Back to Blog•
September 21, 2026
•
9

"This Network Is Blocking Encrypted DNS Traffic": What It Means and How to Fix It

Your iPhone says the network is blocking encrypted DNS. Here's what that means, why it happens, and how to fix it.

You open Wi-Fi settings on your iPhone and see an orange Privacy Warning under the network name: "This network is blocking encrypted DNS traffic." It goes on to say that the names of websites you visit may be monitored and recorded by other devices on the network.

It sounds like a hacking alert. It almost never is. It means one specific privacy feature isn't working on this network, and in most cases you can find the cause in a few minutes.

iPhone Wi-Fi settings showing the privacy warning "This network is blocking encrypted DNS traffic"
TL;DR
  • Your iPhone tried to send DNS lookups (the "which address is this website?" questions) in encrypted form, and something on the network blocked or intercepted them. The phone fell back to plain, readable DNS.
  • The usual causes are a parental control filter, an ad blocker like Pi-hole, a hotel or café login page, a work or school network, a security app, or an old router.
  • On a network you control, the fix is usually one of seven steps below: forget and rejoin the network, restart the router, update firmware, check filters, or change DNS settings.
  • On public Wi-Fi, don't try to fix the network. Use a VPN, which sends your DNS lookups inside an encrypted tunnel the network can't read.

What the warning actually means

Every time your phone opens a website or an app talks to a server, it first asks a DNS server to translate a name like instagram.com into an IP address. That lookup is called a DNS query, and together those queries are your DNS traffic.

Traditional DNS is sent in plain text. Anyone who can see the network, such as the router, its owner or another device running monitoring tools, can read the list of names you look up. Even when the website itself uses HTTPS, the DNS lookup can reveal which site you went to.

Encrypted DNS fixes that. There are two main standards:

DNS over HTTPS
DoH · RFC 8484
port 443
Hides DNS inside normal HTTPS traffic. Harder for a network to single out.
DNS over TLS
DoT · RFC 7858
port 853
Uses its own dedicated port. Easy for a router or firewall to block.
Plain DNSWhat you get when the warning shows
The network sees: instagram.com · reddit.com · yourbank.com
Encrypted DNS (DoH / DoT)What the iPhone tried to use
The network sees: encrypted lookups to a DNS resolver
VPNWorks even when DoH is blocked
The network sees: one encrypted connection to the VPN server

Apple added support for both in iOS 14 and macOS Big Sur in 2020. When your device is set up to use encrypted DNS (through a DNS profile, an app, a security product, or a resolver the network advertises) and that encrypted connection fails on a network, iOS falls back to regular DNS and shows the warning.

Apple describes the same situation in its guide to recommended settings for Wi-Fi routers and access points: the device keeps using the network's DNS server, but the names of the sites and servers it contacts are unencrypted.

So the warning tells you one thing: on this network, your DNS lookups are readable. It doesn't mean someone is reading them, and it doesn't mean your passwords or messages are exposed, since those are protected by HTTPS and app encryption.

What can other people see?

Visible when encrypted DNS is blockedStill protected
Names of websites and servers you look up (reddit.com, bankofamerica.com)Specific pages, searches and posts on HTTPS sites
When you looked them upPasswords, card numbers and form data
Which device made each lookupContent of end-to-end encrypted messages
Lookups made by apps in the backgroundAnything sent through a VPN tunnel

That's the same kind of information we describe in Can the Wi-Fi owner see what you search?. Encrypted DNS removes one of the easiest ways to collect it. When encrypted DNS is blocked, that way is open again.

Why the network blocks encrypted DNS

Is the warning expected on this network?
Parental controls or content filterExpected
Pi-hole, AdGuard HomeExpected
Hotel, airport, café login pageUse a VPN
Work or school networkExpected
Security or VPN app on the phoneFixable, step 5
Old or misconfigured routerFixable, steps 2, 3, 6
iOS bug after an updateFixable, steps 1–3

The warning shows up far more often on innocent networks than on malicious ones. The common causes:

  1. Parental controls and content filters. Filters from internet providers, parental control routers and apps work by reading and answering DNS queries. They can't filter what they can't read, so they block encrypted DNS on purpose. On a home network with parental controls, the warning is the filter doing its job.
  2. Network ad blockers. Pi-hole, AdGuard Home and similar tools block ads by intercepting DNS. Same mechanism, same warning.
  3. Captive portals. Hotel, airport, café and hospital Wi-Fi often intercept DNS to redirect you to a login page. The warning is expected on these networks.
  4. Work and school networks. Organizations monitor or filter DNS for security and policy reasons, and many block DoH and DoT outright.
  5. Security apps and VPN apps. Some antivirus apps, content blockers and VPNs redirect DNS to their own resolver, which can clash with another encrypted DNS setting on the same device.
  6. Old or misconfigured routers. Some older routers block port 853, mishandle DNS forwarding or run outdated firmware.
  7. iOS bugs. Several iOS updates have shown the warning briefly on networks that worked fine before. Apple Community threads document cases that cleared up after a reboot or an update.

