DNS over HTTPS (DoH)
Traditional DNS sends queries in plain text, letting ISPs, network admins, and attackers see every domain you visit. DNS over HTTPS (DoH) encrypts these queries inside regular HTTPS traffic.
How DoH Works
Instead of sending a UDP packet to port 53, your device sends a DNS query as an HTTPS request to a DoH resolver (like dns.google or cloudflare-dns.com). The response comes back encrypted, indistinguishable from normal web traffic.
DoH vs DoT
DNS over TLS (DoT) is an alternative that uses a dedicated port (853). Both encrypt DNS, but DoH is harder to block because it uses port 443 (same as all HTTPS). DoT is easier for network admins to manage.
Privacy Benefits
- ISPs can't see which domains you query
- Coffee shop WiFi attackers can't snoop on your DNS
- Prevents DNS-based censorship and filtering
Concerns
- Centralization: Most DoH traffic goes to Google or Cloudflare, concentrating DNS data
- Enterprise: Makes corporate network monitoring harder
- Performance: Slightly slower than plain DNS due to HTTPS overhead
How to Enable DoH
Modern browsers (Firefox, Chrome, Edge) support DoH natively in settings. For system-wide DoH, configure your OS or router to use a DoH-capable resolver.