Your phone's DNS, filtered by you.

NetShield runs a local VPN on your Android device to intercept DNS queries at the network level. Block ads, trackers, malware, and telemetry - all without root access.

No root required - Android 10+ - Open source

Your apps
NetShield VPN
Upstream DNS
Allowed Blocked
630+ default blocked domains / 0 analytics collected / 100% on-device processing / No root required

DNS filtering, not content blocking

NetShield uses Android's VpnService to create a local DNS resolver. Every DNS query from your apps passes through it. Domains on your blocklist never leave the device - they get a null response. Everything else goes to your chosen upstream resolver.

01

Enable protection

Tap the start button. Android asks for VPN permission. That's it - NetShield begins intercepting DNS traffic immediately.

02

Rules are evaluated

Each DNS query is checked against your allowlist, blocklists, and custom rules using a reversed-domain trie for fast matching.

03

Blocked or forwarded

Blocked domains get a null response. Allowed domains are forwarded to your upstream resolver and cached according to DNS TTL.

Built for control

Every DNS query is logged. Every rule is yours to edit. Every domain can be tested before it matters.

Live DNS activity log

See every query in real time - domain, action, and which rule matched. Search, filter, and clear on demand.

Rule priority engine

System safety, user allowlist, user blocklist, imported lists, default allow. Allowlist always wins over blocklists.

Custom blocklist

Add exact domains or suffix rules. Categorize as ads, trackers, malware, or telemetry. Toggle individual rules on or off.

Blocklist import

Import blocklist files from local storage. Remote sources can be added in future releases.

DNS cache with TTL

In-memory cache respects DNS TTL. Reduces upstream queries and speeds up repeated domain lookups.

Test mode and rule tester

Enter any domain to see the DNS response, IP addresses, rule match, and response time - before it matters in production.

Import / export config

Export your allowlist, custom rules, blocklist sources, and settings as JSON. Restore on a new device.

Custom DNS resolvers

Use system default, or configure your own UDP/TCP upstream. DoH and DoT support is planned for future releases.

Developer diagnostics

VPN status, DNS engine state, query count, cache size, rule count, memory usage, and last DNS error - all visible.

Four categories of blocking, one rule engine

NetShield ships with 630+ default blocked domains across four categories. Every domain can be individually toggled, edited, or removed. You own the rules.

View the full default list

Ads

DoubleClick, AdSense, Taboola, Outbrain

227

Trackers

Google Analytics, Hotjar, Mixpanel, Segment

167

Malware

Known C2 servers, phishing domains, botnets

88

Telemetry

Microsoft, Mozilla, Crashlytics, Flurry

147

Your DNS stays on your device

NetShield operates entirely locally. DNS logs are stored only on your device and are never sent to an external server. No analytics are collected. DNS queries for allowed domains are forwarded to your selected upstream resolver, which may log them according to its own privacy policy.

0
Analytics events sent
0
DNS logs uploaded
100%
On-device processing

What DNS filtering can and can't do

Blocks any domain identified at the DNS level - ad servers, tracker endpoints, known malware C2 domains, and telemetry endpoints.

Works without root, using Android's official VpnService API.

Cannot block ads served from the same domain as content. If an ad and a page load from the same domain, DNS filtering cannot distinguish them.

Per-app DNS attribution is only available where Android's VPN API reliably provides it. NetShield does not fabricate attribution when it cannot be determined.

Questions

Does NetShield require root?
No. NetShield uses Android's VpnService API, which works without root. You only need to grant VPN permission when you start protection.
Does it block all ads?
No. DNS filtering only blocks domains identified at the DNS level. Ads served from the same domain as content cannot be blocked this way. NetShield is a network-level filter, not a content filter.
Where are my DNS logs stored?
Only on your device, in a local file. You choose the retention period: 1, 3, 7, 30 days, or disabled. Logs are never uploaded anywhere.
Can I use my own DNS resolver?
Yes. Configure any UDP or TCP upstream resolver in the DNS Servers screen. DNS-over-HTTPS and DNS-over-TLS are planned for future releases.
What Android version is required?
Android 10 (API 29) or later. The app uses VpnService, foreground service with special-use type, and modern Android networking APIs.

Start filtering your DNS today

Install NetShield, tap start, and grant VPN permission. That's it. Every DNS query from every app passes through your rules.

Download for Android

Android 10+ - 6MB - No root - No analytics