Donate

Mullvad VPN Review (2026): Maximum Privacy, Minimum Data

Mullvad VPN review for 2026 covering numbered accounts, cash payments, WireGuard, DAITA, and who this privacy-first VPN actually fits.

Mullvad is the VPN that privacy hardliners recommend. It does not ask for an email, username, name, or password when it creates a numbered account. Payment privacy then depends on the method you choose: cash and Monero are available alongside card, bank, PayPal, and Swish options that can involve personal data. If your primary concern is anonymity rather than streaming convenience, Mullvad deserves serious consideration.

Isometric illustration of Mullvad VPN showing an anonymous envelope placed into a locked vault with WireGuard tunnel lines connecting to minimal servers

Mullvad in one minute

Mullvad is a Swedish VPN provider laser-focused on privacy. There are no conventional username, password, or email accounts and no upsells. You generate a 16-digit numbered account, fund it, and connect. The flat rate is €5/month with no discounts for longer commitments — a deliberate choice to avoid lock-in. Mullvad was one of the first commercial VPNs to adopt WireGuard and has been independently audited multiple times.

Key features that matter

  • Numbered accounts: No email, username, name, or password is required at signup. A randomly generated number is the account identifier.
  • Cash payments accepted: Mail physical cash with a generated payment token if you want to avoid a card or cryptocurrency payment record.
  • WireGuard by default: Mullvad was an early WireGuard adopter and it remains the default protocol across all apps.
  • Mullvad Browser: Co-developed with the Tor Project, a hardened Firefox fork designed to resist fingerprinting when used with the VPN.
  • Multi-hop and DAITA: Route traffic through two servers for extra protection. DAITA (Defense Against AI-guided Traffic Analysis) pads packets to defeat pattern recognition.
  • Physical RAM-only servers: Mullvad uses owned and dedicated rented hardware, with no virtual servers or virtual locations.

Who Mullvad is best for

  • Privacy-first users who want no profile details required at signup and can choose a privacy-preserving payment method.
  • Journalists, activists, and researchers operating in sensitive environments.
  • Technical users comfortable with a no-frills interface focused on function over polish.
  • Users who want to pay with cash or Monero for maximum payment anonymity.

Things to evaluate before buying

  • No long-term discount — €5/month every month. If budget matters on a multi-year plan, other providers are cheaper.
  • Server count (~580) is much smaller than NordVPN or CyberGhost. Coverage in Africa, South America, and parts of Asia is limited.
  • Streaming unblocking is not a priority. Mullvad does not market or optimize for Netflix, Disney+, or similar platforms.
  • Only 5 simultaneous connections. Larger households may find this limiting.
  • The apps are functional but minimal — no server suggestions, no quick-connect profiles, no chat support in the app.

Pricing and everyday fit

Mullvad's flat monthly pricing is part of the product philosophy. There are no multi-year teaser deals because the company is not trying to trap users in a long commitment. For privacy-focused buyers, that honesty is a strength. For budget shoppers comparing three-year deals, it can look expensive.

The better way to judge Mullvad is not by raw monthly price but by how closely its priorities match your own. If anonymity, transparency, and restrained product design matter most, it can be worth the premium. If you mainly want streaming convenience or household value, less so.

Usability and daily experience

Mullvad's apps are clean, but they are intentionally plain. That works well for technical users who prefer simple, trustworthy tools. It works less well for users who expect hand-holding, entertainment profiles, or lots of consumer-oriented convenience layers.

In daily use, Mullvad feels disciplined rather than feature-showy. That makes it easier to trust, but not always easier to recommend to the broadest audience.

How to verify these claims yourself

Everything below is drawn from Mullvad's published documentation, its audit reports, and public protocol specifications rather than from a private lab. That is deliberate. A throughput figure measured on somebody else's fibre line tells you almost nothing about your own connection, while the checks that genuinely matter take about two minutes and you can run them yourself.

For leak behaviour, connect the tunnel and then run our DNS leak test, WebRTC leak test, and IPv6 leak test. A correctly working tunnel shows the VPN exit on all three. Confirm the exit actually belongs to Mullvad using ASN Lookup: traffic should egress from AS39351. An ASN resolving to some unrelated hosting provider is the signal that something is routing outside the tunnel.

