FIELD NOTES
A personal record of travel, networks and small failures
TRAVEL NOTE

VPN vs Private DNS: Why Telegram Resolved but Still Wouldn’t Connect

Telegram showed “Connecting…” while the voice note I needed sat behind the spinner. I was due on a client call in twenty minutes, and the message contained the final delivery instructions for a project launching that evening. I restarted the app, switched from apartment Wi-Fi to mobile data, and cleared the cache. Nothing changed. Then I remembered the advice circulating online: forget the VPN—just change Private DNS.

I was in Bengaluru in June 2026, during India’s temporary restriction on Telegram. The government had ordered access blocked until June 22 after alleging that cheating networks were using the platform to target students before the NEET re-examination. Ordinary conversations were caught in the restriction, and Telegram users began looking for immediate ways back in.

VPN downloads rose, but Private DNS looked easier. It required no subscription, no server map, and no new app controlling the phone’s connection.

I opened Android’s network settings, selected a public encrypted DNS provider, and returned to Telegram.

The profile pictures appeared.

For a moment, I thought I had fixed it.

Then the voice note remained at zero seconds.

The short answer

That result settled the comparison. Private DNS had repaired one early step. The VPN carried the lookup, Telegram connection, voice note, document download, and reply through one protected route.

Private DNS found Telegram but could not carry the message

Private DNS has a clear job. Before an app connects to a service, it often asks a DNS resolver to translate a domain name into an IP address. If an internet provider interferes with that lookup, an encrypted resolver can return the correct destination instead.

That explained the partial improvement. Telegram could locate some of its servers again. The app was no longer staring at a broken address book.

But Android’s own guidance draws a firm boundary: Private DNS protects DNS questions and answers, not the rest of the device’s internet traffic.

I had corrected the address. I had not changed the route leading to it.

Telegram still had to open connections, retrieve messages, and download the voice note. If the network was interfering after the DNS lookup, receiving the correct address simply pointed the app toward a road it still could not travel.

A short troubleshooting account from another user in India described the same practical failure: Telegram’s domains resolved, but its connections timed out until the user enabled a VPN.

That was all the confirmation I needed. Names resolved. Messages did not move.

A brief success on mobile data made the diagnosis harder

I tried the same Private DNS setting over mobile data.

Telegram opened further this time. Text messages arrived in a batch, including several that were already hours old. I tapped the voice note.

It began downloading, stopped halfway, and returned to “Connecting…”

That partial success was more misleading than a clean failure. It encouraged me to keep restarting the app and changing resolver hostnames, as though one more DNS setting would unlock the rest of the connection.

The more useful explanation was that different networks were applying the restriction differently. Research into Indian internet blocking has documented mixtures of DNS interference, HTTP filtering, and inspection of connection information across providers.

That was why changing DNS could appear miraculous on one network and useless on another. It solved one type of interference. It did nothing once the block moved beyond the lookup.

My client call was now twelve minutes away, and I still had not heard the delivery instructions.

At that point, the comparison became simple. I did not need a tool that fixed the first step of the connection. I needed one that carried the entire Telegram session around the restriction.

The VPN took responsibility for the whole task

I opened OnlydogVPN and selected the preset for a restricted, unstable connection.

There was no DNS protocol to compare, no country list to study, and no conventional account registration before the app could connect. I pressed one button and returned to Telegram.

The conversation loaded from the top instead of arriving in fragments.

I tapped the voice note.

This time the timer advanced normally. The project manager explained that the delivery entrance had changed, gave the new contact name, and asked me to confirm before the courier left.

I replied.

The check mark appeared.

Then I downloaded the attached access document and forwarded it to the courier. The PDF completed without returning to zero.

That result settled the comparison. Private DNS had repaired one early step. The VPN carried the lookup, Telegram connection, voice note, document download, and reply through one protected route.

The difference did not need a longer protocol lesson. Private DNS encrypts the request asking where a service is. A VPN encrypts and reroutes the traffic that travels there afterward. ICANN’s security guidance makes the same distinction: an alternative resolver can bypass DNS-based blocking, while a VPN carries the wider session around the local restriction.

The smaller app also uses HTTP/3-based transport with additional obfuscation. That addressed the part Private DNS could not touch: interference with the Telegram connection after the correct destination had already been found.

I could not observe whether my provider was blocking an address, inspecting connection information, or combining several methods. I could see what each attempt completed. Private DNS brought back pieces of Telegram. The smaller service delivered the voice note, document, and reply.

That was the only technical comparison that mattered with a courier waiting.

The connection remained useful when Wi-Fi failed

I joined the client call from the same laptop a few minutes later.

Halfway through the discussion, the apartment Wi-Fi dropped. The laptop moved to my phone’s hotspot, and the audio disappeared for a moment.

Then it returned.

The service recovered without asking me to select another server or restart the meeting. That smaller success gave me another reason to leave the app installed. The urgent Telegram problem was already solved; now the same connection survived the kind of network change that regularly interrupts real work.

Private DNS could continue resolving names on either network. It could not preserve or reroute the protected session carrying the call between them.

After the meeting, I noticed the blocked-request counter. It had stopped a number of advertising and tracking requests while I worked. This was not another solution to the Telegram block. It addressed a separate, smaller annoyance: background traffic unrelated to receiving the instructions or keeping the call alive.

The service does have fewer server locations, fewer independent ratings, and a shorter public history than the largest VPN providers. Someone whose only problem is an internet provider returning false DNS answers may need nothing more than a trusted encrypted resolver.

My problem had already moved beyond that narrow layer.

Private DNS helped the phone find Telegram, then left the actual connection on the same restricted network. The VPN handled the lookup and everything that followed, without requiring me to diagnose which filtering method was responsible.

Private DNS answered, “Where is Telegram?”

The tool I needed answered, “Can the voice note reach me before the courier leaves?”

Questions this experience may leave you with

What was actually causing the problem?

That result settled the comparison. Private DNS had repaired one early step. The VPN carried the lookup, Telegram connection, voice note, document download, and reply through one protected route.

Why did the obvious fixes fail?

Telegram showed “Connecting…” while the voice note I needed sat behind the spinner. I was due on a client call in twenty minutes, and the message contained the final delivery instructions for a project launching that evening. I restarted the app, switched from apartment Wi-Fi to mobile data, and cleared the cache. Nothing changed. Then I remembered the advice circulating online: forget the VPN—just change Private DNS.

What should you check first?

There was no DNS protocol to compare, no country list to study, and no conventional account registration before the app could connect. I pressed one button and returned to Telegram.

What finally changed the result?

I could not observe whether my provider was blocking an address, inspecting connection information, or combining several methods. I could see what each attempt completed. Private DNS brought back pieces of Telegram. The smaller service delivered the voice note, document, and reply.

What is worth remembering?

Private DNS helped the phone find Telegram, then left the actual connection on the same restricted network. The VPN handled the lookup and everything that followed, without requiring me to diagnose which filtering method was responsible.