DNS over HTTPS encrypts DNS queries between your device and a compatible DNS resolver by sending those queries over HTTPS.
It is usually shortened to DoH.
Traditional DNS traffic can be visible to networks between you and your resolver. DNS over HTTPS changes that by carrying DNS requests inside an HTTPS connection protected by TLS. DoH is standardized in RFC 8484.
Why does DNS over HTTPS matter?
Suppose you visit:
example.com
Before connecting, your device usually needs to discover the site’s IP address.
With traditional unencrypted DNS, that lookup may be observable on the local network.
With DNS over HTTPS, the DNS request and response are encrypted while traveling between your device and the DoH resolver.
Does DoH make you anonymous?
No.
That’s one of the biggest misconceptions about DNS over HTTPS.
DoH protects DNS traffic in transit to the resolver, but the resolver itself can still process the domains you’re requesting. Standard DoH therefore should not be confused with an anonymity service.
Is DNS over HTTPS the same as DNSSEC?
No.
They solve different problems.
DoH protects the connection carrying the DNS query. DNSSEC helps verify the authenticity of DNS data.
The two technologies are independent and can work together. RFC 8484 specifically notes that using one does not remove the usefulness of the other.
For home users, DNS over HTTPS can provide greater protection against local DNS monitoring and tampering.
For companies, things become more complicated because organizations may rely on DNS visibility for filtering, security monitoring and internal services. Managed DoH deployments therefore need to fit the organization’s wider DNS strategy.
In simple terms: DNS over HTTPS doesn’t change what DNS does. It changes how your DNS question travels to the resolver.