for Mail and Slack. Then decide whether you still wanted a truck.
The hostname still has a list
Encrypting the path to a DNS company does not delete the log at that company. Read their policy if that chair matters. Do not file it under VPN.
What Private DNS still shows
Destination IPs of HTTPS. You asked the hostname for a name. You got a number. Chrome connected to the number. That connection is not DNS. TLS wraps the page. RFC 8446. The cafe can still see the number. Often the name in SNI during start. Encrypted Client Hello tries to quiet the name and is uneven. The number remains either way. A VPN hides that number from the cafe by making the interesting hop the VPN server. Private DNS does not.
Mail and Slack are the examples people skip. Their DNS questions can ride Private DNS. Their sessions do not. The cafe still sees you spoke to those IPs. Volume remains. Timing remains. A fat stream to a known CDN IP is a fat stream. DoT does not camouflage it. The DoT session itself is another IP the cafe sees: you talked to a resolver host. That is a smaller map than a shopping list of every site, and a larger map than 'I used a VPN node.' Pick the map you actually wanted.
WebRTC can still volunteer an address. IPv6 can still sneak. Those leftovers are not Private DNS's job. Features lists protections for a connected Klox session. Quote them for Connect. Do not quote them for a Settings hostname. The hostname never claimed the NIC.
Cookies in the browser still exist after DoT and after HTTPS. Our /cookie page is this website. Gmail's cookies are Google's. Neither envelope eats them. If you wanted tracking reduced, that is a different drawer. Tunnel DNS is not an ad blocker. I will not mash Private DNS into a blocklist either.
The IP is the leftover DoT cannot eat
Names in DNS can be wrapped. The later connect is still a connect. Cafe Wi-Fi still sees that connect unless a tunnel ate the hop.
Mail is not a DNS question
Private DNS can hide the lookup for smtp.example. It cannot hide the session that follows. If you wanted that session off the cafe path, you wanted VpnService, not a hostname.
What the system VPN wraps
With Klox connected, the cafe's interesting packet is a blob to a VPN node. Inner website IPs sit behind that blob. Mail and Slack sessions sit behind that blob if they use the default NIC. DNS questions, if they ride the tunnel, sit behind that blob. That is the hop job. It is bigger than Private DNS. It costs a seat, a handshake, sometimes a rude AP that hates UDP. WireGuard first. OpenVPN when that AP is rude. Same DNS story on both protocols if the client is still routing names through the tunnel.
Android implements consumer VPNs through VpnService. Always-on is policy on top of that service. This page is not the Always-on essay. That URL already exists. Here: a connected system VPN is how you wrap the device hop, including DNS through the tunnel on Klox. Private DNS is how you wrap the question to a third party when you are off that hop.
The VPN resolver sees the names. We are a hop operator. On HTTPS sites, we are not the website. Inner TLS still ends at the site. RFC 8446 still applies. People ask whether the VPN can read Gmail. On a normal HTTPS site, the inner lock still faces Gmail. The resolver still saw the name gmail was requested. That is a shopping list at our resolver, not an inbox. If that still bothers you, you wanted a different threat model.
Five devices: phone plus tablet is two seats if both tunnels are up. Private DNS on one Pixel does not cover the laptop. Per device. A tunneled phone does not hide the laptop's clear DNS. Count.
Bigger envelope, real cost
A tunnel hides IPs from the cafe. Private DNS does not. The tunnel also needs a handshake, a seat, and a portal sequence. Pay that cost when the leftover is the hop, not only the question.
Tunnel DNS is not a hostname
Klox routes DNS through the tunnel. That is the default I want. It is not a list of public DoT hosts you tap. Do not open a ticket asking which Private DNS hostname to paste. There is not one in this SKU.
Stacking Private DNS on a VPN
Private DNS plus tunnel DNS is how people get a leak they cannot draw. The stub might still pin the hostname you typed and send DoT off-tunnel. Or it might DoT inside the tunnel to a third party, so the cafe sees a blob but a public resolver still gets the list and your VPN exit IP. Or the OS might ignore both and use the cafe's DHCP DNS. Three owners. One green VPN icon. A leak-test page that disagrees with your feelings.