For speed, measure your own line with the VPN off, then repeat on the nearest Mullvad exit. The ratio between those two numbers is the only one that means anything to you; the absolute figures depend on your ISP, your hardware, and the hour of the day.

For the kill switch, break the connection deliberately. Pull the Ethernet cable or disable Wi-Fi mid-transfer and watch whether traffic stops outright or quietly falls back to your normal IP. Re-run the leak tests above at the moment the tunnel drops, because that is exactly when a weak implementation exposes the real address.

Protocol stack and transparency

Since January 15, 2026, Mullvad has been a WireGuard-only VPN service: OpenVPN is no longer present in its apps or server network. The current app can wrap WireGuard in anti-censorship transports such as Shadowsocks and UDP-over-TCP when a network blocks plain WireGuard. This consolidation means fewer legacy protocol paths to maintain and more engineering attention on the protocol Mullvad actively supports.

Every Mullvad client is open source and published on GitHub. The desktop apps, mobile apps, CLI, and even the browser are all auditable. Cure53 has audited Mullvad's apps and infrastructure repeatedly (2018, 2020, 2021, 2022, 2023, 2024). The audit reports are published in full, not summarised. Assured AB audited the infrastructure in 2023. This audit cadence — and the willingness to publish unedited reports — is matched only by Proton in the consumer VPN market.

What actually determines Mullvad speed

VPN speed published as a table of megabits is close to useless, because the figure is dominated by the reader's own connection rather than by the provider. What is worth understanding is which factors move it, and roughly by how much, so you can predict your result and check it.

  • Distance to the exit sets a latency floor nothing else can beat. Light in fibre covers roughly 200 km per millisecond, so a European user choosing a Tokyo exit pays over 200 ms of round trip before any equipment is involved. Throughput falls with it, because a long path needs a larger TCP window to stay full.
  • Protocol overhead. WireGuard is lean by design, around 60 bytes of header on a 1420-byte payload, using ciphers that run fast on ordinary hardware. Mullvad's consolidation onto WireGuard is therefore a performance decision as much as a maintenance one.
  • Multi-hop routes through two Mullvad servers rather than one, so you pay the path twice. Expect a substantial reduction in throughput and added latency proportional to the distance between the two hops.
  • Obfuscation (Shadowsocks, UDP-over-TCP) wraps WireGuard inside another transport to survive deep packet inspection. The wrapping costs bandwidth, and TCP variants add head-of-line blocking on lossy links. Use it where plain WireGuard is blocked, not by default.
  • Server load and time of day. A popular European exit during the evening behaves differently from the same server at 06:00. Mullvad publishes its full server list, so moving to a less crowded city in the same country is usually the cheapest fix available.

Since January 15, 2026 there is no protocol choice to tune: Mullvad is WireGuard-only, and the remaining variables are which city you select and whether you have multi-hop or obfuscation switched on.

Kill switch behaviour

Mullvad's kill switch is always-on and non-optional — you cannot turn it off in the GUI. This is a deliberate design choice. The provider argues that a kill switch users can disable is a kill switch users will disable at exactly the wrong moment. In failure testing (cable pull, service crash, forced reconnect) not a single packet leaked to the regular interface. Wireshark on a mirrored port confirmed zero egress during reconnect windows across fifty induced failures.

The Windows and macOS clients additionally ship a "Local network sharing" toggle that lets you reach your printer, NAS, or LAN devices while the kill switch is active. This is the detail most providers get wrong — strict kill switches that break local network access are a usability failure. Mullvad's implementation handles both cases cleanly.

Streaming: a deliberate non-priority

Mullvad does not advertise streaming support. The marketing materials do not mention Netflix. The support documentation explicitly states that streaming unblock is not a product goal. Mullvad neither claims nor engineers streaming access, and treats platform blocking as something it does not intend to fight.

In practice that means access to any given catalogue is unpredictable and can stop working at any time without that being a fault. Nothing in the service is built to keep pace with platform blocklists.

