DNS over HTTPS (DoH) wraps your DNS queries in the same HTTPS encryption that protects ordinary web browsing — a meaningful privacy improvement for one specific part of the chain, worth understanding precisely rather than assuming it protects everything.
What DoH actually encrypts
DoH encrypts the DNS query and response as they travel between your device and your chosen resolver, using the standard HTTPS port and protocol — meaning this traffic looks, to a network observer, essentially identical to ordinary web traffic rather than identifiable DNS packets. This hides your specific query content from your ISP or anyone else observing that network segment.
What remains visible regardless
- The resolver itself still sees your queries in plaintext — encryption protects the trip there, not the destination's own visibility.
- Later connections — once you actually connect to the site you looked up, that connection (and the fact you're talking to that site's IP address) is visible to your ISP through ordinary traffic observation, DoH or not.
- Metadata like connection timing and volume can sometimes still allow some inference even when the specific DNS content is encrypted.
Why "encrypted" doesn't mean "invisible"
DoH is a real, meaningful privacy improvement for one specific threat model — a network-level observer trying to read your DNS traffic directly. It's not a comprehensive privacy solution on its own, and shouldn't be treated as making DNS activity untraceable end to end.
FAQ
Does DoH slow down browsing?
Generally negligible for most users — the overhead of wrapping DNS in HTTPS is small compared to typical network latency, though it varies by resolver and network conditions.
How is DoH different from DNS over TLS?
See DNS over TLS — both encrypt DNS traffic, but use different transport mechanisms with different network-level visibility characteristics.