How to fix "This network is blocking encrypted DNS traffic"

Work through these in order. Start with the first two, which fix most one-off cases.

STEP 1–2 · 2 min
Forget the network, restart phone and router
Fixes most one-off cases
STEP 3–5 · 10 min
Updates, filters, DNS profiles
When the warning keeps coming back
STEP 6–7 · last resort
Router DNS settings, reset network settings
Wipes saved Wi-Fi networks

1. Forget the network and reconnect

  1. Open Settings > Wi-Fi.
  2. Tap the ⓘ next to the network.
  3. Tap Forget This Network, then confirm.
  4. Rejoin the network and enter the password.

This clears the cached network profile. Many users report the warning disappears right away.

2. Restart your iPhone and the router

Turn the iPhone off and on. Unplug the router for 30 seconds, then plug it back in. If the router's DNS forwarding got stuck, a restart usually clears it.

3. Update iOS and the router firmware

On the iPhone: Settings > General > Software Update. For the router, check its admin page or app for a firmware update. Both sides have had bugs that caused this warning.

4. Check for filters and ad blockers on the network

If your internet provider's parental controls, a parental control router, Pi-hole or AdGuard Home is running, that's the cause. You have a choice to make:

  • Keep the filter if you rely on it, especially with kids at home. The warning is the expected trade-off.
  • Turn the filter off in your provider's account or the tool's settings if you don't need it.
  • Configure encrypted DNS on your own device only. This protects that one device, but it also steps around the household filter, so do it on purpose, not by accident.

5. Look for DNS profiles and security apps on the iPhone

Go to Settings > General > VPN & Device Management. Look for DNS profiles or VPN configurations you don't use anymore, especially from old security or ad-blocking apps, and remove them. If you use a security app or VPN that has its own DNS feature, try pausing it to see if the warning changes.

While you're in Settings, check two more things:

  • Configure DNS. In Settings > Wi-Fi, tap the ⓘ next to the network and scroll to Configure DNS. If it's set to Manual with servers you don't recognize, switch it back to Automatic.
  • iCloud Private Relay. If you pay for iCloud+ and Private Relay is on, a network that blocks it can trigger privacy warnings too. In the same ⓘ screen, look for the Private Relay switch for this network. Turning it off for one network is fine at home; on public Wi-Fi, use a VPN instead.

6. Check the router's DNS settings

In the router's admin page (often 192.168.0.1 or 192.168.1.1), find the DNS or WAN settings.

  • If the DNS servers are set to an old or unusual resolver, switch to a mainstream one such as your provider's default, or a public resolver that supports encryption.
  • Make sure the router isn't set to intercept or redirect all DNS traffic, a feature some routers call "DNS hijacking", "DNS redirect" or "force DNS".
  • Some users on TP-Link, Eero and other forums report the warning cleared after changing the Wi-Fi security mode from WPA3-only to WPA2/WPA3 mixed, or after updating firmware. It's worth a try if nothing else works.
  • If your router or DNS filter has a blocklist, make sure it doesn't block mask.icloud.com and mask-h2.icloud.com, the hostnames Apple uses for iCloud Private Relay.

7. Reset network settings (last resort)

Settings > General > Transfer or Reset iPhone > Reset > Reset Network Settings. This wipes all saved Wi-Fi networks, VPN settings and custom DNS settings, so you'll need to rejoin networks afterward.

Should you fix it on public Wi-Fi?

Your home network
✓ Find the cause
✓ Fix router or filter settings
✓ Or keep the filter on purpose
Hotel, café, airport
✕ Don't try to fix their router
✓ Turn on a VPN
✓ Blocked? Use OpenVPN TCP 443

No. On a hotel, airport or café network, you don't control the router, and the warning is a fair description of the situation: your DNS lookups are readable by whoever runs the network, and potentially by other devices on it.

The right move is to protect your traffic instead of trying to change the network:

  • Use a VPN. A VPN sends all your traffic, including DNS, through an encrypted tunnel to the VPN server. The network sees one encrypted connection and nothing else. Because the DNS lookups travel inside the tunnel, it doesn't matter that the network blocks DoH or DoT.
  • If the network also blocks VPNs, switch the VPN protocol to OpenVPN over TCP port 443, the same port HTTPS uses. It gets past most hotel and campus firewalls that block by port, though networks with deep packet inspection can still detect it. We explain the differences in WireGuard vs OpenVPN vs IKEv2.
  • Avoid sensitive tasks like banking on an untrusted network without a VPN.

