0

Using NextDNS Private DNS with VPN - does it work?

Hi there, I want to use a VPN like Mullvad but keep using NextDNS. This is on an Android 11 Phone and a Mac 10.15. I know it is not possible for both to use the one VPN slot. I have seen lots of (for me) too complicated explanations for how to nevertheless use both at the same time. As far as I can see, a simple way is to add my NextDNS profile (xxxxxx.dns.nextdns.io) as the Private DNS on my phone and add the NextDNS server addresses (eg 45.90.28.100) as the DNS addresses on the Mac. This seems to work, the logs show NextDNS working with both devices and it is very simple but I am suspecting there is a problem partly because it seems so much easier than the other methods suggested and because I have seen no-one else suggesting this method. Are these two configurations using my NextDNS blocklists (which is what I want) or just connecting via NextDNS? The logs seem to show they are doing the former. Are there any security issues, eg some of the logs do not show a padlock sign by the log which is what I am used to seeing. Is this because it is via HTTPs not TLS?. In short, given the simplicity of this solution and lack of people suggesting this method, does this work for combining a VPN with NextDNS on Android phone and Mac and allowing the NextDNS blocklists to be used. I have above average capability with techy stuff but not enough to understand the other solutions I have seen. Thanks for any advice!

28 replies

null
    • Chris.6
    • 2 yrs ago
    • Reported - view

    Yes, it's possible. I can only speak for iOS and Mac though. You can take a look at this guide. It involves using apps that allow you to set custom DNS, like Viscosity and Passepartout. 

    You can't use the NextDNS IPv4 IP on Mac, the VPN will override it. Also, this will lose your configuration ID every time you receive a new IP from your ISP. 

    You could try the IPv6 DNS IP on Mac, but again, most VPN connections will override this, unless you specifically use apps like Viscosity, which can use custom IPv6 DNS, or Passepartout, which can use custom DoH DNS (and more). 

    In case of Mullvad, they mention custom DNS as an option, as long as it's not DoH/DoT. This means you could try putting the NextDNS IPv6 IP directly into the Mullvad app and test what is shown on browserleaks.

      • Lukemb64
      • 2 yrs ago
      • Reported - view

      Chris It seems my ISP has not deployed IPv6 yet.

      • Chris.6
      • 2 yrs ago
      • Reported - view

      Luke Someone with more knowledge would have to chime in what that means. My guess would have been that it doesn't matter, because you are not trying to use your ISP DNS. 

      • Lukemb64
      • 2 yrs ago
      • Reported - view

      Chris thanks!

Content aside

  • 2 yrs agoLast active
  • 28Replies
  • 7150Views
  • 4 Following