# Privacy warning: this network is blocking encrypted DNS traffic. What it means on iPhone and whether you should worry URL: https://webvpn.org/encryption/network-blocking-encrypted-dns-traffic/ Updated: 2026-09-12 What the iPhone warning This network is blocking encrypted DNS traffic means, why a Wi-Fi network shows it, whether it is dangerous, and what it says about the router. The privacy warning "This network is blocking encrypted DNS traffic" on an iPhone means that the Wi-Fi network intercepts or blocks the encrypted DNS protocols iOS tried to use, forcing your device to send domain lookups in plain text to the network's own DNS server, so the network operator can see the names of the sites and services your device contacts. It appears on many home routers, mesh systems and networks with parental controls or ad blocking, because those features work by capturing DNS. It is not a sign of malware or decrypted traffic, but it does mean your lookups are visible on that network. The wording of the warning frightens people into thinking their connection has been compromised, when most of the time it describes a router configuration they or their ISP chose. This guide explains exactly what iOS is detecting, why home and public networks trigger the warning, what the network can and cannot see, when the warning deserves concern, and what to do about it, with the fixes themselves detailed in the companion guide on this site. ## What iOS is checking Since iOS 14, iPhones and iPads support encrypted DNS, described in the encrypted DNS guide on this site, and iOS probes networks for it. When you join a Wi-Fi network, iOS tests whether encrypted DNS works, whether through a configured DNS profile or through the network's own resolver. If the network's DNS server does not support encrypted protocols and the network prevents devices from reaching outside encrypted resolvers, or if the network redirects all DNS traffic to itself, iOS concludes the network is blocking encrypted DNS and displays the privacy warning on the Wi-Fi details screen. The same screen may also show a warning about the network's DNS not supporting encryption, or about a lack of a private Wi-Fi address; they are related but distinct. The warning is informational. iOS continues to work on the network, using the plain DNS it is forced into. The warning is Apple telling you that a privacy protection it normally provides is unavailable here. ## Why networks trigger the warning Several common configurations cause it. Routers that redirect DNS. Many consumer and ISP-provided routers intercept all DNS traffic on port 53 and answer it themselves, to apply parental controls, to redirect mistyped domains, or simply as a default. If the router also blocks the ports encrypted DNS uses, or does not support encrypted DNS itself, iOS sees the block. Filtering devices. Pi-hole, AdGuard Home and similar tools work by being the network's DNS server, and administrators often force all DNS through them so devices cannot bypass the filtering. That forcing is exactly what iOS reports. The blocking guide on this site describes these setups from the administrator's side. Mesh and managed Wi-Fi systems. Some mesh systems and subscription security features route DNS through the vendor's filtering service, and some ISP gateways run content filtering that requires intercepting DNS. Public and corporate networks. Schools, workplaces, hotels and public Wi-Fi frequently block outside DNS to enforce content policies, capture logins through captive portals, or monitor usage. Captive portals in particular intercept DNS before you have authenticated. Ubiquiti and similar prosumer gear. Features such as ad blocking or content filtering on UniFi and comparable systems redirect DNS and trigger the warning on every Apple device in the household until configured to allow or provide encrypted DNS. ## What the network can see, and what it cannot With encrypted DNS blocked, the network's DNS server receives every lookup your device makes: the websites you open, the services your apps contact in the background, the update servers, the messaging platforms. Each is a domain name with a timestamp, tied to your device on that network. This is meaningful information about your habits, which is why iOS treats it as a privacy matter. The network cannot see the contents of your HTTPS connections, which remain encrypted end to end between your device and the sites, as the HTTPS guide on this site explains. It cannot read your messages, passwords or the pages you view. It cannot decrypt anything. It can also, in principle, answer your lookups falsely, blocking or redirecting sites, which is how filtering works and how some captive portals operate. ## When the warning is a concern On your own home network, the warning describes your equipment's configuration. If you run a filter deliberately, it is expected and you can make the filter itself use encrypted DNS upstream, as the fixing guide on this site describes. If you did not configure anything and the warning appears, your router or ISP is intercepting DNS, and you may prefer to change