Private Relay vs. this warning

iCloud Private Relay, part of iCloud+, also encrypts DNS. According to Apple, it protects your web browsing in Safari, all DNS lookups from the device and unencrypted traffic from apps. Networks can block it too, but iOS shows a different message for that: "iCloud Private Relay is turned off for this network" or similar. If you see the encrypted DNS warning, Private Relay isn't necessarily involved.

Private Relay doesn't cover the rest of your app traffic, and it doesn't change your IP address for apps outside Safari. A VPN covers all traffic on the device.

How to check that your DNS is actually private

After you fix the warning, or once you're connected to a VPN, confirm it:

  1. Run a DNS leak test. The resolvers it lists should belong to your encrypted DNS provider or your VPN, not to the Wi-Fi network or your internet provider. Our guide on how to check your VPN for DNS leaks takes about two minutes.
  2. Check what sites can see. The Atomic VPN homepage shows your visible IP address, city and provider, and whether your DNS requests are exposed.

Atomic VPN: DNS inside the tunnel, on every network

  • All DNS lookups go through the encrypted tunnel, so a network that blocks encrypted DNS still can't read them.
  • IPv6 is blocked outside the tunnel by default, a common source of DNS leaks.
  • OpenVPN over TCP 443 for restrictive hotel, campus and office networks that block other VPN traffic.
  • No DNS query logs. RAM-only servers and an independently audited no-log policy.
  • $2 a month on the yearly plan, 5 devices, 88+ countries.

Apps for Windows and macOS are available now, and Macs can show the same warning in Wi-Fi settings. iOS and Android apps are on the way. Until then, setting Atomic VPN up on your router protects every device on your home network, including iPhones. See how to set up a VPN on any device.

Keep your DNS private on any network

Atomic VPN sends every DNS lookup through the encrypted tunnel, so it doesn't matter what the Wi-Fi blocks. One account, five devices, 88+ countries, from $2 a month on the yearly plan.

FAQ

What does "This network is blocking encrypted DNS traffic" mean?

Your iPhone tried to send DNS lookups encrypted, and the network blocked or intercepted them. The phone switched to plain DNS, so the names of sites you visit can be seen by whoever handles DNS on that network.

Is the encrypted DNS warning dangerous?

Not by itself. It's a notice that one privacy feature isn't available on this network, not a sign of a hack. On public Wi-Fi, treat it as a reminder to use a VPN.

Why does my home Wi-Fi say it's blocking encrypted DNS?

Usually because of parental controls from your internet provider, a Pi-hole or other ad blocker, a security app, or router settings. Forgetting and rejoining the network or restarting the router fixes most one-off cases.

What is DNS traffic?

DNS traffic is the stream of lookups your device makes to turn website and server names into IP addresses. Every site you open and many background app connections start with one.

What is encrypted DNS traffic?

Encrypted DNS traffic is DNS lookups sent through DNS over HTTPS (DoH) or DNS over TLS (DoT) instead of plain text. The network can see that your device is talking to a DNS server, but not which website names it asks about.

What is DNS traffic on Wi-Fi?

It's the DNS lookups your devices send through the Wi-Fi router. On most home networks the router forwards them to your internet provider in plain text, so the router owner and the provider can log which sites every device looks up.

What is DNS over HTTPS?

DNS over HTTPS (DoH) sends DNS lookups inside encrypted HTTPS connections on port 443, so the network can't read which names you look up. Most modern browsers and operating systems support it.

Should DNS over HTTPS be on or off?

On, in most cases. It keeps your DNS lookups private from the network. Turn it off only if it breaks a filter you rely on, such as parental controls, or if your workplace requires it.

Does a VPN fix the encrypted DNS warning?

A VPN makes the warning irrelevant: your DNS lookups travel inside the encrypted VPN tunnel, so the network can't read them even if it blocks DoH and DoT.

Does the warning mean someone can see my passwords?

No. Passwords, messages and page content are protected by HTTPS and app encryption. The warning only concerns the names of the servers you connect to.

‍

Questions and answers

Apps for everything you own

Windows icon
Windows
Download
Google Play icon
Android
Download
App Store icon
iOS
Coming soon
Android TV icon
Android TV
Coming soon
Chrome icon
Chrome
Coming soon
Firefox icon
Firefox
Coming soon
Linux icon
Linux
Coming soon

Stay private on any Wi‑Fi

One account, five devices, 88+ countries. From $2 a month on the yearly plan, cancel in one click.