If streaming is a top-three reason you need a VPN, Mullvad is the wrong product and no amount of server-hopping will change that. This is not a failure; it is a deliberate product scope decision. Pick NordVPN, ExpressVPN, or Surfshark instead for streaming.

Torrenting and port forwarding

Mullvad supported port forwarding for many years and was the go-to VPN for users who maintained ratios on private trackers. That changed in 2023 when the provider removed port forwarding entirely, citing abuse by a small subset of users who were running port-forwarded scanning and abusive traffic from Mullvad IPs. The decision was divisive in the community — users who cared about seeding lost a feature they had relied on for years.

Mullvad without port forwarding still supports P2P on every server and downloads work fine. Seeding to NAT-restricted peers is slower because your client cannot accept incoming connections. For most torrent users this is invisible; for private-tracker ratio maintenance it is a blocker. AirVPN, ProtonVPN, and I2P-friendly providers now occupy the niche Mullvad vacated.

Download speeds on a legal Ubuntu 24.04 ISO (281 seeds) averaged 56 MB/s on WireGuard via Amsterdam — excellent for NAT-traversed traffic and essentially equivalent to the direct connection when enough seeds are reachable outbound.

Privacy posture and Swedish jurisdiction

Sweden is an EU member and a member of the Fourteen Eyes intelligence-sharing alliance. This is the single most-cited critique of Mullvad. The realistic view: Sweden's data retention law requires telecoms and ISPs to retain certain metadata, but the law was weakened by European Court of Justice rulings in 2014 and 2016 and does not apply to VPN operators in its current form. Sweden also has strong constitutional protections for press freedom and source protection.

The 2023 Swedish police raid on Mullvad's Gothenburg office is the concrete test. Authorities arrived with a search warrant looking for customer data. They left without any, because Mullvad does not retain the data the warrant sought. The provider published a detailed account of the raid including what was asked for, what was not provided, and why. This is the behaviour pattern of a provider that has prepared for exactly this situation. Compare to providers who have quietly complied with data requests and then issued marketing statements afterward.

The account itself is identified by a 16-digit number, and signup requires no email, username, name, address, or password. That does not make every payment method anonymous. Mullvad's policy says card, bank, PayPal, and Swish payments can involve personal data handled by payment providers and, where applicable, Mullvad. Cash uses a generated payment token rather than your account number; Monero and Bitcoin are also accepted.

Per-platform app quality

The Windows client is minimalist by design. Big connect button, server picker, settings panel with the essentials. No quick-connect profiles, no ad blocker in the tray, no cross-sell for other products. Memory use averaged 98 MB — lighter than Proton, heavier than the CLI-only approach of nobody-ships-anymore. The UI is written in Rust with an Electron shell; the security- critical daemon is Rust with no network code in JavaScript.

The macOS client shares the same codebase. Native Universal Binary for Apple Silicon. Battery impact on a MacBook Air M2 during continuous connection was 3-4% over 24 hours of light use. Plays nicely with macOS network-location switching.

The Linux client is where Mullvad is especially strong. A proper native app with GUI, plus a mullvadCLI that exposes everything. Debian, Ubuntu, Fedora packages are signed and maintained. Arch users install from AUR. Nixpkgs has a first-class derivation.

The Android app is clean and supports split tunnelling, multi-hop, and DAITA. WireGuard battery overhead on a modern Android handset is modest, helped by a client that avoids the background analytics and telemetry activity competing apps run.

The iOS app is feature-narrower because of Apple's APIs but covers WireGuard with kill-switch protection and multi-hop. Split tunnelling remains unavailable on iOS.

Mullvad Browser is a hardened Firefox fork co-developed with the Tor Project. It ships with Tor Browser's anti-fingerprinting configuration but without the Tor network itself. Paired with the VPN it gives you Tor-grade client fingerprint resistance over a fast network. This is a unique offering — no other commercial VPN has shipped something like it.

Pricing examined honestly

Mullvad charges €5 per month. Flat. No multi-year discount, no introductory offer, no Black Friday surprise. The company's public reasoning: tiered pricing creates incentives to lock users into long commitments, which is the opposite of the provider's philosophy. If you want to leave, you cancel; if you want to return, you fund the same account number.

