What Is DNS over TLS (DoT) and How Do You Enable It?
DNS over TLS (DoT) encrypts your DNS queries by wrapping them in the TLS protocol, typically on port 853, so that anyone between your device and the resolver cannot read or tamper with the names you look up. You enable it by pointing your device or router at a DoT-capable resolver, such as DNS.SB, and turning on the encrypted-DNS setting for your platform. DoT is the better fit when you want a dedicated, always-encrypted DNS channel and your network allows port 853; DoH is the better fit when you need DNS to blend into normal HTTPS traffic on port 443.
How DoT works
A normal DNS query travels in plaintext, usually over UDP port 53. Anyone on the path — your ISP, a Wi-Fi operator, or an attacker on the same network — can see which domains you request and can alter the answers.
DoT changes that in three ways:
- Encryption: the DNS query and response are carried inside a TLS session, the same protocol that protects HTTPS.
- Dedicated port: DoT uses TCP port 853, so it is a separate, clearly identified encrypted channel rather than a tunnel hidden inside web traffic.
- Authentication: the TLS handshake verifies the resolver's certificate, which makes man-in-the-middle manipulation of DNS answers much harder.
DNS.SB describes its service as encrypting DNS queries and answers via the TLS protocol, with the stated goal of preventing eavesdropping and manipulation of DNS data through man-in-the-middle attacks. It also states that it keeps no logs.
DoT vs DoH: which should you pick?
Both encrypt DNS. The practical difference is the port and how the traffic looks on the network.
| Dimension | DNS over TLS (DoT) | DNS over HTTPS (DoH) |
|---|---|---|
| Transport | TLS directly over TCP | HTTPS (HTTP inside TLS) |
| Typical port | 853 | 443 |
| Traffic appearance | Distinct encrypted DNS channel | Looks like ordinary web traffic |
| Blocking risk | Higher — port 853 is easy to block | Lower — blocking it can break normal HTTPS |
| Best fit | Devices and routers where you control the setting and want explicit encrypted DNS | Networks that block or throttle port 853, or apps that need DNS to look like web traffic |
Choose DoT when your platform exposes a native "Private DNS" or encrypted-DNS setting and port 853 is reachable. Choose DoH when DoT fails because the network blocks port 853, or when you specifically want DNS to be indistinguishable from other HTTPS traffic.
How to enable DoT
The exact menu names vary by vendor and OS version, so treat the steps below as the pattern rather than a fixed map. The input is always the same: a DoT hostname from a resolver that supports it.
Android (Private DNS)
- Open Settings → Network & internet → Private DNS (on some versions it is under Connections).
- Select Private DNS provider hostname.
- Enter the DoT hostname of your resolver, for example
dns.sb. - Save. Android will now resolve names over DoT and will show a warning if it cannot connect.
Expected result: DNS queries leave the device encrypted on port 853. If the hostname is wrong or port 853 is blocked, Android falls back to the network's plain DNS and may display a "couldn't connect" notice.
Windows
Windows does not expose a single built-in DoT toggle in all versions. The common approaches are:
- Use a browser that supports secure DNS, or a resolver client that manages DoT for the system.
- Configure DoT through a supported client or a router that handles DNS for the whole network.
Because availability depends on your Windows build, verify that your chosen method actually reports an encrypted connection before relying on it.
Routers
Many routers let you set an upstream DNS server and, on supported firmware, enable DoT for all devices on the network.
- Open the router admin page and find the DNS or encrypted-DNS section.
- Enable DNS over TLS if the firmware offers it.
- Enter the DoT hostname of your resolver.
- Save and reboot if required.
Expected result: every device behind the router uses encrypted DNS without per-device configuration. This is the most efficient option for a home or small office.
Public DoT resolvers
Use the resolver's official DoT hostname, not a guessed one. DNS.SB publishes its resolver addresses and states that it supports DNS over TLS alongside DNS over HTTPS.
| Resolver | DoT hostname (verify with the provider) |
|---|---|
| DNS.SB | dns.sb |
| Other public resolvers | Check each provider's documentation for its current DoT hostname |
Always confirm the hostname and any required port from the provider's own documentation before entering it, since these details can change.
How to verify DoT is working
Enabling the setting is not proof that encryption is active. Check it:
- Look for a status indicator. Android's Private DNS shows whether the connection succeeded.
- Test for plaintext DNS. Use a DNS leak test that reports whether queries are encrypted.
- Check the port. A working DoT connection uses TCP port 853 to the resolver.
- Compare results. If a domain resolves the same way with DoT on and off, and no error appears, the setting is likely active — but confirm with a leak test rather than assuming.
Troubleshooting common DoT failures
Port 853 is blocked. Many corporate, hotel, and public networks block non-standard ports. If DoT will not connect, switch to DoH on port 443, which is usually allowed.
Silent fallback to plain DNS. Some devices quietly revert to unencrypted DNS when DoT fails, so you keep browsing but lose the protection. Watch for a warning indicator and re-test after changing networks.
Wrong hostname. A typo in the DoT hostname prevents the TLS handshake. Copy the hostname from the provider's documentation.
Certificate errors. If the resolver's certificate cannot be validated, the connection fails by design. Do not disable certificate checking to force it through — that removes the protection DoT is meant to provide.
Router firmware lacks DoT. If your router has no encrypted-DNS option, configure DoT per device, or use a router that supports it.
FAQ
Does DoT hide which sites I visit? It hides your DNS queries from anyone between you and the resolver. It does not hide the destinations you actually connect to, and the resolver itself can still see your queries unless it commits to not logging them. DNS.SB states that it keeps no logs.
Is DoT faster than plain DNS? Not inherently. Speed depends on the resolver's network. DNS.SB says it runs on a global anycast network across 30 locations on 6 continents, which is the kind of infrastructure that reduces lookup latency.
Can I use DoT and DoH at the same time? You can, but there is usually no benefit. Pick one per device or network to keep behavior predictable.
What happens if I enter the wrong DoT hostname? The TLS handshake fails, and the device either reports an error or falls back to plain DNS. Always verify with a leak test after setup.