Mozilla VPN is one of several consumer VPN services that hides your IP address and routes your traffic through remote servers. Beyond simply masking your location, some VPNs offer extra controls — notably custom DNS and multi‑hop routing — so you can choose more privacy or more control when you need it.
What multi‑hop (double VPN) does and when to use it
Multi‑hop means your traffic is routed through two VPN servers in sequence instead of just one. The first server receives and encrypts your data, then forwards it through a second server which sends it on to the internet. That second server is often called an “exit” server.
The practical result is an additional layer of separation between your device and the sites you visit. If a single VPN server were compromised or coerced into revealing logs, a multi‑hop chain makes it harder to match your real IP to the final connection. It’s especially useful if you want stronger protection on untrusted networks (public Wi‑Fi) or when you’re dealing with very sensitive browsing.
Trade‑offs: extra security comes at a cost. Because traffic takes a longer route and is encrypted/decrypted more times, you can expect higher latency and slower throughput. Multi‑hop is overkill for everyday browsing, streaming or most routine tasks — save it for occasions where the extra privacy is worth the speed penalty.
Why custom DNS matters
DNS (Domain Name System) is the phonebook of the internet: it translates website names into the IP addresses your device connects to. By default your DNS requests usually go to a resolver provided by your ISP or your VPN. Choosing a custom DNS lets you pick a resolver that better matches your priorities.
Reasons to use a custom DNS: - Privacy: some DNS providers promise not to log or to anonymise queries. - Security: providers can block known malicious domains to protect you from phishing and malware. - Filtering and parental controls: some resolvers offer content blocking or family safe options. - Performance: a well‑run DNS resolver can be faster for lookups in your region.
Most VPN apps that support custom DNS let you enter the resolver of your choice in the app’s network or advanced settings. You can also set DNS at the operating‑system level if you prefer it to apply across all networks.
Caveats: changing DNS is a trust decision. A DNS provider can see which sites you ask about, unless you use DNS over HTTPS or DNS over TLS. If privacy is the goal, pick a reputable provider and check their policy on logging and data retention.
A sensible approach
These features are about choice. If you want a straightforward, fast VPN experience, the default single‑server setup is fine. Use multi‑hop when you need extra anonymity and accept slower speeds. Use custom DNS when you want different privacy, security or filtering behaviour than your default resolver provides.
If you’re interested, open your VPN app and look in the network or advanced settings to see whether these options are available and how to enable them. Read the provider’s documentation to understand defaults, logging policies and any performance implications before switching them on.