DNS over TLS (DoT) takes a different technical approach than DNS over HTTPS to the same basic goal — encrypting DNS queries in transit — using its own dedicated network port rather than blending in with ordinary web traffic.

The dedicated port approach

DoT runs on port 853, specifically reserved for encrypted DNS traffic, rather than sharing port 443 with regular HTTPS web traffic the way DNS over HTTPS does. This means DoT traffic is identifiable as DNS traffic at the network level — visible as "DNS is happening," even though the actual query content is encrypted and unreadable.

System-level deployment

DoT is commonly implemented at the operating-system or network level rather than per-browser, meaning a properly configured DoT setup protects DNS queries from every application on the device consistently, rather than only the specific browser that has its own DoH setting enabled. This can be an advantage for consistent, device-wide protection.

Comparing the two encrypted-DNS approaches

  • DNS over HTTPS — blends in with web traffic on port 443, making it harder for network-level filtering to selectively block, but often configured per-application (like per-browser).
  • DNS over TLS — identifiable as DNS traffic on its dedicated port, which some networks can selectively block, but more commonly deployed system-wide for consistent device coverage.

Neither is universally "better" — the right choice depends on whether you want per-application control or consistent system-wide coverage, and whether your network environment might specifically block port 853 traffic.

FAQ

Can a network block DoT specifically?

Yes — because it runs on its own identifiable port, a network that wants to block encrypted DNS can target port 853 specifically, which is harder to do with DoH's web-traffic-blended approach.