TTemp90
T
← Back to BlogPrivacy

What Is DNS-over-HTTPS (DoH) and Should You Use It?

Learn what DNS-over-HTTPS is, how it encrypts your DNS queries to protect privacy, the tradeoffs involved, and how to enable it.

What Is DNS-over-HTTPS (DoH) and Should You Use It?

What Is DNS and Why It Matters for Privacy

The Domain Name System (DNS) translates the website names you type (like example.com) into the numerical IP addresses computers use to connect. Every time you visit a website, your device makes a DNS query to look up its address. Traditionally, these queries are sent in plain text — unencrypted — meaning anyone who can observe your network traffic can see every website you look up.

This DNS visibility is a significant privacy gap. Even when you browse HTTPS sites (encrypting the content), your DNS queries reveal which sites you visit. DNS-over-HTTPS addresses this gap.

What Is DNS-over-HTTPS (DoH)?

DNS-over-HTTPS encrypts your DNS queries by sending them over an encrypted HTTPS connection, the same protocol that secures websites. Instead of broadcasting your DNS lookups in plain text, DoH wraps them in encryption, hiding which sites you are looking up from anyone observing your network.

With DoH:

  • Your DNS queries are encrypted, hiding the sites you look up
  • Your ISP and network observers cannot see your DNS queries
  • DNS queries blend in with regular HTTPS traffic, harder to identify and block

What DoH Protects

ISP visibility: Your ISP can no longer see your DNS queries, reducing their ability to log and monetize your browsing.

Network surveillance: Anyone monitoring your network (on public WiFi, for example) cannot see which sites you look up.

DNS manipulation: Encrypted DNS resists certain tampering and redirection attacks (pharming).

Censorship circumvention: DoH can bypass DNS-based content blocking in some contexts.

What DoH Does NOT Protect

DoH addresses DNS query privacy specifically. It does not:

  • Hide your IP address (the websites still see it; use a VPN for that)
  • Hide your browsing from the DNS provider (they see your queries — choose a trustworthy one)
  • Encrypt the content of your browsing (HTTPS does that)
  • Provide complete anonymity (it is one privacy layer, not a complete solution)

The Tradeoffs and Considerations

Choosing a DNS provider: With DoH, you send your queries to a DoH provider who can see them. You are shifting visibility from your ISP to the DoH provider. Choose a reputable provider with a strong privacy policy.

Network filtering: DoH can bypass network-level filtering, which has implications:

  • It can bypass censorship (a benefit for privacy)
  • It can also bypass legitimate parental controls and corporate security filtering (a consideration for those contexts)

Centralization concerns: Routing DNS through major DoH providers centralizes DNS data with fewer entities, a consideration some privacy advocates raise.

How to Enable DoH

In your browser:

  • Firefox: Settings > Privacy & Security > DNS over HTTPS — enable and choose a provider
  • Chrome: Settings > Privacy and security > Security > Use secure DNS
  • Edge: Similar settings under privacy and security

At the system level:

  • Windows 11 supports DoH in network settings
  • Configure DoH for system-wide coverage rather than just the browser

At the router level:

  • Some routers support DoH, protecting all devices on your network

Choosing a provider: Reputable DoH providers include those focused on privacy. Review each provider's logging and privacy policies before choosing.

DoH as Part of Layered Privacy

DoH is one privacy layer addressing DNS query visibility. For comprehensive privacy:

  • DoH: Encrypts DNS queries
  • VPN: Hides your IP address and encrypts all traffic (and typically handles DNS privately too)
  • HTTPS: Encrypts website content
  • Temp90: Protects your email identity
  • Tracker blocking: Reduces behavioral tracking

Note that a good VPN already routes DNS queries privately through the VPN tunnel, so DoH is most valuable when you are not using a VPN.

Frequently Asked Questions

Do I need DoH if I use a VPN?

A reputable VPN already routes your DNS queries privately through its encrypted tunnel, providing similar DNS privacy. DoH is most valuable when you are not using a VPN. Using both is not harmful but the VPN's DNS handling typically takes precedence.

Does DoH make me anonymous?

No. DoH encrypts your DNS queries, hiding which sites you look up from your ISP and network observers. But websites still see your IP address, and the DoH provider sees your queries. DoH is one privacy layer, not complete anonymity.

Can DoH bypass parental controls or workplace filtering?

Yes, which is both a benefit (bypassing censorship) and a consideration (bypassing legitimate filtering). On managed networks (work, school) or for household parental controls, DoH can circumvent DNS-based filtering. This is why some organizations configure their networks to manage DoH usage.

Conclusion

DNS-over-HTTPS closes a significant privacy gap by encrypting the DNS queries that traditionally reveal every website you visit, even when browsing encrypted sites. It protects your DNS lookups from your ISP and network observers and resists certain manipulation attacks. The key considerations are choosing a trustworthy DoH provider and understanding its interaction with network filtering. As one layer in a comprehensive privacy approach — alongside a VPN, HTTPS, tracker blocking, and Temp90 for email privacy — DoH strengthens your protection against the pervasive monitoring of your online activity.

More from Temp90

Privacy resources made simple

FAQCommon temporary email questions. Trust CenterService status and transparency. Privacy PolicyHow Temp90 protects privacy. Terms of UseRules for using Temp90 safely.