Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Yes, your internet provider may be able to learn which domains you visit even when a site uses HTTPS. HTTPS encrypts the page contents in transit, but it does not automatically encrypt the DNS lookup that helps your device find the site. With ordinary, unencrypted DNS, that lookup can be read by parties on the network path, potentially including your ISP. It is not a guarantee that an ISP sees every domain: encrypted DNS, caching, resolver choice, and other connection metadata affect what is visible.

What HTTPS protects—and what it does not

When you open a website, your device needs its IP address. It usually asks a DNS resolver to translate the domain name, such as example.com, into an address it can connect to. That lookup is separate from the subsequent web connection.

HTTPS encrypts the contents of the connection between your browser and the website. A network observer generally cannot read the page text, passwords, or form submissions from that encrypted traffic. But HTTPS alone does not encrypt conventional DNS queries. If the query is sent in plaintext, a party able to observe that network traffic can read the requested domain. Cloudflare describes this exposure and notes that many devices use an ISP-provided resolver by default: Cloudflare’s DNS privacy explanation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

So the claim that DNS “broadcasts every domain” is too broad. A plaintext lookup can reveal a domain to observers on its route, but not every visit necessarily generates a fresh visible request. A cached answer may avoid a new lookup, and device, browser, network, or resolver settings can change the path. Even when a DNS query is hidden, other connection metadata may offer clues.

#1 Best Overall
Sale
TP-Link ER605, Wired Gigabit VPN Router
  • 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
  • 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
  • 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
  • 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
  • Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q

What your ISP may be able to see

If your device sends an ordinary DNS query through a path your ISP can observe, the ISP may be able to see the domain being requested. If the query goes to a different resolver, the ISP may still be in a position to observe plaintext traffic traveling to it; changing resolvers is not the same as encrypting the query.

With HTTPS, this does not mean the ISP can automatically read the page you viewed, what you typed, or the specific content delivered. Domain-level visibility and page-content visibility are different. Encrypted DNS reduces the visibility of the DNS request on the path to the resolver, but it does not make all evidence of a destination disappear: Mozilla notes that Server Name Indication (SNI) can expose some domain names in some connections. Mozilla’s FAQ discusses the concern without claiming that every domain is exposed: Mozilla’s DNS-over-HTTPS FAQ.

Rank #2
GL.iNet GL-SFT1200 Opal Travel Router, AC1200 Dual-Band Wi-Fi
  • 【AC1200 Dual-band Wireless Router】Simultaneous dual-band with wireless speed up to 300 Mbps (2.4GHz) + 867 Mbps (5GHz). 2.4GHz band can handles some simple tasks like emails or web browsing while bandwidth intensive tasks such as gaming or 4K video streaming can be handled by the 5GHz band.*Speed tests are conducted on a local network. Real-world speeds may differ depending on your network configuration.*
  • 【Easy Setup】Please refer to the User Manual and the Unboxing & Setup video guide on Amazon for detailed setup instructions and methods for connecting to the Internet.
  • 【Pocket-friendly】Lightweight design(145g) which designed for your next trip or adventure. Alongside its portable, compact design makes it easy to take with you on the go.
  • 【Full Gigabit Ports】Gigabit Wireless Internet Router with 2 Gigabit LAN ports and 1 Gigabit WAN ports, ideal for lots of internet plan and allow you to connect your wired devices directly.
  • 【Keep your Internet Safe】IPv6 supported. OpenVPN & WireGuard pre-installed, compatible with 30+ VPN service providers. Cloudflare encryption supported to protect the privacy.

How encrypted DNS changes the picture

DNS over HTTPS (DoH) and DNS over TLS (DoT) encrypt DNS traffic between your device or application and its selected resolver. That makes the query harder for intermediaries on that route to read. The resolver still has to process the requested domain, so trust shifts: the resolver can see the query and its own privacy and data-handling policies matter.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Method How DNS is carried What the protection changes
DoH DNS inside HTTPS traffic, typically over port 443. See Cloudflare’s DoH documentation. Encrypts the query between client and resolver; the resolver can still read it.
DoT DNS inside a TLS-protected TCP connection; Cloudflare documents its service on port 853. See Cloudflare’s DoT documentation. Encrypts the query between client and resolver; the resolver can still read it.

DoH uses the same port commonly used for HTTPS web traffic, while DoT uses a dedicated port in Cloudflare’s documented setup. The protocol alone does not determine which resolver you use, whether your browser applies it to every lookup, or what happens when secure DNS is unavailable. Review the resolver’s published policy rather than assuming encryption means the provider cannot see or retain queries. Mozilla describes its resolver policies, and Cloudflare publishes commitments for its 1.1.1.1 service; these are the organizations’ stated policies, not independent audits: Cloudflare’s 1.1.1.1 privacy commitments.

Rank #3
Sale
ASUS RT-AX1800S Dual Band WiFi 6 Extendable Router, Subscription-Free Network Security, Parental Control, Built-in VPN, AiMesh Compatible, Gaming & Streaming, Smart Home
  • New-Gen WiFi Standard – WiFi 6(802.11ax) standard supporting MU-MIMO and OFDMA technology for better efficiency and throughput.Antenna : External antenna x 4. Processor : Dual-core (4 VPE). Power Supply : AC Input : 110V~240V(50~60Hz), DC Output : 12 V with max. 1.5A current.
  • Ultra-fast WiFi Speed – RT-AX1800S supports 1024-QAM for dramatically faster wireless connections
  • Increase Capacity and Efficiency – Supporting not only MU-MIMO but also OFDMA technique to efficiently allocate channels, communicate with multiple devices simultaneously
  • 5 Gigabit ports – One Gigabit WAN port and four Gigabit LAN ports, 10X faster than 100–Base T Ethernet.
  • Commercial-grade Security Anywhere – Protect your home network with AiProtection Classic, powered by Trend Micro. And when away from home, ASUS Instant Guard gives you a one-click secure VPN.

