Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

DNS over HTTPS (DoH) sends DNS questions and answers through an HTTPS connection between your device and a chosen DNS resolver. That encrypts the exchange on that connection, but it does not hide your DNS queries from the resolver or make your internet activity anonymous.

What DNS over HTTPS means

DNS, the Domain Name System, helps a device find the network address associated with a domain name. DoH carries those DNS queries and responses over HTTPS instead of sending them through an unencrypted DNS transport. The IETF standard defines each query-response pair as an HTTP exchange. RFC 8484

DoH changes how a DNS message travels between a client and resolver; it does not change DNS’s basic purpose. A resolver receives the query, looks up or otherwise processes it, and returns a response.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How a DoH request works

  1. Select a resolver. The client needs a DoH server endpoint. RFC 8484 leaves discovery and configuration of that endpoint outside the protocol, so it is selected by the user, software, or network configuration.
  2. Send a DNS query over HTTPS. RFC 8484 defines two HTTP methods. With GET, the DNS message is encoded in base64url in a dns query parameter. With POST, the DNS message is placed in the request body and identified as application/dns-message.
  3. Receive the response. The resolver returns the DNS response through the HTTP exchange. HTTPS encrypts the connection and authenticates the server to the client.

For example, Google Public DNS documents https://dns.google/dns-query as an RFC 8484 endpoint supporting GET and POST. It also documents a separate JSON API at https://dns.google/resolve, which supports GET only; that API is not the same request format as RFC 8484 DoH. Google Public DNS DoH documentation

GET and POST trade-offs

Google says GET can be cached more effectively and may reduce latency, while POST is less cacheable and may increase latency. It suggests considering POST for privacy-sensitive applications or browser modes where reduced caching is desirable. This is provider guidance, not a universal speed result: latency depends on the client, resolver, network, and caching behavior.

What DoH protects—and what it does not

Encryption makes DNS exchanges harder for people observing the network path between the client and resolver to read. HTTPS authentication and encryption also help defend against on-path attempts to alter or redirect DNS requests. DoH commonly uses HTTPS port 443, and its traffic can share a connection with other HTTPS traffic, which can make it less distinguishable to simple network devices. Cloudflare documents support for HTTP, HTTP/2, and HTTP/3 for its DoH service. Cloudflare DoH documentation

The resolver still receives and processes the DNS questions. The HTTP layer can also carry identifying information: RFC 8484 notes that cookies and request-header fingerprinting may contribute to correlation. DoH therefore does not make DNS anonymous, encrypt all of an app’s internet traffic, or prevent every form of tracking. It protects the client-to-resolver DNS connection, not every connection or every party that may observe activity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

DoH compared with other DNS privacy and security tools

Technology What it addresses What it does not mean
DoH Encrypts DNS transport between a client and resolver using HTTPS. Does not hide queries from the resolver or route all internet traffic through a VPN.
DNS over TLS (DoT) Encrypts DNS transport using TLS. It offers similar protection against on-path observation and tampering. It is not DoH: DoT uses TLS as its transport, while DoH carries DNS in HTTPS.
DNSSEC DNSSEC validation helps establish the authenticity of DNS data. It does not encrypt the DNS connection.
Oblivious DoH (ODoH) A distinct, experimental proxying design intended to prevent any one server from knowing both the client’s IP address and the contents of its DNS queries. That separation is not a privacy property of ordinary DoH.

DoH and DNSSEC solve different problems and can be used together; encrypted transport does not remove the need for DNSSEC validation. The IETF describes them as independent and compatible. RFC 8932 ODoH is specified separately as an experimental protocol. RFC 9230

DoH is also not the same as a VPN. DoH concerns DNS requests; by itself, it does not send all application traffic through a VPN tunnel.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choosing a DoH resolver

DoH is a protocol, not a single service or a guarantee that a particular resolver is private. Before selecting an endpoint, consider:

  • Data handling: Read the operator’s privacy and retention policy to understand what query data it handles and how it is treated.
  • Filtering: Check whether the resolver offers the filtering or parental-control behavior you want.
  • Compatibility and availability: Confirm that your device, browser, and network can use the endpoint reliably.
  • Network requirements: A workplace, school, or other administrator may require a particular resolver or apply network policies.

There is no single best resolver established by the cited documentation, and the available sources do not provide comparable current performance measurements. For organizations using managed filtering, Cloudflare Gateway is a separate service: its browser DNS policies apply when browser DoH is pointed at a Gateway DNS location endpoint. That is a configuration for that managed service, not an inherent feature of DoH.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.