Slow down before sharing. Urgency usually makes privacy worse. :)

Tools

Mullvad VPN

Mullvad is a VPN service based in Sweden, built around the idea that a VPN provider should know as little about you as possible. It's one of the most privacy-focused commercial VPN providers available.

Mullvad VPN

Why it matters

Most VPN providers ask for an email address, create an account tied to your identity, and accept payment in ways that link back to you. Mullvad takes a different approach, accounts are generated as random numbers, no personal information is required, and you can pay with cash or cryptocurrency. If you're going to use a VPN, the less the provider knows about you, the more the privacy benefit holds.

Mullvad is also consistently transparent about what it does and doesn't do, and has undergone independent audits of both its apps and infrastructure.

What Mullvad helps with

  • Hiding your browsing destinations from your internet provider, the ISP sees you're connected to Mullvad, not what you're accessing
  • Hiding your IP address from websites you visit, they see a Mullvad server address instead
  • Using public or untrusted Wi-Fi networks with less risk of interception
  • Bypassing network blocks on content filtered by your ISP or country
  • Routing DNS queries through the encrypted tunnel so your DNS lookups don't leak to your ISP's resolver

What Mullvad does not do

It does not make you anonymous. It moves trust from your ISP to Mullvad. Mullvad is designed to retain as little as possible, but it's still a commercial service you're trusting.

It does not protect your content from websites. You're hidden behind a Mullvad IP address, but the sites you visit still see everything you send them, logins, form submissions, what pages you load.

It does not protect against mistakes at the application layer. If you're logged into accounts, those accounts know who you are regardless of IP address.

It does not protect against tracking that doesn't use IP addresses. Browser fingerprinting, cookies, and login-based tracking work independently of your IP. See the Mullvad Browser page for an approach designed around that problem.

Tradeoffs to be aware of

All VPN traffic routes through Mullvad's servers, which adds latency. The impact varies by server location, connecting to a nearby server is generally fast enough for most use. Streaming and general browsing work fine.

Some services block VPN exit nodes. Banks and streaming platforms in particular sometimes refuse connections from known VPN IP addresses.

Mullvad costs €5/month. There's no free tier.

The kill switch is integrated, if the VPN connection drops, all traffic stops until the connection is restored. This protects against accidental IP leaks but can cause brief connectivity interruptions.

Practical guidance

Download Mullvad from the official site, mullvad.net

Generate an account number during setup. Write it down, it's your only access credential, and there's no email recovery.

Choose a server location close to you for best performance, unless you need to appear to be in a different country for a specific reason.

Enable the kill switch. It's off by default on some platforms.

The multihop feature routes traffic through two servers in different countries. This adds a layer of separation but also increases latency. Worth considering for sensitive work; not necessary for everyday use.

Going deeper

DAITA. Mullvad's Defense Against AI-guided Traffic Analysis is a feature that adds traffic patterns designed to make it harder for a network observer to infer what you're doing based on packet timing and volume, even when the content is encrypted.

Quantum-resistant tunnels. Mullvad offers WireGuard tunnels that include post-quantum cryptography. This protects against an adversary who captures traffic now and tries to decrypt it in the future using quantum computing. It's optional and adds overhead, but it's an unusually forward-looking feature for a commercial VPN.

Audits. Mullvad has published results from independent security audits of its applications and server infrastructure. These are available on their website. Independent auditing is a meaningful marker of a provider taking security seriously.

No affiliate program. Mullvad explicitly avoids affiliate partnerships and paid reviews. Many VPN review sites are financially incentivized to recommend particular services. Mullvad's absence from those incentive structures is worth noting when comparing providers.

Foldy

Foldy tip

Mullvad is one of the few VPNs that genuinely tries not to know who you are.

Related pages

  • VPNs explained, what a VPN does and doesn't do
  • Mullvad Browser, fingerprint-resistant browsing without routing through Tor
  • Tor, a different approach to network anonymity
  • Metadata, what even a good VPN doesn't protect
  • Threat modeling, helps clarify whether a VPN is what you actually need