Check Firefox’s secure DNS behavior

Firefox exposes DNS-over-HTTPS protection levels. The choice matters because some modes may fall back to system DNS or disable secure DNS under conditions such as network, VPN, parental-control, or enterprise policies. Mozilla’s current instructions describe the protection levels and their behavior: Configure DNS over HTTPS protection levels in Firefox.

  1. Open Settings: In Firefox, open the menu and choose Settings.
  2. Find DNS over HTTPS: Use the Settings search box for “DNS over HTTPS,” or open the relevant section under Privacy & Security.
  3. Choose a protection level: Default protection may fall back or turn secure DNS off in certain network situations. Increased or Custom protection keeps the selected provider active with backup behavior if there are problems. Max protection keeps secure DNS active and warns if the secure resolver cannot be used.
  4. Review the resolver: Check which provider is selected and read its privacy policy. A secure connection to a resolver protects the query in transit, not from that resolver.

Labels and behavior can change, and organizations or network administrators may manage these settings. If secure DNS is unavailable or Firefox reports that it has been disabled, the browser may use system DNS depending on the protection level and circumstances.

Rank #4
Sale
GL.iNet GL-BE3600 Slate 7 Wi-Fi 7 Travel Router Touchscreen 2.5G
  • 【DUAL BAND WIFI 7 TRAVEL ROUTER】Products with US, UK, EU, AU Plug; Dual band network with wireless speed 688Mbps (2.4G)+2882Mbps (5G); Dual 2.5G Ethernet Ports (1x WAN and 1x LAN Port); USB 3.0 port.
  • 【NETWORK CONTROL WITH TOUCHSCREEN SIMPLICITY】Slate 7’s touchscreen interface lets you scan QR codes for quick Wi-Fi, monitor speed in real time, toggle VPN on/off, and switch providers directly on the display. Color-coded indicators provide instant network status updates for Ethernet, Tethering, Repeater, and Cellular modes, offering a seamless, user-friendly experience.
  • 【OpenWrt 23.05 FIRMWARE】The Slate 7 (GL-BE3600) is a high-performance Wi-Fi 7 travel router, built with OpenWrt 23.05 (Kernel 5.4.213) for maximum customization and advanced networking capabilities. With 512MB storage, total customization with open-source freedom and flexible installation of OpenWrt plugins.
  • 【VPN CLIENT & SERVER】OpenVPN and WireGuard are pre-installed, compatible with 30+ VPN service providers (active subscription required). Simply log in to your existing VPN account with our portable wifi device, and Slate 7 automatically encrypts all network traffic within the connected network. Max. VPN speed of 100 Mbps (OpenVPN); 540 Mbps (WireGuard). *Speed tests are conducted on a local network. Real-world speeds may differ depending on your network configuration.*
  • 【PERFECT PORTABLE WIFI ROUTER FOR TRAVEL】The Slate 7 is an ideal portable internet device perfect for international travel. With its mini size and travel-friendly features, the pocket Wi-Fi router is the perfect companion for travelers in need of a secure internet connectivity on the go in which includes hotels or cruise ships.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

DNS encryption is not the same as DNSSEC

DNSSEC and encrypted DNS address different risks. DNSSEC helps verify that DNS responses have not been tampered with in transit; it does not hide queries. Mozilla states: “DNSSEC ensures that DNS responses have not been tampered with while in transit, but does not encrypt DNS requests and responses.” DoH and DoT encrypt transport to the resolver, but that does not by itself establish that a response is authentic. Treat them as complementary protections, not substitutes. See Mozilla’s explanation of DNSSEC and DoH.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What Oblivious DoH is—and why it is not a default answer

Oblivious DNS over HTTPS (ODoH) uses separate proxy and target roles. The proxy sees the client’s IP address but cannot read the query; the target can read the query but sees the proxy’s IP address. The separation depends on the proxy and target not colluding. Cloudflare describes ODoH as experimental and says RFC 9230 is not endorsed by the IETF, so it is better understood as a developing, specialized design than a universal setting: Cloudflare’s ODoH overview.

Best Value
TP-Link Dual-Band AX3000 Wi-Fi 6 Wireless Gigabit Internet Router for Home
  • Next-Gen Gigabit Wi-Fi 6 Speeds: 2402 Mbps on 5 GHz and 574 Mbps on 2.4 GHz bands ensure smoother streaming and faster downloads; support VPN server and VPN client¹
  • A More Responsive Experience: Enjoy smooth gaming, video streaming, and live feeds simultaneously. OFDMA makes your Wi-Fi stronger by allowing multiple clients to share one band at the same time, cutting latency and jitter.²
  • Expanded Wi-Fi Coverage: 4 high-gain external antennas and Beamforming technology combine to extend strong, reliable, Wi-Fi throughout your home.
  • Improved Battery Life: Target Wake Time helps your devices to communicate efficiently while consuming less power.
  • Improved Cooling Design: No heat ups, no throttles. A larger heat sink and redefined case design cools the WiFi 6 system and enables your network to stay at top speeds in more versatile environments.

Practical takeaways

  • HTTPS protects the contents of a web connection; by itself, it does not encrypt ordinary DNS lookups.
  • DoH or DoT can prevent intermediaries on the route to the resolver from reading DNS queries, but the resolver can still process them.
  • Check the actual secure-DNS setting and fallback behavior in your browser or device; a setting that falls back to system DNS may use ordinary DNS in some circumstances.
  • Do not assume encrypted DNS hides every destination clue. Some domain metadata may remain observable, and visibility depends on the connection and network configuration.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.