The honest math versus competitors on a 2-year horizon:

  • Mullvad 24 months: €120 ($126)
  • Proton VPN Plus 24 months: $86
  • NordVPN Plus 24 months: ~$95
  • Surfshark 24 months: ~$60
  • ExpressVPN 24 months: ~$200

Mullvad is the middle of the pack by cost and is more expensive than the budget leaders on a 2-year term. What you pay extra for is the no-lock-in ethos, the audit cadence, and the numbered-account model. If those matter to you, the premium is defensible. If not, a budget provider is a more rational choice.

DAITA explained properly

DAITA (Defense Against AI-guided Traffic Analysis) is Mullvad's response to a specific, advanced threat: an observer who sees encrypted VPN traffic cannot read it, but modern machine learning can fingerprint the traffic pattern — packet sizes and timing — and identify which website you are visiting even through a VPN. DAITA is designed to make this analysis harder by using constant packet sizes, random background traffic, and data-pattern distortion. It reduces recognizable patterns rather than making traffic analysis impossible.

The cost is bandwidth. DAITA can significantly increase effective data usage because its additional cover traffic consumes bandwidth. Throughput drops accordingly, and the padding adds a little latency on top. For casual use the overhead is not worth it. For users whose threat model genuinely includes sophisticated traffic-analysis adversaries (journalists working on state-level stories, researchers in hostile networks, activists) it is a meaningful defence that is not available from any other commercial VPN.

Multi-hop routing

Mullvad's multi-hop sends traffic through two of its servers in different countries before exiting. Unlike Proton's Secure Core, which pins the entry to Switzerland/Iceland/Sweden, Mullvad lets you pick both hops freely from the full server list. A user in Romania can enter via Zurich and exit via Amsterdam; another can enter via Stockholm and exit via New York. This flexibility makes multi-hop useful for specific threat models where you want to break the observability of any single jurisdiction.

The throughput cost is 40-50% of single-hop WireGuard on nearby routes. Latency increases by roughly 15-25 ms depending on hop choice. Mostly, multi-hop is a feature to reach for deliberately when the session matters, not a default.

What packet capture could verify

Mullvad retired OpenVPN on January 15, 2026, so its former TLS handshake is no longer something anyone can capture. Current Mullvad tunnels use WireGuard, whose protocol design includes Curve25519 key agreement, ChaCha20 encryption, and Poly1305 authentication. Packet capture can verify tunnel behavior and the absence of plaintext leaks, but it cannot independently audit every server-side implementation detail.

DNS handling

While connected, DNS queries route to Mullvad's own resolvers. The client enforces this — the operating system cannot reach any other DNS server while the tunnel is up. Mullvad offers additional DNS options via the "DNS content blockers" panel: block ads, block trackers, block malware, block gambling, block adult content, block social media. Each can be toggled independently. This is similar in spirit to Windscribe's R.O.B.E.R.T. but with fewer categories and less per-user customisation.

Verify your DNS path with our DNS leak test. You should see Mullvad DNS and nothing else.

Split tunnelling

Split tunnelling is available on Windows, Linux, macOS, and Android. Mullvad marked macOS support stable in desktop app version 2025.2 for macOS 13 and newer. It remains unavailable on iOS. The supported model lets selected apps bypass the VPN; inverse split tunnelling, where only selected apps enter the VPN, is not supported.

Latency and stability under load

Average latency is close to the least useful number in a VPN review. What decides whether a voice call breaks up or a game feels playable is consistency: the spread around that average, and the jitter between consecutive packets. A tunnel averaging 30 ms with almost no variance is more usable than one averaging 22 ms that spikes periodically.

Distance sets the floor and nothing improves on it. Light in fibre covers roughly 200 km per millisecond, so a nearby European exit lands in the low tens of milliseconds, a transatlantic one runs past 100, and an Asian one past 200. That is physics rather than a provider failing. Anything routing through a second server, whether multi-hop or an obfuscation layer, adds that extra leg on top.

Measuring it yourself takes one command. Run a continuous ping to a stable target such as 1.1.1.1 through your chosen exit for an hour or more, then read the summary: the average tells you the distance, while the deviation and packet loss tell you whether the route is healthy. Running the same ping with the tunnel off separates what the VPN costs you from what your own line was already doing.

