How DNS Over HTTPS Limits ISP Snooping
Every time a device looks up a website name, it usually asks a DNS resolver to translate that name into an IP address. Traditional DNS sends the request in plain text, so the network carrying it can often read which domains you are trying to reach. Your internet service provider may not see the contents of an encrypted page, but it can still learn a great deal from these lookups.
DNS over HTTPS, usually shortened to DoH, places DNS requests inside an encrypted HTTPS connection. This prevents a local network operator or ISP from casually inspecting the domain queries as they travel between your device and the resolver. It is a useful privacy measure for home broadband, mobile data and public Wi-Fi.
Learning how to use DNS over HTTPS to prevent ISP snooping is straightforward, though it is not a complete anonymity system. DoH changes who can observe your DNS activity; it does not conceal every connection, remove tracking cookies or stop a website from identifying you. The best results come from treating it as one layer in a broader privacy strategy.
What DNS Reveals About Your Browsing
DNS is the internet’s address book. When you enter a domain such as example.com, your device asks a resolver for the numerical address needed to connect. The request can reveal the site’s domain even when the website itself uses HTTPS. The page contents, login details and URL path may be encrypted, but the initial lookup can still expose a useful outline of your online activity.
That outline can be surprisingly revealing. A sequence of lookups may suggest visits to health services, political organisations, financial websites, employment portals or specialist forums. An ISP may use DNS information for network security, troubleshooting and legal compliance, while advertisers and other intermediaries may have their own reasons for collecting browsing signals. In Australia, where much household access runs through NBN connections supplied by companies such as Telstra, Optus, TPG and their resellers, the provider sits in a position to observe the traffic leaving your connection.
Australia’s telecommunications data-retention framework adds another reason to understand the difference between content, metadata and DNS. It does not mean every DNS lookup is automatically stored in an identical way, yet lawful access obligations and network records remain part of the environment. DoH reduces routine visibility on the path to the resolver; it does not make communications legally invisible or erase other records.
How Encrypted DNS Changes The Path
With ordinary DNS, your computer may send a query over UDP or TCP to a resolver supplied by the ISP. DoH instead sends the query through an HTTPS session, commonly to a service such as Cloudflare, Google, Quad9 or NextDNS. The ISP can see that your device is communicating with the chosen resolver, but it should not be able to read the individual domain queries inside that encrypted connection.
This shifts trust rather than eliminating it. The DoH operator can generally see the DNS requests it receives, along with information such as the source address and timing. A provider may retain logs, publish a privacy policy, offer filtering or use different arrangements for free and paid accounts. Read those policies before choosing a resolver, and avoid assuming that a familiar technology company automatically offers the most private option.
DoH also leaves important clues visible. Your ISP can usually see the IP addresses your device connects to, traffic volume, connection times and sometimes the service infrastructure behind a website. Encrypted web traffic can also expose patterns through techniques such as traffic analysis. DNS over HTTPS is therefore best understood as protection against straightforward DNS inspection, rather than a cloak over all internet activity.
The history of advertising technology shows why this distinction matters. Google’s FLoC experiment tried to replace individual tracking with group-based signals, yet the basic question remained: which parties receive information about your interests and what can they infer? This privacy history of FLoC is a useful reminder that changing the mechanism does not automatically remove surveillance incentives.
Choosing A Resolver You Can Trust
Start by deciding what you want DoH to achieve. If your main concern is stopping an ISP from reading DNS requests, any reputable encrypted resolver may address that specific problem. If you also want malicious-domain blocking, family filtering, analytics controls or detailed device policies, look for a service that documents those features clearly rather than treating them as accidental benefits.
Quad9 is often considered by people who want security-oriented blocking, while Cloudflare’s 1.1.1.1 service is widely known for speed and ease of use. Google Public DNS is another established option. NextDNS provides extensive customisation, including blocklists and per-device settings, though its account model and logging controls deserve close attention. A locally operated resolver can reduce dependence on a large commercial provider, but running one does not automatically hide requests from your ISP unless the connection to the upstream resolver is encrypted.
Read the provider’s privacy documentation for collection, retention, sharing and deletion practices. Check whether the service keeps full query logs, temporary operational logs or aggregated statistics. Some providers publish transparency reports or independent audits; these are useful evidence, although they are not guarantees. A free service may be funded by products or data practices that are less obvious than a paid subscription.
Performance matters as well. A resolver with a nearby Australian point of presence may respond quickly for users in Sydney, Melbourne, Brisbane or Perth, but speed should not outrank a clear privacy policy. Test two or three reputable options rather than choosing a resolver solely because it returns the fastest result in one afternoon.
