What is DNS over HTTPS, and should I use it?
DNS over HTTPS (DoH) encrypts your DNS queries so that whoever carries your traffic cannot read which sites you are looking up. It closes a genuine privacy gap and shifts trust rather than eliminating it.
The problem it addresses. Conventional DNS is sent in plain text. Every lookup — every website, every app's backend, every device phoning home — is visible to your ISP, to anyone on the same Wi-Fi, and to any network in between. Even with HTTPS protecting the page content, the DNS query reveals which site you visited.
It is also unauthenticated, so responses can be tampered with — the basis of DNS hijacking and of some ISP-level redirection.
How DoH works. DNS queries are sent inside ordinary HTTPS requests to a DNS resolver that supports it. Because the traffic looks like normal web traffic on port 443, it is both encrypted and difficult to distinguish or block — which is a feature or a problem depending on your position.
DoT (DNS over TLS) does the same encryption on a dedicated port, which makes it identifiable and therefore easier for networks to manage — and easier to block.
What it protects against: passive surveillance of your browsing by your ISP or network operator; tampering with responses; and lookups being read on untrusted public Wi-Fi.
What it does not do:
It does not hide which sites you visit from your ISP entirely. The IP addresses you connect to are still visible, and SNI in the TLS handshake frequently reveals the hostname anyway unless encrypted client hello is in use.
It does not make you anonymous.
It moves trust to the resolver. Your DNS provider now sees everything your ISP used to. Choosing a large centralised provider means concentrating that visibility, which is the main criticism.
What it breaks: parental controls and content filters that work at the network level; enterprise security monitoring; split-horizon DNS on corporate networks; and ISP-level blocking, which is why it has been politically contentious in the UK.
Practical advice: it is worth enabling on untrusted networks; choose a resolver whose logging policy you have actually read; and check whether it conflicts with filtering you rely on.