Hide/modify DNS over HTTPS options
I was looking at the DOH settings in Privacy & Security
, and on Default Protection, there's the following:
- Mullvad Browser decides when to use secure DNS to protect your privacy.
- Use secure DNS in regions where it’s available
- Use your default DNS resolver if there is a problem with the secure DNS provider
- Use a local provider, if possible Turn off when VPN, parental control, or enterprise policies are active Turn off when a network tells Mullvad Browser it shouldn’t use secure DNS
Half of it is incorrect, but there's this one line that got me curious: Turn off when VPN, parental control, or enterprise policies are active
.
It would be of value to disable DoH when a VPN is active.
Alternatively, we could hide Default Protection
, since half of it is wrong and doesn't apply to Mullvad Browser. Probably Increased Protection
should go as well, since when we talk about leaks, it's better to have DoH either on or off, not something nebulously in between.
There are some confused users out there: https://www.reddit.com/r/mullvadvpn/comments/1gxbvgn/mullvad_browser_dns/
We've also reported multiple people unsure about what to do with this and we actually recommend users to disable DoH when Mullvad VPN is active.