Turning On DoH In Common Devices
The simplest route is usually the browser. In Firefox, open Settings, go to Privacy & Security, find DNS over HTTPS and select a standard protection level or a custom provider. Chrome and Chromium-based browsers such as Microsoft Edge place a similar control under privacy or security settings, often labelled Use secure DNS. Choose a provider deliberately instead of leaving the setting tied to an unknown default.
Browser-level DoH protects lookups made by that browser, but other applications may continue using the operating system’s ordinary DNS. Games, software updaters, messaging clients and smart-home applications can bypass it. If you want broader coverage, configure encrypted DNS in the operating system, install a reputable privacy application or set it up on a compatible home router.
Windows 11 includes encrypted DNS options in network settings, although the exact labels can vary with the release. macOS does not offer a universally simple built-in DoH switch, so users commonly rely on a configuration profile, a trusted client or router-level support. Android 9 and later includes Private DNS, which generally uses DNS over TLS rather than DNS over HTTPS. It still encrypts the DNS channel, but the protocol and configuration are different. iPhone and iPad users typically need an app or configuration profile for system-wide encrypted DNS.
Router configuration can be convenient for a household, particularly in a Brisbane flat or a family home outside Adelaide where several devices share one connection. It can also create problems: some routers silently fall back to standard DNS, and some ISP-supplied gateways restrict advanced settings. After changing the configuration, verify it with a reputable DNS leak test and check that ordinary applications are using the intended resolver.
Avoiding Leaks And False Confidence
A DoH setting can be defeated by another network component. A VPN may route DNS through its own resolver, a corporate security tool may intercept requests, and a captive portal at a hotel, university or café may require ordinary DNS before granting access. Malware can also alter DNS settings or install a local proxy. A browser icon saying secure DNS is enabled does not prove that every lookup from the device is protected.
Encrypted DNS can interfere with services that depend on local resolution. Australian workplaces, schools and universities may use internal domains that only resolve through their managed DNS service. Streaming platforms, banking websites and game networks can also behave differently when a resolver changes your apparent location or applies blocking. On a Qantas lounge network or a café Wi-Fi connection in Melbourne, a privacy setting may be valuable, but it should not be treated as a substitute for a VPN when you need to conceal destinations from the Wi-Fi operator.
Use split decisions carefully. Some setups allow selected private domains to use a local resolver while public lookups use DoH. This may be necessary for work, but it means the privacy boundary is more complicated. Keep track of which device, browser and network is responsible for each DNS request. Testing after major operating-system, browser or router updates is worthwhile because settings can be reset.
DNS privacy also sits beside other security basics. HTTPS protects the connection to the website, strong account authentication reduces takeover risk, and tracker controls limit what sites and advertising networks can associate with you. Encrypted backups matter for a different part of the same privacy model: protecting stored information when a device is lost, seized or compromised. A practical encrypted backup guide can help connect network privacy with protection for the data sitting on your laptop and phone.
Building A Sensible Privacy Routine
Begin with one device and one clear objective. Enable DoH in your main browser, select a resolver whose logging policy you understand and test a few ordinary sites. Then check a banking service, a streaming platform and any work or study system you use. If something breaks, record the failure before changing several settings at once; that makes it easier to identify whether the resolver, browser or network is responsible.
Next, consider the rest of your household network. Router-level encrypted DNS can cover televisions, tablets and consoles that offer no privacy controls of their own. However, family members may rely on ISP filtering, local services or parental controls that disappear when the router uses a different resolver. Explain the change and keep a simple record of the previous settings so they can be restored if necessary.
A VPN provides a different protection: it can hide more of your destination traffic from the ISP, while moving trust to the VPN operator. Tor offers stronger anonymity properties but is slower and unsuitable for many everyday services. Neither tool makes accounts, browser fingerprints or voluntarily shared information disappear. Combining technologies without understanding their trust boundaries can create a false sense of safety.
For a broader perspective on surveillance, technology policy and everyday privacy, the privacy essays at Twenty of Time place encrypted DNS alongside advertising systems, legislation and social habits. That context is important because privacy is rarely determined by one setting. The goal is to reduce unnecessary exposure while knowing which companies, networks and applications still receive information.
DNS over HTTPS is a modest change with a clear benefit: it prevents ordinary network observers from reading your DNS requests in transit. Its limits are equally clear. The resolver still needs trust, destination IP addresses remain visible to the ISP, and applications may bypass the setting. Use it because it closes a specific leak, then verify what actually changed.
Open your main browser’s secure-DNS settings today, choose a documented resolver, enable the feature, and run a DNS leak test before browsing normally.