TTemp90
T
← Back to BlogPrivacy

What Is Encrypted DNS?

What is encrypted DNS (DNS over HTTPS/TLS)? A clear explanation of what DNS is, why encrypting it improves privacy, and its limits.

What Is Encrypted DNS?

What Is Encrypted DNS?

Encrypted DNS is a way of making your DNS queries — the lookups your device does to translate website names into addresses — private by encrypting them, so they cannot be easily seen by your network or others. It improves privacy by hiding which sites you are looking up. This article explains what DNS is, what encrypted DNS does, why it matters, and its limits, in plain terms.

First, What Is DNS?

To understand encrypted DNS, start with DNS:

DNS translates names to addresses: DNS (Domain Name System) is like the internet's phone book — it translates human-readable website names (like a domain) into the numerical IP addresses computers use.

Your device makes DNS queries: When you visit a website, your device makes a DNS query to look up the site's address.

Traditionally unencrypted: Traditionally, DNS queries have been sent unencrypted, meaning they can be seen by your network, ISP, or others on the path — revealing which sites you are looking up.

What Encrypted DNS Is

Encrypted DNS, in plain terms:

Encrypting your DNS queries: Encrypted DNS encrypts the DNS queries your device makes, so they cannot be easily read by your network, ISP, or others in transit.

Common methods: Common methods include DNS over HTTPS (DoH) and DNS over TLS (DoT), which send DNS queries over encrypted connections.

Hides which sites you look up: By encrypting DNS, it hides which website names you are looking up from those who could otherwise see your unencrypted DNS queries.

Why Encrypted DNS Matters

Encrypting DNS improves privacy because:

Unencrypted DNS reveals your browsing: With traditional unencrypted DNS, your network or ISP can see the DNS queries you make — revealing which sites you visit, even if the site connections themselves are encrypted (HTTPS).

Encryption hides the lookups: Encrypted DNS prevents your network or ISP from easily seeing which sites you are looking up via DNS, improving your privacy.

Also improves integrity/security: Encrypted DNS can also help prevent tampering with your DNS queries, adding a security benefit.

Part of private browsing: It is one piece of browsing more privately, complementing other measures.

The Limits of Encrypted DNS

It is important to understand what encrypted DNS does not do:

Doesn't hide all activity: Encrypted DNS hides your DNS queries, but your network/ISP may still infer sites you visit through other means (like the IP addresses you connect to, or other unencrypted information). So it is not complete privacy.

Doesn't replace a VPN: A VPN encrypts all your traffic and masks your IP, providing broader protection. Encrypted DNS only encrypts DNS queries — useful, but narrower.

The DNS resolver sees your queries: Your DNS queries go to a DNS resolver, which can see them. So you shift some visibility to the DNS provider — choose a trustworthy resolver with good privacy practices.

Not anonymity: Encrypted DNS improves privacy for DNS lookups but does not make you anonymous.

How to Use Encrypted DNS

Using encrypted DNS:

Built into browsers and systems: Many modern browsers and operating systems support encrypted DNS (DoH/DoT) and may enable it by default or offer it in settings.

Choose a trustworthy resolver: You can often choose your DNS provider/resolver. Choose a reputable one with good privacy practices, since it sees your queries.

Combine with other measures: Use encrypted DNS alongside HTTPS, a VPN (which also protects DNS), tracker blocking, and other privacy measures for broader protection.

Frequently Asked Questions

What is encrypted DNS in simple terms?

Encrypted DNS is a way of making your DNS queries private by encrypting them. DNS (Domain Name System) is like the internet's phone book — it translates website names into the numerical IP addresses computers use, and your device makes a DNS query whenever you visit a site. Traditionally these queries were sent unencrypted, so your network or ISP could see which sites you were looking up. Encrypted DNS (using methods like DNS over HTTPS or DNS over TLS) encrypts these queries, so they cannot be easily read by your network, ISP, or others in transit — hiding which website names you are looking up and improving your privacy.

Why should I use encrypted DNS?

You should consider it because, with traditional unencrypted DNS, your network or ISP can see the DNS queries you make — revealing which sites you visit, even if the site connections themselves are encrypted with HTTPS. Encrypted DNS prevents your network or ISP from easily seeing which sites you are looking up via DNS, improving your privacy, and can also help prevent tampering with your DNS queries (a security benefit). It is one piece of browsing more privately. Note that it has limits — it does not hide all your activity or replace a VPN, and your DNS resolver still sees your queries (so choose a trustworthy one) — but it is a useful privacy improvement, often built into modern browsers and systems.

Does encrypted DNS replace a VPN?

No — they are different in scope. Encrypted DNS only encrypts your DNS queries (the lookups translating website names to addresses), hiding which sites you look up via DNS from your network or ISP. A VPN encrypts all your internet traffic and masks your IP address, providing broader protection. So encrypted DNS is useful but narrower than a VPN. Also, encrypted DNS does not hide all your activity — your network may still infer sites you visit through the IP addresses you connect to — and your DNS resolver still sees your queries. Use encrypted DNS as one privacy measure, alongside HTTPS, a VPN (which also protects your DNS), and other measures, rather than as a replacement for a VPN.

Conclusion

Encrypted DNS is a way of making your DNS queries private by encrypting them, so they cannot be easily seen by your network or others — improving privacy by hiding which sites you are looking up. DNS (the Domain Name System) translates website names into IP addresses, and your device makes a DNS query whenever you visit a site; traditionally these queries were unencrypted, letting your network or ISP see which sites you look up. Encrypted DNS (using methods like DNS over HTTPS or DNS over TLS) encrypts these queries, hiding your lookups and improving privacy, while also helping prevent tampering. However, it has limits: it does not hide all your activity (your network may infer sites through IP addresses), does not replace a VPN (which encrypts all traffic and masks your IP), shifts some visibility to your DNS resolver (so choose a trustworthy one), and does not make you anonymous. Encrypted DNS is often built into modern browsers and systems; use it alongside HTTPS, a VPN, tracker blocking, and other measures. Understanding what encrypted DNS is, why it improves privacy, and its limits helps you use it as one useful piece of browsing more privately.

More from Temp90

Privacy resources made simple

FAQCommon temporary email questions. Trust CenterService status and transparency. Privacy PolicyHow Temp90 protects privacy. Terms of UseRules for using Temp90 safely.