that. On a public network, the warning tells you the operator sees your lookups. On a network you do not trust, this is a reason to turn on a VPN, which carries DNS inside its tunnel and makes the warning irrelevant, as the VPN guides on this site describe. The warning by itself does not indicate an attack; an attacker who controlled the network would gain the same visibility with or without the warning, and the appropriate response, a VPN, is the same. The warning would be more concerning if it appeared on a network that previously did not show it and nothing changed in your equipment, which could indicate a new device on the network answering DNS. Checking the router's DHCP client list and its DNS settings resolves the question. ## What to do - Read the fixing guide on this site for the step-by-step options, which fall into three categories. - On your own network, reconfigure the router or filter to permit encrypted DNS, or to provide it, so iOS is satisfied and lookups are encrypted upstream. - On any network, install a DNS profile or use an app that configures encrypted DNS to a resolver of your choice; if the network blocks that too, the warning remains accurate and a VPN is the remaining option. - On untrusted networks, use a VPN, which removes the network from the picture entirely. - If you simply want the warning gone and accept the network seeing lookups, there is no toggle to dismiss it; it reflects a fact about the network. ## A five-point summary - The warning means the network forces plain DNS and can see your lookups. - It is caused by routers, filters, mesh systems and network policies that intercept DNS. - It does not mean your traffic is decrypted or that you are under attack. - On your own network, reconfigure; on others, use a VPN. - The fixing guide on this site provides the steps for each situation. ## What Apple and network vendors document The explanation above follows Apple's documentation and the vendors' own descriptions of their features. Apple documents that iOS and iPadOS support encrypted DNS through DNS over HTTPS and DNS over TLS, and that the Wi-Fi settings display a privacy warning when a network prevents encrypted DNS, along with related warnings about DNS servers that do not support encryption and networks that require a device's real hardware address. Vendors of filtering products such as Pi-hole and AdGuard Home, and of prosumer networking equipment, document that their DNS-based filtering requires devices to use the local resolver and describe how to configure encrypted upstream DNS and how to handle Apple's warning. Network security practitioners describe DNS interception as a common and usually benign feature of home and enterprise networks, note that it grants the operator visibility into domain lookups, and recommend a VPN on untrusted networks regardless of whether the warning appears. ## A warning about visibility, not an alarm Your iPhone is telling you that on this network, someone can see which sites you look up. At home that someone is your router, and the fixing guide on this site shows how to give it encrypted DNS of its own. Elsewhere, it is whoever runs the Wi-Fi, and a VPN makes the question moot. Either way, the warning has done its job by making a normally invisible fact visible. ## FAQ Q: What does this network is blocking encrypted DNS traffic mean? A: It means iOS tried to use encrypted DNS on the Wi-Fi network and found that the network intercepts or blocks it, forcing devices to use the network's own DNS server in plain text. As a result the network operator can see the names of the websites your devices look up while connected. Q: Is the blocking encrypted DNS traffic warning dangerous? A: Usually not. It appears on many home routers, mesh systems and networks with parental controls or ad blocking, because those features work by intercepting DNS. It does not mean the network is infected or that your traffic is being decrypted. It does mean that domain lookups are visible to whoever runs the network. Q: Why does my own Wi-Fi show the blocking encrypted DNS warning? A: Your router or a device on your network, such as a Pi-hole, AdGuard Home, or a mesh system with built-in filtering, is redirecting DNS queries to itself, and either blocks or fails to support the encrypted DNS protocols iOS probes. Some ISP-supplied routers do this by default for their content filtering or DNS redirection. Q: What can the network see if encrypted DNS is blocked? A: The domain names your device looks up, such as the sites you visit and the services your apps contact, with timestamps. It cannot see the contents of HTTPS traffic, your passwords or messages. Domain names alone reveal a lot about browsing habits, which is why iOS raises a privacy warning rather than a security alert. Q: Does the warning appear on Android or Windows? A: Not in the same form. Android's Private DNS setting fails to connect and shows a warning or falls back depending on the mode, and Windows and macOS silently fall back or fail depending on configuration. iOS is unusual in surfacing the condition prominently on the Wi-Fi settings screen.