My rule: while Klox is up, let Klox own names. Set Private DNS to Automatic or Off unless you have measured that the hostname stays inside the tunnel and you like that third-party reader. Most people should not measure. Most people should leave the default. The resolver-hop article already said stop collecting resolvers like vitamins. This page repeats it because Private DNS is how vitamins get installed on a Pixel.
If you are off the VPN, a Private DNS hostname can be a reasonable cafe habit for the question leftover. It still will not hide IPs. If that leftover still bothers you, Connect. Do not 'fix' a VPN by adding a hostname on top without a test. Fix a leak with the leak articles, then stop.
Split tunnel, if you ever punch a hole, makes this worse. Excepted apps may use system DNS. System DNS may be cafe DHCP if Private DNS lost the fight. The hole is a scheduled leak. The hostname will not patch the hole. The split-tunnel English lives elsewhere. Here: do not stack three leftovers and call it defense in depth.
One owner while connected
Klox owns names on a connected session. Private DNS is another owner. Two owners is how tickets start with 'but DNS is encrypted' and end with an ISP resolver on the leak page.
Off-VPN Private DNS is a different day
No tunnel, cafe Wi-Fi, you only wanted to hide clear DNS: a hostname can do that job. It still shows IPs. Know the size of the win before you skip Connect.
School and work DNS is a policy
Some networks want their own resolver. Schools filter names. Offices inspect names. They hand you DHCP DNS, or they push a profile, or they break DoT on purpose so filtering still works. Private DNS in strict hostname mode can fail those networks: the phone cannot reach your typed host, or the portal never completes, or an app cannot resolve. That failure is the policy working. It is not a Klox bug.
I will not coach you around that policy. I will not give you a hostname that 'just works on the campus filter.' I will not tell you to pin dns.google so the lab cannot see names. If you do not run the network, you follow the network. If the leftover you wanted was a cafe hop you do run as a guest, Connect after the splash. If the leftover is a managed device, this essay is background. Read the Always-on article if lockdown is the row that is fighting the portal. Different row.
Captive portals hate extra DNS wraps. Hotel lobby, airport, campus guest: complete the splash first. Private DNS strict mode can deadlock the portal the same way a tunnel can. Pause the wrap. Sign in on a boring site. Restore. The cafe habit post owns the timing. Here: a hostname is another wrap that can deadlock. Name it before you blame WireGuard.
Five devices do not share a Private DNS hostname. The Pixel setting is not the iPhone. You will 'fix DNS' on Android and then leak on the laptop. Per device. Download the real client from /download so you are not configuring a cousin app's Secure DNS screen from memory.
Do not bypass a filter you do not own
Work and school DNS is their network. This article explains envelopes. It does not give you a hostname to evade a policy. If that is what you searched, stop.
Portals still come first
Splash pages need a moment of boring DNS. Strict Private DNS can starve that moment. Pause, portal, then decide which envelope you actually wanted.
Always-on is a different Android row
Always-on VPN and Block connections without VPN are OS settings on top of a VpnService app. Private DNS is a resolver setting. People turn all three on because a blog said to, then they cannot log into hotel Wi-Fi, and they uninstall. The Always-on essay already covered battery, portals, and five-device households. I will not clone it. I will say: Always-on is a lock on the hop. Private DNS is a lock on the question. Locks stack until a portal needs a key.
If you travel on a phone that should stay tunneled, Always-on can be the right lock, with the block off until you know how to pause for a splash. Private DNS on that same phone, while Klox is up, is the stacking leftover. Prefer one owner. If you only wanted quieter DNS on a phone that will not run a VPN, Private DNS is the smaller envelope. Honest. Small. Not a cape.
