Definition · DNS & Email Spoofing

What is DNS over HTTPS?

DNS over HTTPS (DoH), specified in RFC 8484, wraps DNS queries in HTTPS requests to a resolver endpoint, typically on port 443. Classic DNS travels in cleartext on port 53, where anyone on the path — a network operator, a coffee-shop router, an ISP — can see every name a client looks up and can tamper with the answers. DoH encrypts and authenticates that leg of the journey.

DNS over TLS (DoT), defined in RFC 7858, does the same thing on its own port, 853. The cryptography is equivalent; the practical difference is that DoT is easy to identify and block by port, while DoH is indistinguishable from other HTTPS traffic.

What DoH does and does not protect

  • Protects the query and response between the client and its chosen resolver from eavesdropping and modification.
  • Does not hide anything from the resolver itself, which sees every lookup in plaintext. DoH changes who you trust, it does not remove the need to trust someone.
  • Does not authenticate the DNS data itself. That is DNSSEC, which proves an answer came from the authoritative zone; DoH secures the transport. The two solve different halves of the problem and are usually best deployed together.
  • Does not conceal which sites a client visits from an observer watching TLS Server Name Indication and destination addresses, unless Encrypted Client Hello is also in play.

The enterprise tension

Many organisations rely on inspecting or filtering DNS: blocking known malicious domains, spotting beaconing to newly registered domains, and logging lookups for investigations. When a browser or application enables DoH to a public resolver, those queries bypass the corporate resolver entirely, and the visibility disappears. Malware authors noticed the same property and use DoH to hide command-and-control lookups.

Practical responses are to run an internal DoH or DoT resolver and point managed clients at it, to use the canary domains and enterprise policies that major browsers honour for disabling automatic DoH upgrades, and to accept that filtering by DNS is a control with a shrinking blast radius rather than a boundary.

See DNS record types, DNS propagation, network segmentation for other boundary controls, and defence in depth for why DNS filtering should not be a single point of protection.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.