Posted in

DNS over HTTPS Explained Simply

DNS over HTTPS encrypts DNS queries between your device and a compatible DNS resolver by sending those queries over HTTPS.

It is usually shortened to DoH.

Traditional DNS traffic can be visible to networks between you and your resolver. DNS over HTTPS changes that by carrying DNS requests inside an HTTPS connection protected by TLS. DoH is standardized in RFC 8484.

Why does DNS over HTTPS matter?

Suppose you visit:

example.com

Before connecting, your device usually needs to discover the site’s IP address.

With traditional unencrypted DNS, that lookup may be observable on the local network.

With DNS over HTTPS, the DNS request and response are encrypted while traveling between your device and the DoH resolver.

Does DoH make you anonymous?

No.

That’s one of the biggest misconceptions about DNS over HTTPS.

DoH protects DNS traffic in transit to the resolver, but the resolver itself can still process the domains you’re requesting. Standard DoH therefore should not be confused with an anonymity service.

Is DNS over HTTPS the same as DNSSEC?

No.

They solve different problems.

DoH protects the connection carrying the DNS query. DNSSEC helps verify the authenticity of DNS data.

The two technologies are independent and can work together. RFC 8484 specifically notes that using one does not remove the usefulness of the other.

For home users, DNS over HTTPS can provide greater protection against local DNS monitoring and tampering.

For companies, things become more complicated because organizations may rely on DNS visibility for filtering, security monitoring and internal services. Managed DoH deployments therefore need to fit the organization’s wider DNS strategy.

In simple terms: DNS over HTTPS doesn’t change what DNS does. It changes how your DNS question travels to the resolver.

Posted in

What Is a DNS Sinkhole?

A DNS sinkhole is a security mechanism that prevents users or infected devices from reaching known malicious domains by redirecting their DNS requests to a controlled destination.

Normally, when your computer requests example.com, DNS finds the IP address associated with that domain.

A DNS sinkhole changes that process for domains known to be dangerous.

How does a DNS sinkhole work?

Imagine malware on an employee’s laptop trying to contact a command-and-control server at:

bad-domain.example

Instead of returning the attacker’s real server address, the organization’s DNS system recognizes the domain as malicious and redirects the request to a safe destination.

The malware has effectively reached a dead end.

CISA describes DNS sinkholing as a way to redirect clients trying to reach malicious domains toward a benign destination, helping block command-and-control communication.

DNS sinkholes can also detect infections

Blocking traffic isn’t their only advantage.

Security teams can monitor DNS sinkhole logs and identify devices repeatedly attempting to contact malicious domains. That can reveal an infected endpoint that might otherwise remain unnoticed. CISA specifically recommends sinkhole monitoring and logging for this reason.

Does a DNS sinkhole stop every attack?

No.

Malware might communicate directly with a hard-coded IP address instead of resolving a domain. Incorrect threat intelligence can also cause legitimate domains to be blocked.

DNS caching matters too. If a malicious address was already cached, a newly created DNS sinkhole rule may not take effect until the existing DNS TTL expires.

That makes a DNS sinkhole one layer of security rather than a complete security system.

Its biggest strength is simple: DNS happens early in many network connections, so stopping a malicious domain at the DNS layer can prevent the connection before it ever begins.