Use encrypted DNS. Pick DoH for easy setup and better disguise on public Wi Fi. Pick DoT for cleaner network rules and simpler logging at home or work. Both protect DNS queries from nosy eyes.
TLDR
DoH sends DNS queries through HTTPS on port 443, so it blends in with normal web traffic. DoT sends DNS through TLS on port 853, so it is easier to spot and manage. For example, a family using public Wi Fi at a hotel could switch to DoH in a browser and hide most DNS lookups from the hotspot owner in under 2 minutes. In tests by several public DNS providers, encrypted DNS often adds only a few milliseconds, but bad routing can add 50 ms or more.
What DNS Does
DNS is the internet’s phone book.
You type example.com. DNS finds the matching IP address. Your device then visits that server.
Simple, right?
Here is the annoying part. Old style DNS is usually plain text. That means your internet provider, coffee shop Wi Fi, school network, or office gateway may see the domains you ask for. Not full pages. Not passwords. But domain names can still say a lot.
If you ask for:
- bank site
- medical portal
- job board
- game server
Someone watching DNS can guess what you are doing. That feels creepy because it is creepy.
What Encrypted DNS Fixes
Encrypted DNS wraps DNS queries in encryption. It stops casual snooping. It also helps block tampering.
Without encryption, a bad network can answer with fake DNS results. That can send you to a fake site. With encrypted DNS, this gets much harder.
There are two common choices:
- DoH: DNS over HTTPS
- DoT: DNS over TLS
They both use encryption. They both help privacy. They just package DNS in different ways.
DoH: DNS Wearing a Hoodie
DoH sends DNS queries over HTTPS. That is the same protocol used by secure websites.
It usually uses port 443. That is the normal web traffic port. Because of that, DoH blends in well. A network admin may see HTTPS traffic, but not easily tell which part is DNS.
This is great when you use sketchy Wi Fi. Airports. Hotels. Cafes. That one bus with Wi Fi that works until someone breathes near it.
DoH is popular in browsers. Firefox, Chrome, Edge, and many mobile apps can use it. Setup is often just a setting. Sometimes it is one toggle. Nice.
DoH is good for:
- Public Wi Fi
- Browser based privacy
- Getting around weak DNS filtering
- Simple setup for one person
But DoH can annoy network teams. Since it hides inside HTTPS, company filters may miss it. Parents may also find that some filtering tools stop working.
Honestly, it feels like hiding your house key inside a loaf of bread. Clever. Also irritating if you are the person checking the bread.
DoT: DNS in a Clear Safe
DoT sends DNS queries through TLS. TLS is the same encryption system that protects HTTPS.
DoT usually uses port 853. This makes it easy to recognize. A router or firewall can allow it, block it, or send it to a chosen resolver.
The DNS content is still encrypted. But the traffic type is not trying to hide.
This makes DoT a good fit for homes, offices, schools, and managed devices. It gives privacy without making network control a guessing game.
DoT is good for:
- Home routers
- Business networks
- School filtering
- Central DNS policies
- Clear firewall rules
DoT can be blocked more easily. If a network blocks port 853, it may fail. Then your device might fall back to normal DNS unless you stop it.
That fallback is a sneaky little gremlin. Check your settings.
DoH vs DoT: The Simple Matchup
| Feature | DoH | DoT |
|---|---|---|
| Main port | 443 | 853 |
| Looks like | Normal HTTPS | Encrypted DNS |
| Easy to block | Harder | Easier |
| Best for | Personal privacy | Network control |
| Common setup | Browser or app | Router or operating system |
If you want stealth, choose DoH. If you want order, choose DoT.
That is the cleanest answer.
Does Encrypted DNS Make You Anonymous?
No.
This is where people get tricked.
Encrypted DNS hides the domain lookup. It does not hide everything else.
Your internet provider may still see:
- The IP address you connect to
- How much data you send
- When you connect
- How long the session lasts
Some sites share IP addresses. Some do not. If one website lives alone on one IP, the IP gives it away.
Encrypted Client Hello, often called ECH, can hide more website details. It is still rolling out. A VPN can hide more from your internet provider, but then the VPN provider sees more. Pick carefully.
So yes, encrypted DNS helps. No, it is not an invisibility cloak.
What About Speed?
Most people will not notice a speed change.
DNS queries are tiny. A good encrypted DNS service is fast. Many queries are cached too. That means your device remembers recent answers.
Still, bad resolver choice can slow things down. If your encrypted DNS server is far away, each lookup may take longer. A normal lookup might take 20 ms. A poor encrypted route might take 90 ms. That can make pages feel sticky.
Expect to waste time on this if your device chooses a weird server far from you. Test two or three providers. Keep the fastest reliable one.
Which One Should You Use?
Here is the easy cheat sheet.
- Use DoH if you mostly care about personal privacy on laptops and phones.
- Use DoH if you use lots of public Wi Fi.
- Use DoT if you manage a home router.
- Use DoT if you need family rules or office rules.
- Use either if your goal is basic DNS encryption.
For a single person, DoH is usually easier. For a whole network, DoT is usually cleaner.
A Simple User Story
Meet Sam.
Sam works from cafes three days a week. Their laptop used normal DNS. One cafe Wi Fi redirected unknown domains to an ad page. Another blocked random sites for no clear reason. Very fun. Not.
Sam turned on DoH in the browser. Setup took about 90 seconds. DNS queries now go through HTTPS. The cafe router can still see connections, but it cannot read those DNS requests like a shopping list.
At home, Sam uses DoT on the router. Every phone, tablet, and smart TV gets encrypted DNS. The router keeps one family safe search rule. No need to fix each device.
This mix works well. DoH on the go. DoT at home.
How to Pick a DNS Provider
Do not choose only by logo. Choose by policy.
Look for:
- No selling DNS logs
- Clear privacy policy
- Servers near your region
- Support for DoH and DoT
- Good uptime
- Optional malware blocking
Popular public providers include Cloudflare, Google Public DNS, Quad9, and NextDNS. Each has different rules. Quad9 focuses on blocking known malicious domains. NextDNS offers strong custom controls. Cloudflare is known for speed. Google is widely reachable.
Pick based on trust. Speed matters. Privacy policy matters more.
Final Recommendation
Turn on encrypted DNS. It is a small change with a real privacy gain.
If you are a normal user, start with DoH in your browser or phone settings. If you run a home network, set up DoT on your router when possible. If you manage an office, test both and block unsafe fallback to plain DNS.
The best setup is boring. It works quietly. It does not break apps. It does not add weird delays. It just stops your DNS queries from being shouted across the room.
And really, DNS should have stopped shouting years ago.