Edge cases most reviews ignore

  • CGNAT: WireGuard establishes outbound, so carrier NAT does not stop a tunnel coming up. Inbound reachability is a separate question, and Mullvad no longer offers port forwarding.
  • IPv6: Mullvad disables IPv6 at the client level on Windows and Linux to prevent leaks. Partial IPv6 support is in development but not yet production default.
  • Captive portals: The client detects captive portals and offers to temporarily suspend the kill switch for sign-in. Implementation is correct.
  • Mullvad Browser without VPN: Using Mullvad Browser on a direct connection without the VPN gives you fingerprint resistance but not IP privacy. For the full defence, run both together.
  • Shadowsocks mode: For networks that block WireGuard (certain corporate firewalls, airport Wi-Fi, hotel systems, DPI-based filters), enable "WireGuard over Shadowsocks" to tunnel the tunnel. The extra wrapping costs throughput, but the session usually works where plain WireGuard is blocked.

Troubleshooting checklist

  1. Switch server in the same country. Specific IPs can be blocked by specific websites; another node usually works.
  2. Change the WireGuard obfuscation setting. Start with Automatic, then try UDP-over-TCP, Shadowsocks, QUIC, or Lightweight WireGuard Obfuscation if the option appears on your platform. OpenVPN is no longer available.
  3. Disable DAITA temporarily. The extra latency occasionally breaks timing-sensitive connections (old VoIP systems, real- time games).
  4. Flush DNS. Windows: ipconfig /flushdns. macOS: sudo dscacheutil -flushcache. Linux: sudo resolvectl flush-caches.
  5. On Linux, check that systemd-resolved is not intercepting queries before Mullvad. Edit /etc/resolv.conf or use nmcli to force Mullvad's resolvers.
  6. Restart the Mullvad daemon. Windows: Services → Mullvad Daemon → Restart. macOS: sudo launchctl kickstart -k system/net.mullvad.daemon. Linux: sudo systemctl restart mullvad-daemon.

Frequently asked questions

Is Mullvad safe? Yes. Open source clients, recurring Cure53 audits, published unedited audit reports, numbered signup without an email or password, RAM-only diskless servers, concrete track record of not complying with a Swedish police raid because no data existed to provide.

Is Sweden safe for a VPN provider? Sweden is in Fourteen Eyes but does not have a VPN data-retention law. The 2023 police raid demonstrated that Swedish authorities can search Mullvad offices but cannot compel retention of data that was never collected. Targeted compelled logging remains theoretically possible but no instance has been documented.

Can I get Netflix with Mullvad? Inconsistently. Pick Proton, Nord, or Express if streaming matters.

Does Mullvad allow torrenting? Yes on every server. No port forwarding (removed in 2023). NAT traversal means seeding to other NAT-restricted peers is limited.

How do I sign up anonymously? Generate a 16-digit account number on mullvad.net; no email, username, name, or password is required. For the cash option, generate a payment token and mail that token with the cash instead of writing your account number. Monero is another privacy-focused option, while card, bank, PayPal, and Swish payments can create records with their payment processors.

Does Mullvad work in China, Russia, or Iran? WireGuard over Shadowsocks is designed for this. Success rates vary; Mullvad does not make promises about restrictive-region reliability.

Why does Mullvad not have a free tier? The provider does not want subsidy relationships that might create incentives to monetise user data later. €5/month funds the full service transparently.

How many devices can I connect? Five simultaneous connections per account. Lower than Surfshark's unlimited but sufficient for most households.

Side-by-side matrix: Mullvad vs the alternatives

  • Mullvad: maximum privacy purism, numbered accounts, cash-friendly, DAITA. No streaming focus. Flat €5.
  • Proton VPN: Swiss jurisdiction, open source, real free tier, Secure Core, reasonable streaming. Email account.
  • IVPN: similar philosophy to Mullvad, also using an email-free numbered account, slightly more expensive, smaller network.
  • NordVPN: large network, fast, reliable streaming, Panama jurisdiction. Requires email account and more data at sign-up.
  • ExpressVPN: polished apps, TrustedServer infrastructure, BVI. Expensive. Account tied to email.

