Adjusting key settings like private DNS, MAC address randomisation, and auto-connect on Android devices can significantly improve privacy and security when using public Wi-Fi networks, according to experts.
Public Wi-Fi on Android: the settings worth changing first
Connecting an Android phone to a new Wi-Fi network is usually routine, but the default setup can expose more than many users realise. How-To Geek notes that public and unfamiliar networks can leave DNS traffic, device identifiers and background data use more visible than they should be. That makes a few quick privacy checks worthwhile before trusting a hotspot with anything sensitive.
One of the most useful changes is private DNS. Standard DNS look-ups can be readable on the network, which creates room for interception or spoofed responses on hostile Wi-Fi. Android allows users to switch to a private DNS provider in connection settings, giving the connection an encrypted resolver path. Services such as Protectstar’s DNS Changer, ShieldDNS and Rethink DNS also show how Android users can route DNS through privacy-focused tools without root access, with options for filtering ads, trackers and unwanted connections.
It is also sensible to check MAC address randomisation. A device’s MAC address can otherwise act as a persistent identifier when it scans or joins Wi-Fi, which makes tracking easier across visits. Privacy guides from macadress.com and MacLookup explain that Android’s randomisation feature assigns a different identifier for specific networks, reducing the chance of long-term profiling. The same settings screen can also stop the phone from broadcasting its device name to the network.
Auto-connect deserves the same scrutiny. If a phone rejoins open or familiar public networks without prompting, it can reconnect in places where the user no longer wants to trust the connection. Turning off automatic reconnection gives more control, especially in cafés, stations and other shared spaces. Where a hotspot has limited data or a fair-use cap, marking it as metered can also help prevent background updates from consuming the allowance unexpectedly.
These changes will not make public Wi-Fi safe in absolute terms, and they do not replace cautious behaviour. Sensitive log-ins are still best left for a trusted mobile or home connection. But taken together, private DNS, MAC randomisation, disabled auto-reconnect and metered network controls can make an Android phone harder to monitor and less likely to leak data when it joins a network you do not control.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





