Modern DNS & Privacy
DNS over HTTPS, DNS over TLS, encrypted DNS, and privacy considerations.
6 articles · ~43 min total · reads in order
Encrypted DNS: Privacy vs. Anonymity
How encrypted DNS changes who can observe DNS traffic, why encryption doesn't make queries anonymous, and where the privacy boundaries actually sit.
DNS over TLS: How DoT Encrypts Resolver Traffic
How DNS over TLS carries ordinary DNS messages through a dedicated TLS connection: port 853, authentication, connection reuse, and privacy profiles.
DNS over HTTPS: How DoH Changes the DNS Transport
How DNS over HTTPS carries ordinary DNS messages through HTTPS, what changes for clients and networks, and what stays DNS all the way through.
DNS over QUIC (DoQ): Encrypted DNS Without TCP
How DNS over QUIC carries encrypted DNS over QUIC, what changes compared with DNS over TLS, and why independent streams matter for DNS transport behavior.
Oblivious DNS over HTTPS (ODoH): Separating Client Identity from DNS Queries
How Oblivious DNS over HTTPS separates the client network address from query contents by placing a non-colluding proxy between client and target.
Transparent DNS Proxies and Hidden DNS Interception
How networks transparently redirect unencrypted DNS, why the term DNS proxy is ambiguous, and what interception means for resolver choice and troubleshooting.