Skip to content
← VPNs & Privacy Tools
Mullvad icon

Mullvad

Expert review • Updated May 2026

The minimalist privacy VPN — one product, one price, no email, and a track record that survives an actual police raid.

Check Pricing (opens in new tab — affiliate link) Intermediate Solo / Researcher Desktop, mobile, router

Expert rating

4.7/5

  • Performance — 4.4
  • Privacy posture — 5.0
  • Transparency — 4.9
  • Value — 4.3
Visit Website (opens in new tab — affiliate link)

Who Mullvad is, in one paragraph

Sign up for Mullvad and you are handed a 16-digit number. That is the whole account. No email, no username, no password, no recovery flow — lose the number and the subscription is gone, and support cannot help you, because there is nothing on their side to match you against. Most people read that as an inconvenience. It is the product. Mullvad is operated by Amagicom AB, a small, privately held Swedish company in Gothenburg founded in 2009 by Daniel Berntsson and Fredrik Strömberg. It has never taken outside investment, employs roughly 50 people, and sells exactly one thing: a €5-a-month subscription with no commitment, no tiers, no upsells, no "lifetime" deal and no streaming pitch. The founding position — that the operator should know as little about its users as the technology permits — is why the email field does not exist, and it explains nearly every other strange-looking decision on this page. Mullvad also works directly with the Tor Project on the Mullvad Browser, which is broadly the Tor Browser fingerprinting posture pointed at a VPN exit rather than the Tor network.

Backend architecture & engineering

Mullvad is WireGuard-only after the OpenVPN sunset completed in January 2026. The data path is the simplest of the three providers reviewed here — there is no proprietary protocol layer like NordLynx and no multi-hop default like Proton's Secure Core. Sessions are identified by an ephemeral WireGuard public key rotated on every reconnection; the account database stores only the account number, the expiry date, and the most recent rotated key.

flowchart LR A[Your device
Mullvad client] -->|WireGuard
UDP 51820| B[Edge server
RAM-only] B -->|Local NAT| C[Egress IP
shared] C -->|Plain TCP/UDP| D[Internet] A -.->|DAITA pacing /
cover traffic| B B -.->|Auditable
System Transparency| E[(Boot attestation
signed image)] style B fill:#0e1a2b,stroke:#f59e0b,color:#fff style C fill:#0e1a2b,stroke:#f59e0b,color:#fff

Two architectural features genuinely set Mullvad apart. The first is the System Transparency programme — Mullvad publishes the boot image its servers run, signs each release, and works with hardware vendors to publish boot attestations from each server. The point is that a third-party auditor can verify which image is actually running on a Mullvad server today, not just trust Mullvad's word that the audited image is the deployed one. NordVPN's RAM-only fleet and Proton's stateless fleet conceptually do the same thing, but neither publishes boot attestations to the public.

The second is DAITA: Defence Against AI-guided Traffic Analysis, shipped in 2024. Encryption hides what is in your packets. It does not hide how big they are or when they arrive, and those two properties alone are enough to distinguish a video call from a large download from an idle chat client — raw WireGuard produces a clean, distinctive shape for each. DAITA pads and paces packets and injects cover traffic at the tunnel layer to smear that shape. It is the only meaningful defence any commercial VPN currently ships against traffic-analysis side channels; Proton and Nord have nothing equivalent. It is also not free: you are paying bandwidth to send traffic that carries nothing, and on a metered or mobile connection that cost is yours, not Mullvad's.

The full fleet — diskless RAM-only servers running a signed Linux image — was completed in late 2023 in direct response to the April-2023 Stockholm police raid (see incidents below). Worth being precise about what RAM-only buys: it defeats seizure of a powered-down box and it defeats the forensic recovery of anything that outlived a reboot. It does nothing at all against an adversary with live access to a running server, which is the scenario the System Transparency attestations are there to make harder rather than impossible.

Traffic monitoring, encryption & network privacy

Standard WireGuard cryptography — ChaCha20-Poly1305, Curve25519, BLAKE2s, HKDF — with key rotation on every reconnect. Mullvad shipped a post-quantum WireGuard preview using Classic McEliece + Kyber/ML-KEM hybrid in 2023, ahead of Proton's similar work in 2024, and it is now enabled by default on roughly half of Mullvad's fleet. Practically this protects against harvest-now-decrypt-later archival attacks; it does not change anything about your day-to-day stream confidentiality.

DNS resolves on the same node that terminates your tunnel — no third party in the path, and the resolvers carry optional ad and malware filter lists you toggle in the client. Because nothing at the egress writes to disk, there is no query history to retain. The filter lists are worth a caution that Mullvad's own documentation gives and most users skip: a blocklist that breaks a checkout page or a corporate SSO redirect breaks it silently, weeks after you enabled it, and nobody connects the two. If something stops working, turn the lists off before you start debugging anything else.

Legal compliance, jurisdiction & law enforcement

Sweden is a 14-Eyes member with an EU data-retention regime that the CJEU struck down in 2014 (Digital Rights Ireland) and which has been in legislative flux ever since. On paper that is a worse jurisdiction than Switzerland (Proton) or Panama (Nord), and jurisdiction-shopping marketing will tell you so. Mullvad's answer is engineering rather than paperwork, and the distinction matters: a no-logs policy is a promise a court can order broken, prospectively, with a gag attached. A no-logs architecture means the order arrives and there is nothing to produce. Sweden can compel Mullvad to hand over what Mullvad has. What Mullvad has is an account number, an expiry date and a rotating public key. The 2023 raid is the field test.

