What Is DNS over HTTPS (DoH) and How Do You Use It?

DNS over HTTPS (DoH) sends DNS queries inside encrypted HTTPS traffic instead of plaintext DNS, so your resolver requests can't be easily read or altered in transit. You use it by enabling DoH in a browser or OS, or by pointing a device at a DoH endpoint from a resolver that supports it. The main conditions: your browser/OS must support DoH, and you must trust the resolver you choose, since that resolver still sees your queries.

How DoH works

Normally, when you type a domain, your device sends a DNS query to a resolver to get the IP address. Standard DNS is unencrypted, so anyone on the path (your network, ISP, or a Wi-Fi operator) can observe or tamper with it.

DoH changes the transport:

  • The DNS query and answer are wrapped in HTTPS (the same protocol used for secure websites).
  • To the network, the traffic looks like ordinary HTTPS to a web server.
  • This prevents eavesdropping and manipulation of DNS data via man-in-the-middle attacks, which is the core privacy and security benefit.

DNS.SB describes DoH as "performing remote DNS resolution via the encrypted HTTPS protocol," and offers it alongside DNS over TLS (DoT), which encrypts and wraps DNS queries and answers via the TLS protocol. Both encrypt DNS; the difference is mainly the transport and how the network sees it.

DoH vs plain DNS vs DoT

Aspect Plain DNS DoH DoT
Encryption None HTTPS TLS
Typical port 53 443 853
Blends with normal web traffic No Yes (looks like HTTPS) Less so
Main benefit Simple, universal Privacy + harder to block/identify Privacy with a dedicated encrypted channel

If you want DNS traffic that's hard to distinguish from regular browsing, DoH is usually the better fit. If you want a clearly separated encrypted DNS channel, DoT may suit you.

Why it matters for privacy

  • No plaintext exposure: Your queries aren't readable by intermediaries on the network path.
  • Tamper resistance: Encrypted transport makes it harder for an attacker to redirect you by altering DNS answers.
  • Resolver trust still matters: Encryption protects the path, but the resolver you use still handles your queries. DNS.SB states it is designed to protect personal DNS data with "no logs, forever," and says it has taken technical steps so it can't know what you do online. Treat that as the resolver's stated policy when deciding whether to trust it.

How to enable DoH

In a browser

  1. Open the browser's settings and find the DNS or "Secure DNS" section (wording varies by browser).
  2. Turn on secure DNS / DoH.
  3. Either choose a provider from the list or enter a custom DoH URL from a resolver that supports DoH.
  4. Save, then verify by visiting a DNS leak test page or the resolver's own check page.

Expected result: your browser resolves names over HTTPS. If pages still load but the leak test shows your old resolver, the setting didn't take effect.

On a device or OS

  1. Find the network/DNS settings for your OS or device.
  2. Switch DNS from automatic/manual plain DNS to an encrypted option (DoH or DoT) if supported.
  3. Enter the resolver's DoH endpoint.
  4. Reconnect the network and test resolution.

Expected result: system-wide DNS goes through the encrypted endpoint. If the OS only supports DoT, use that instead—both encrypt DNS.

Pointing at a resolver

Use a resolver that publishes DoH support. DNS.SB is one option: it offers DoH and DoT, runs on xTom's global anycast network across 30 locations on 6 continents, and publishes easy-to-remember addresses (for example IPv4 185.222.222.222 and 45.11.45.11, and IPv6 2a09:: and 2a11::). Check the resolver's site for its exact DoH URL before entering it.

Trade-offs to weigh

  • Latency: DoH adds encryption overhead. A fast resolver on a nearby anycast network can offset this, but a distant or overloaded resolver can slow browsing.
  • Resolver trust: You're shifting who sees your queries from your network/ISP to the resolver. Choose one whose logging policy you accept.
  • Network compatibility: Some networks, captive portals, or parental-control systems rely on inspecting or blocking plain DNS. DoH can bypass or break those, and some networks block DoH outright.
  • Enterprise/managed devices: If your organization enforces DNS, enabling DoH may conflict with policy.

Troubleshooting when DoH fails or slows down

  • Nothing resolves: Temporarily switch back to automatic/plain DNS to confirm DoH is the cause, then re-check the endpoint URL.
  • Slow browsing: Try a different resolver or a closer anycast location; compare load times with DoH off.
  • Works in browser but not system-wide: The browser setting and OS setting are separate—enable both if you want full coverage.
  • Blocked on a network: Some networks block DoH on port 443. Fall back to DoT or plain DNS there.
  • Captive portal won't load: Disable DoH until you've signed in, then re-enable it.

Start by enabling DoH in your browser with a resolver you trust, verify with a leak test, then extend it to your OS if you want system-wide encryption.

dns.sb
DNS.SB is a free, fast, and privacy-focused DNS resolver service. Supports DNS over HTTPS (DoH) and DNS over TLS (DoT) with no logging. Protect your …