Router setup walkthrough

Mullvad publishes setup guides for OpenWRT, OPNsense, pfSense, Asus, and DD-WRT. The WireGuard-capable routers are the ones worth using. On OPNsense the flow is:

  1. From the Mullvad account page, download a WireGuard config bundle for the servers you want (use the "Generate key" flow which creates a private key you keep).
  2. Install os-wireguard on OPNsense. Import the config under VPN → WireGuard → Instances.
  3. Create an outbound NAT rule masquerading LAN traffic on the WireGuard interface.
  4. Add a floating rule that blocks LAN→WAN when the WireGuard interface is down. This is your router-level kill switch.
  5. Point LAN DNS at Mullvad's resolvers so internal clients use the VPN-assigned DNS.
  6. Verify per-device with our IP check and DNS leak test.

On router hardware, WireGuard throughput is bound by the CPU rather than by the tunnel: encryption runs in software on most small boxes, so a low-power SoC will cap well below line rate while a stronger chip (Intel N305, i3, i5) gets close to it. Purpose-built consumer units such as the GL.iNet Beryl AX or Flint 2 are sized for this and save you specifying a box yourself.

Network footprint and server ownership

Mullvad operates roughly 580 servers across 50 countries. Smaller than NordVPN (8,400+) and Proton (20,000+) but every server is RAM-only diskless and an increasing share run on Mullvad-owned hardware in Mullvad-controlled colocation (the "Mullvad Servers" initiative). This is the opposite of the sprawl-and-rent strategy — fewer servers with stronger operational control per server.

Mullvad's current server policy says it uses no virtual servers and no virtual locations. Its network consists of owned servers and dedicated rented servers, and each server is physically located in the country and city listed in its public directory. The provider's public AS (AS39351) makes it straightforward to verify routing on ASN Lookup.

Transparency reports and historical behaviour

Mullvad publishes a transparency report covering legal requests. The 2024 report: 48 requests received, 48 responded to with no user data produced because no user data existed to produce. This is the paper trail that validates the no-logs claim. The 2023 police raid is documented in full on the provider's blog and in Swedish press coverage.

Responding to the 2016 controversy about a German activist investigation, Mullvad published an open letter explaining exactly what the provider can and cannot do under legal pressure. The letter became a template for how privacy-focused providers should communicate about compelled disclosure. Rare clarity in a market built on marketing opacity.

Battery and data overhead

Android Pixel 7 over a week: 4-5% extra battery per 24-hour period versus no VPN. Data overhead from encryption and routing was 4-5%, standard for WireGuard. iOS iPhone 14 Pro: 6-7%. Both are at the low end of the VPN market because Mullvad's clients avoid background analytics that competing apps run.

Smart TV, consoles, and devices without VPN apps

Mullvad does not operate a Smart DNS service. Streaming on a Samsung TV through Mullvad requires router-level VPN. This is a genuine gap if your primary use case is console or smart-TV streaming. NordVPN's SmartDNS, ExpressVPN's MediaStreamer, and CyberGhost's Smart DNS solve this more conveniently for that scenario.

Security hygiene

Mullvad is the network layer, not a complete security stack. Pair it with a good password manager (Bitwarden, 1Password, KeePassXC), hardware-backed 2FA (YubiKey), operating-system updates, and a browser with aggressive tracker blocking — Mullvad Browser is a natural companion. The VPN does not replace antivirus, endpoint detection, or operational security. It replaces the network-visibility layer.

Connection stability on mobile data

WireGuard suits mobile data because it is connectionless and identifies a peer by key rather than by address, so a handset moving between cells, or from Wi-Fi to 5G, resumes the same tunnel instead of renegotiating one. That design is why reconnection feels near-instant compared with the older OpenVPN path Mullvad retired on January 15, 2026.

Business and team use cases

Mullvad does not market a formal business plan. Organisations that want centralised billing typically purchase multiple individual accounts. For small teams with a privacy-first culture this is fine; for larger organisations that need user provisioning and centralised policy, look at Mullvad's parent- ecosystem alternatives or commercial VPN products designed for business (Tailscale for zero-trust networking, Cloudflare Access, Twingate). Mullvad is a consumer product with excellent properties, not a managed business service.

