DNS over HTTPS, usually shortened to DoH, is a way to send domain-name lookups through an encrypted HTTPS connection. When someone enters a website address, a device normally asks a Domain Name System resolver for the numerical Internet address needed to reach that site. Traditional DNS queries have often traveled without transport encryption, allowing a network operator or another party on the path to see the domain being requested or interfere with the answer. DoH places each DNS query and response inside the same protected web protocol used for secure websites, helping prevent that local observation and tampering.
The process begins with a DoH-capable browser, operating system, or application. It connects to a configured DoH resolver over HTTPS and authenticates that server with a TLS certificate. The client sends a standard DNS message using an HTTPS request, and the resolver performs the usual work of finding or retrieving the requested record. The response returns through the encrypted channel and is cached according to its allowed lifetime. To the DNS system beyond that resolver, the lookup is still a normal request; the important change is that the section between the user’s device and the resolver is protected.
This design can improve privacy on public Wi-Fi and other networks where ordinary DNS traffic would be easy to inspect. It can also stop simple attacks that redirect an unencrypted query to a false answer. Because DoH generally uses the standard HTTPS port, it blends with other encrypted web traffic rather than relying on a separate, easily identified DNS connection. That makes casual blocking or manipulation more difficult. The protection is especially useful when the local network is not trusted, but it depends on choosing a resolver whose security and data-handling practices are acceptable.
DoH does not make browsing anonymous. The resolver receives the client’s queries and may be able to associate them with an IP address or other connection information. The destination website can still see the visitor’s network address, while other network signals may reveal which service is being contacted. DoH also does not replace HTTPS for page content. It protects the lookup, not everything that happens after the address is found. A virtual private network changes where more of a device’s traffic becomes visible, so it solves a broader and different problem.
DoH and DNSSEC are also complementary rather than interchangeable. DoH protects the transport between a client and its selected resolver. DNSSEC uses cryptographic signatures to help a validating resolver determine whether certain DNS data is authentic and unchanged. A connection may use one, both, or neither. The resolver choice can also affect local filtering, parental controls, split-network addresses, or enterprise security tools. Organizations therefore often manage DoH settings so internal names and required policies continue to work.
For everyday users, DoH is usually a background feature controlled by a browser, device, or network policy. Its value is best understood as reducing exposure on one important part of an Internet connection. It makes ordinary name lookups harder for parties on the local path to read or rewrite, while leaving trust concentrated in the chosen resolver and the services contacted afterward. Keeping browsers and operating systems updated remains important because secure DNS is one layer in a larger system of certificates, encrypted connections, software isolation, and careful account security. Administrators also need to decide whether applications may choose their own resolver or must follow the network policy. Allowing every app to select a different service can make troubleshooting and compliance harder, while forcing one resolver concentrates trust and may reduce user choice. Browsers commonly provide fallback behavior when an encrypted resolver is unavailable. The exact setting therefore reflects a tradeoff among privacy, reliability, local controls, and operational visibility rather than a universal switch that is best in every environment.
It encrypts DNS queries and responses between a client and its selected DoH resolver, limiting local observation and tampering.
No. The resolver and destination service still receive connection information, and other network signals may remain visible.
No. DoH protects transport to a resolver, while DNSSEC helps validate the authenticity of signed DNS data.
Explore more "Explainers"
Discover additional explainers across politics, science, business, technology, and other fields. Each explainer breaks down a complex idea into clear, everyday language—helping you better understand how major concepts, systems, and debates shape the world around us.