Smart Connect, if the app shows the row, is untrusted Wi-Fi. It starts the truck. It does not type a DoT hostname. If the row is missing, you have a Connect button. Use the button. I will not invent a DNS mode so this article matches a competitor's 'Secure DNS' screenshot.
IPv6 can still sneak around a v4-only leftover. WebRTC can still volunteer an address. Features lists protections. Confirm after connect if you like labs. Then stop. Daily hostname experiments are how people forget to live.
Two locks, two failures
Always-on fails a portal by blocking the NIC. Strict Private DNS fails a portal by starving DNS. Pause the one that is actually stuck. Do not toggle both at random.
Travel phone versus kid phone
A travel Pixel can wear a tunnel. A kid device on school Wi-Fi should not wear a hostname chosen to fight the school. Policy first. Envelope second.
Klox as a hop, not a DoT SKU
Klox is the truck: WireGuard, OpenVPN, OpenConnect, and Shadowsocks, five devices, yearly from $2.83 a month, 7-day first-purchase money-back. DNS through the tunnel. IPv6 and WebRTC called out on Features. Download from /download. Do not sideload a random APK because a listicle hosted one. Do not paste a DoT hostname into Settings because a farm said it was faster. Faster DNS to a public host can be a leak you scheduled.
We are not dns.google. We are not a recursive-resolver brand. Google's Private DNS help is a follow link so you can see the other envelope in someone else's words. Wikipedia's VPN page is the noun for ours. RFC 8446 is still the page lock. Three documents. Three jobs. Keep them in separate drawers.
If you want proof the resolver hop moved, use DNS Leak: Why It Matters and How to Test and the after-connect checklist. This page will not become those procedures. A leak site that still shows your ISP while the UI says connected is the failure mode. A leak site that shows a public DoT host while you wanted tunnel DNS is the stacking mode. A leak site that shows the VPN is the hop you paid for. Do it once on a network you control. Then stop.
Yearly from $2.83 a month is not a resolver ranking. Seven days on first purchase if the apps will not own DNS and you are inside the clock. /refund. Store purchases follow the store. This page will not turn into a billing sermon. It will also not turn into a custom-DNS roadmap. Absence of a picker is the product. Practice once on a guest SSID. Then use it.
No custom DNS SKU
No picker. No 'choose your Private DNS provider' in this article. Tunnel DNS is the consumer default. If a brand operator wanted different copy, that is white-label. You are not that chair.
Download, then look at DNS once
Install. Connect. Run one leak test. Confirm the resolver is the tunnel, not the cafe and not a hostname you forgot. Then stop collecting envelopes.
Key Takeaways
Android Private DNS encrypts DNS to a hostname you typed. It is OS-wide for the question. It does not wrap Mail, Slack, or the IP hop of HTTPS. The cafe can still see those numbers, and often SNI. Encrypted Client Hello is uneven. Do not claim the shop sees nothing because Settings has a DNS row.
Klox routes DNS through the tunnel. That is not a public DoT picker. WireGuard, OpenVPN, OpenConnect, and Shadowsocks, five devices, yearly from $2.83 a month, seven-day first purchase. No custom DNS SKU. Cookies on this site live at /cookie.
If you wanted the browser DoH essay, that URL is next door. If you wanted the resolver-hop essay, that URL exists. If you wanted a leak procedure, those checklists exist. If you wanted a winner, you wanted a farm. If you wanted one owner for names while connected, download the apps and leave the hostname experiments off until you can draw the leftover.
Related Resources
The hop already carries DNS
KloxVPN is WireGuard, OpenVPN, OpenConnect, and Shadowsocks, five devices, yearly from $2.83 a month, 7-day first-purchase money-back. Private DNS wraps the question to a hostname. A tunnel wraps the hop. Download the apps if you want names and destination IPs off the cafe path. No custom DNS picker.
Download KloxVPNFrequently Asked Questions
KloxVPN Team
Experts in VPN infrastructure, network security, and online privacy. The KloxVPN team has been building and operating VPN services since 2019, providing consumer and white-label VPN solutions to thousands of users worldwide.