The April 2023 Stockholm raid — the most important data point in commercial VPN history

On the morning of 18 April 2023, Swedish police arrived at Mullvad's Gothenburg office with a search warrant seeking customer data tied to a specific case. Mullvad's lawyers explained, on the record, that the company does not store the requested data and that even if the police seized every server they would obtain nothing useful — the data does not exist to be seized. The officers consulted with the prosecutor, agreed that seizing servers would be pointless, and left the premises with no equipment and no data. The raid is documented in Mullvad's transparency report, in Swedish press coverage, and in subsequent independent reporting.

No other major VPN provider has been through a comparable adversarial process and emerged with this outcome. NordVPN's 2018 Finland breach was a third-party datacenter problem; Proton's 2021 Mail case involved compelled metadata that did exist. Mullvad's raid produced the result the company's architecture had been designed to produce.

Data breaches & incident response

Mullvad has had no known data breach. The only notable client-side issue was a DNS leak in the Android app under specific OS-level VPN-toggle conditions, disclosed and patched in October 2022. Mullvad publishes the full report and the corresponding code change on its security blog. Incident communications are unusually direct — short, technical and dated, more like a CERT advisory than a corporate blog post. Compared to NordVPN's 19-month delay on the 2018 Finland disclosure, the difference in incident-response posture is stark.

Company transparency & trustworthiness

Mullvad's transparency record is the cleanest in the industry. Independent infrastructure audits by Cure53 (2018, 2020) and Assured AB (2021, server infrastructure). Public reproducible builds. Public boot attestations. Public, dated, dry incident reports. The owners are named and reachable; the company hosts an open recruiting page that names every team. There is no marketing department in any meaningful sense and the website refuses to claim things the engineering team can't ship. The principal frustration with Mullvad — that it's plain, has no streaming pitch and no affiliate program — is the same posture that makes it trustworthy.

Performance & reliability

On a gigabit line to a same-continent server, Mullvad's standard WireGuard delivers 500–750 Mbps single-stream — slower than NordLynx's modified WireGuard, faster than ProtonVPN's userspace WireGuard. With DAITA on, expect a 10–25% throughput hit and an extra 5–15 ms of latency, which is the engineering cost of the cover-traffic shaping. Server count (~700) is a fraction of Nord's ~6,400, but the servers are predominantly owned and Mullvad is unusually willing to publish utilisation data per server so you can pick a quiet one.

Streaming is the explicit blind spot, and it is a choice rather than a failure. Keeping a fleet unblocked means maintaining residential IP pools and a working relationship with the platforms doing the blocking, which is precisely the kind of ongoing identifiable relationship Mullvad has built the company to avoid. If you want Netflix US from outside the US, buy NordVPN. Port forwarding is gone too — removed in June 2023 after sustained abuse and the takedown pressure that followed — which rules Mullvad out for a chunk of self-hosting and torrenting use. The pattern is consistent: where a feature would require Mullvad to know more about you or negotiate on your behalf, Mullvad drops the feature. Read the missing checkboxes as the design, not the gap.

How Mullvad stacks up against NordVPN & ProtonVPN

Spec Mullvad ProtonVPN NordVPN
Identity required at signup None — 16-digit random account number Email (anon email OK) Email + payment metadata
Cash payment by mail Yes, in any major currency Yes (BTC easier) Crypto only
Pricing tiers One — €5/mo flat, no commitment Free / Plus / Unlimited Std / Plus / Complete
Server fleet ~700 servers, 40+ countries ~3,300, 90+ countries ~6,400, 60+ countries
Owned vs rented Mostly owned hardware ("Mullvad servers") Mixed; Secure Core fully owned Mixed; colocation fleet owned
Reproducible builds Yes — desktop & mobile Partial No
Traffic-shaping defence DAITA (defence against AI-guided traffic analysis) None equivalent None equivalent
Default protocol WireGuard only (OpenVPN sunset Jan 2026) WireGuard / OpenVPN / Stealth NordLynx (WireGuard)
Streaming claims None — actively discouraged Paid plans only Aggressive marketing focus
Public incident history 2023 Stockholm police raid — no data seized 2021 Mail-only compulsion case 2018 Finland server compromise (disclosed 2019)

Pros & cons

Use Mullvad if…

  • Your threat model includes the VPN provider itself.
  • You want to pay cash by mail and never share an email address.
  • You're a researcher, journalist or activist who wants DAITA defences.
  • You value engineering minimalism over a feature checklist.
  • You want a provider whose claims have survived an actual police raid.

Avoid Mullvad if…

  • You want Netflix US, BBC iPlayer or Disney+ from outside their regions.
  • You need port forwarding for torrenting or self-hosting.
  • You expect 24/7 live-chat support and a slick onboarding.
  • You're shopping primarily on price — Nord's 2-year plan is cheaper per month.
  • You want servers in 100 countries — Mullvad sits at ~40.

Verdict

Mullvad is the VPN I personally use, and the one I recommend to anyone whose threat model places the provider itself in the adversary list. The account-number model removes a class of identifying metadata that ProtonVPN and NordVPN both still collect; the engineering — RAM-only fleet, System Transparency, DAITA, reproducible builds — is the most aligned with the marketing claims of any provider in this comparison; and the 2023 raid is the field test that vindicated the architecture. The trade-offs (no streaming, smaller fleet, no port forwarding) are real, and if those matter you should pick differently. If they don't, Mullvad is the strongest choice on this page.

Sponsored Links

Subscribe to my newsletter

Receive my case study and the latest articles on my WhatsApp Channel.

Warning

Ask CyberROX AI