"Is my DNS private?" isn't really one question — it's several, because different parties in the DNS chain can see different things depending on your setup. Mapping visibility layer by layer is more useful than a single yes/no answer.
Who can see what
- Your device. Every domain you look up, obviously, along with timing.
- Your local network. Anyone with visibility into your local network traffic (relevant on shared or compromised networks) can potentially observe unencrypted DNS queries.
- Your ISP. By default, your ISP's resolver sees every domain you look up, unless you've configured a different resolver or are using an encrypted DNS protocol they can't inspect.
- Your DNS resolver operator. Whichever resolver actually answers your queries — your ISP, a VPN provider, or a public service like Cloudflare or Google — sees your query history, regardless of encryption in transit.
- The domain's authoritative operators. They see that someone looked up their domain, but generally without the same level of aggregate visibility across all your browsing that your resolver has.
What encryption does and doesn't change
DNS over HTTPS and DNS over TLS (see DNS over HTTPS and DNS over TLS) encrypt the trip between your device and your chosen resolver — hiding your queries from your ISP or anyone else observing that specific network segment. They do not hide your queries from the resolver itself, which still sees everything in plaintext to actually answer the query.
Choosing based on who you're protecting against
If your concern is your ISP or local network snooping, an encrypted connection to any trustworthy resolver addresses that. If your concern is the resolver operator itself, the choice of which resolver you trust matters more than the encryption — see Public DNS Resolvers for the tradeoffs between different resolver choices.
FAQ
Does a VPN make my DNS private?
It changes which resolver handles your queries (typically the VPN provider's own), and typically encrypts the trip to that resolver — but the VPN provider itself can still see your DNS query history, same as any other resolver operator would.