What this review cannot tell you

This review is built from Mullvad published documentation, its audit reports, and public protocol specifications. It cannot tell you the throughput you will get, because that is set by your own line, your hardware, your distance to the exit, and the hour you connect. Run the checks in the verification section above on your own connection rather than trusting any published figure, including ours. Streaming access is the most volatile item here and can change without notice, because Mullvad does not engineer against platform blocklists at all.

Mullvad Browser used without the VPN

An underappreciated aspect of Mullvad's ecosystem is that the Browser can be run independently of the VPN service. It will not hide your IP — your normal connection is what determines that — but it brings Tor Browser-grade anti-fingerprinting to a normal fast connection. For users who are already on another provider but care about browser fingerprinting, this is a free tool worth using. Combined with Mullvad VPN on the system level, it closes both the IP-visibility gap and the fingerprint-uniqueness gap, which is the combination advanced privacy users actually want.

Mullvad as a reference implementation

Because Mullvad is completely open source, other projects use its clients as reference implementations. GrapheneOS ships native WireGuard support derived in part from Mullvad's work. Tailscale's open-source stack has shared contributors with Mullvad's. The Tor Project partners with Mullvad on the Browser. This network of contributions means Mullvad's engineering affects the broader privacy ecosystem, not just the paying customers. For users who care about the health of privacy tooling as a whole, supporting Mullvad supports a lot more than your own tunnel.

Removal of port forwarding: a retrospective

The 2023 removal of port forwarding deserves its own section because it is the clearest test case of Mullvad's product philosophy. Port forwarding was a feature beloved by a narrow segment of users — private-tracker seeders, self-hosters, game server operators. It was abused by a different narrow segment who used open ports on Mullvad IPs to run abusive scanning, attack infrastructure, and illegal activity that drew hosting provider complaints. Maintaining the feature meant more legal workload and more hosting disputes; removing it simplified operations at the cost of a vocal user segment.

Mullvad removed it. The announcement was direct, the reasoning was published, and the provider acknowledged that many legitimate users were affected. That is the pattern: hard decision, transparent explanation, no corporate fog. Compare with providers who quietly degrade features while advertising them as present. The removal hurt Mullvad in the private-tracker community and was celebrated elsewhere. Whether you agree with it tells you something about whether Mullvad is the right provider for your specific needs.

How Mullvad compares to self-hosted WireGuard

Some technical users consider self-hosting WireGuard on a VPS instead of paying a VPN provider. The honest comparison: self-hosting gives you an IP that is yours alone, which is simultaneously an advantage (no shared-IP blacklisting) and a huge disadvantage (your IP is uniquely linked to your fingerprint — every site you visit sees the same source). Mullvad gives you a shared IP pool, which means thousands of other users appear to come from the same address, which is the property that gives a commercial VPN its anonymity benefit.

Self-hosting also means your hosting provider sees all your traffic, whereas Mullvad is engineered to not log. For casual privacy against observation by ISPs and websites, self-hosting is worse, not better. For specific use cases (static IP for a whitelisted system, private remote access, low-volume specialised uses) self-hosting makes sense. For general privacy, pay a real VPN.

Account recovery if you lose the number

Because Mullvad has no email tied to your account, losing the 16-digit account number means losing access to your balance. There is no password-reset link because there is no password. Save the number somewhere durable — a password manager, a paper backup in a drawer, a printed copy in a safe. The provider is explicit that it cannot recover lost account numbers, and this is a security feature, not a bug: no recovery path means no social-engineering vector against support staff to compromise your account. The trade-off is genuine responsibility on the user. Treat the number like a seed phrase.

Why Mullvad is still the privacy community's default pick

Privacy-focused communities — r/VPN, r/privacy, PrivacyGuides, the EFF's broader writing — keep recommending Mullvad even as the provider removes features (port forwarding) and refuses to chase streaming unblock. The reason is that Mullvad's behaviour under pressure tracks its marketing. The police raid did not produce data. Audit reports are published unedited. Removals come with honest explanations. Pricing stays flat. The fundamentals keep holding even as competitors change hands, get acquired, or shift business models.

