DNS Privacy Explained: DoH, DoT and Encrypted DNS

DNS is the internet’s phone book: your device asks a resolver to turn a name like example.com into an address. By default these questions travel unencrypted, so your ISP and anyone on the network can see every domain you look up. Encrypted DNS, using DNS over HTTPS (DoH) or DNS over TLS (DoT), hides those lookups from outsiders.
What happens during a DNS lookup
Before your browser loads a page, it needs the site’s IP address. It sends a query to a DNS resolver, usually the one your ISP or router assigns, and the resolver replies. Classic DNS uses plain text, so the query and answer are readable by any party on the path.
That makes DNS a surprisingly rich record. Even if the page itself uses HTTPS, the list of domains you resolve reveals which services you use and roughly when. The resolver operator also gets that list.
DoH and DoT: what they change
Both technologies wrap DNS queries in encryption between your device and the resolver.
- DNS over TLS (DoT) uses a dedicated connection. It is easy for network admins to identify and manage because it uses its own port.
- DNS over HTTPS (DoH) sends DNS inside normal HTTPS traffic, so it blends in with web traffic and is harder to filter.
The benefit is the same: people between you and the resolver cannot read or alter your queries. A network cannot easily redirect you to a fake site by tampering with DNS answers either.
What encrypted DNS does not hide
Encrypted DNS is often oversold. Remember:
- The resolver still sees your queries. You are choosing whom to trust, not removing the observer. Pick a resolver with a clear privacy policy.
- The destination IP is still visible. Your ISP can see which IP addresses you connect to, which often reveals the site.
- SNI may reveal the hostname. In many HTTPS connections the site name is sent in a field that is not always encrypted, although newer technology is improving this.
- It does not block tracking. Ads and trackers still load.
So encrypted DNS closes one leak; it is not a replacement for a VPN or Tor.
How to turn it on
- In your browser: most major browsers have a “secure DNS” setting under privacy or security. Choose a provider or enter a custom resolver address.
- On your phone or computer: recent operating systems offer a private DNS or encrypted DNS option in network settings.
- On your router: some routers support DoT or DoH for the whole household, which saves configuring each device.
Pick the resolver by reading its privacy policy: look for statements about logging, retention and whether it filters content. Some resolvers offer optional malware or ad blocking.
Common problems
Encrypted DNS can bypass parental controls or corporate filters set at the network level, which is by design. Some captive portals, such as hotel sign-in pages, can fail until you temporarily disable it. If a site stops loading after a change, try another resolver before assuming the site is down.
DNS privacy in a layered setup
Think of privacy as layers. Encrypted DNS hides your lookups from the local network. A VPN hides your destinations from your ISP and your IP from sites. A tracker-blocking browser reduces what sites learn from cookies and scripts. Each layer addresses a different observer, and none of them covers everything alone. Setting encrypted DNS takes a minute, so it is a cheap first layer.
Choosing a resolver
Look for a resolver that publishes a privacy policy, states how long it keeps query logs, supports DoH or DoT, and validates DNSSEC, which helps detect tampered answers. Filtering options such as malware blocking are optional extras. Avoid resolvers with no named operator. If you run a home network, a local resolver that forwards over encrypted DNS can combine ad blocking with privacy.
Testing that it works
After enabling encrypted DNS, visit a DNS leak or resolver-check page and see which resolver answers. It should name the provider you chose, not your ISP. Test again after switching networks, since some operating systems fall back to the network’s resolver when encrypted DNS fails. If your setting has a strict mode that refuses to fall back, use it where privacy matters more than convenience.
Home network considerations
If you configure encrypted DNS on a router, every device benefits, including smart TVs and consoles that offer no DNS settings of their own. Keep in mind that devices with hard-coded resolvers may ignore the router, and that family filters set at the network level may stop working if individual browsers use their own encrypted DNS.
Frequently asked questions
Is encrypted DNS the same as a VPN?
No. It only protects DNS lookups. A VPN encrypts all your traffic and hides your IP from sites, which encrypted DNS does not.
Does DoH make me anonymous?
No. The chosen resolver sees your queries and your IP address, and sites can still identify you through other means. It prevents eavesdropping on the path.
Which is better, DoH or DoT?
Neither is stronger in encryption. DoH blends in with web traffic, while DoT is simpler for administrators to manage. Use whichever your device supports easily.
Key takeaways
- DNS lookups are usually plaintext and reveal the domains you visit.
- DoH and DoT encrypt queries between you and the resolver.
- You still must trust the resolver, and IP addresses remain visible.
- Turn it on in your browser, OS or router and test for leaks.


