$linuxjunkies
>

DoH

also: DNS over HTTPS

DoH (DNS over HTTPS) is a protocol that encrypts DNS queries by sending them over HTTPS instead of plain-text UDP, preventing ISPs and network observers from seeing which domains you visit.

DNS over HTTPS (DoH) wraps traditional DNS lookups in HTTPS encryption, protecting your DNS queries from eavesdropping and tampering. Normally, when you visit a website, your computer sends an unencrypted DNS request to resolve the domain name—any device on your network can see this. DoH encrypts these requests end-to-end using TLS/SSL.

For example, instead of querying your ISP's DNS server directly, your browser or system resolver sends encrypted HTTPS requests to a DoH provider like Cloudflare's 1.1.1.1 or Google's 8.8.8.8. This prevents network administrators and ISPs from monitoring your browsing habits through DNS logs.

On Linux, you can enable DoH using systemd-resolved, curl, or third-party tools. Many modern browsers also support DoH natively, allowing you to bypass system DNS settings entirely for privacy.

Related terms