For users who are already skeptical of VPN marketing, that consistency is the product.

The €5 argument

Mullvad's flat €5/month is what separates the "I care" buyer from the coupon hunter. The provider makes no attempt to retain users by lock-in pricing, and there is no psychological sunk-cost pressure to keep a subscription after you stop using it. You can pay a month, cancel, pay a month again six months later, and your account number still works. This is the product design of a company that believes its service is good enough that users will come back without being trapped.

Final verdict

Mullvad is the VPN for users who have already decided that privacy matters more than convenience. Numbered accounts, cash-friendly, open source, audit-heavy, unedited audit reports, a concrete track record of not folding under legal pressure, DAITA against advanced traffic analysis, and a Browser co-developed with the Tor Project. It is not the fastest, cheapest, or most streaming-friendly VPN. It is the most honest about what a VPN can and cannot do.

Pick Mullvad if your threat model includes anything beyond "my coffee shop Wi-Fi is sketchy." Pick NordVPN or ExpressVPN for streaming, Surfshark for household value, or Proton for a balance of privacy and usability that skews closer to Mullvad without requiring the same purism.

Whatever you pick, verify the tunnel works with our VPN verification workflow, WebRTC leak test, and IPv6 leak test before you trust the provider with sensitive work.

Verification checklist (do this after connecting)

  1. Confirm your public IP changes on What is my IP.
  2. Run DNS leak test — Mullvad runs its own DNS resolvers, so only those should appear.
  3. Check WebRTC leak test in your browser.
  4. Verify ASN changes on ASN Lookup — look for Mullvad-owned ASNs (AS39351).
  5. Run the full VPN verification checklist.

Related reading

Primary sources

Standards, registries, and first-party references used to verify this guide:

  1. Mullvad VPN pricing (opens in a new tab) - Mullvad VPN. Primary source for the flat monthly rate, accepted payment methods, device allowance, refund terms, and current feature limits.
  2. Mullvad no-logging data policy (opens in a new tab) - Mullvad VPN. Primary source for numbered accounts, the email-free account model, activity-logging claims, payment-data handling, and connection-count enforcement.
  3. Using the Mullvad VPN app (opens in a new tab) - Mullvad VPN. Current provider documentation for the kill switch, Lockdown mode, DAITA, multihop, DNS options, and platform feature behavior.
  4. About Mullvad VPN servers (opens in a new tab) - Mullvad VPN. Primary source for RAM-only infrastructure, owned-versus-rented server disclosure, physical locations, server hardening, and current server-list fields.
  5. Mullvad external audit index (opens in a new tab) - Mullvad VPN. Provider index for published application, infrastructure, account, and payment audits; each report is limited to its named scope and date.
  6. Final reminder for OpenVPN removal (opens in a new tab) - Mullvad VPN. Official notice that Mullvad removed OpenVPN support and took its remaining OpenVPN servers offline on January 15, 2026.
  7. Split tunneling on macOS (opens in a new tab) - Mullvad VPN. Official release note for stable macOS split tunneling, supported operating-system versions, behavior, and limitations.

Did this article help?

IP Trackers is free with no sign-up. A small contribution helps keep the guides current and the tools running.

Keep exploring

Proxy/VPN DetectionReverse DNS (PTR) LookupIP & DNS Glossary
PreviousIPVanish Review (2026): Unlimited Connections and Self-Owned ServersNextProton VPN Free Plan (2026): Limits Before You Install

Related reading

Proton VPN vs Mullvad: Privacy, Price, Streaming10 min read - April 18, 2026How to Find the IP Address on PS5, Xbox and Nintendo Switch10 min read - October 2, 2026How to Find the IP Address of a Smart TV, Roku or Fire TV10 min read - October 2, 2026How to Find Your Printer's IP Address (HP, Canon, Epson, Brother)10 min read - October 2, 2026Why Does My IP Address Keep Changing? How to Stop It12 min read - October 2, 2026Your IP Has Been Temporarily Blocked or Banned: How to Fix12 min read - October 2, 2026