.::dns::.

updated 2026-07 · 8 min read · index

before your browser talks to any site, it asks a resolver "what is the ip of this name". by default that question travels in clear text, usually to your isp's resolver. the result is a complete diary of every domain you visit, produced as a side effect of routing and trivially logged. encrypting dns closes one specific seam. it is worth doing and easy to overestimate, so this guide is as much about the limits as the fix.

what encryption changes

dns over https (doh, rfc 8484) or dns over tls (dot, rfc 7858) hides the questions from anyone on the path: the coffee-shop wifi, the isp's middlebox, the hotel network. it does not delete the diary. it moves it to the resolver you chose. this is the vpn lesson again, trust displaced rather than removed. the entire game is deciding who holds the diary and under what written policy.

dnssec is not privacy

a common confusion worth clearing. dnssec signs dns records so you can verify they were not tampered with in transit. that is integrity, not confidentiality. dnssec does nothing to hide your queries, and an encrypted resolver (doh/dot) does nothing to prove the answer is authentic. they solve different problems and are best used together, not mistaken for each other.

the honest limits

encrypting dns is one seam, not a cloak. even with it on:

newer designs push further. oblivious doh (odoh, rfc 9230) splits knowledge so that no single party sees both who you are and what you asked. useful where available, still niche.

pick a resolver

read the logging policy, then decide whose diary drawer you prefer.

all three beat your isp's default. none is magic, and a large well-run resolver also means a large anonymity set, which cuts both ways.

setup, from quick to thorough

a pi-hole is a fine lan-wide ad blocker, but note the nuance. it only helps your privacy from your isp if its own upstream resolver is itself encrypted. by default it is not.

full hermit mode

run your own recursive resolver (unbound) and no third party holds the diary at all. the trade is real. your isp now watches you query the root and authoritative servers directly, so the browsing pattern is visible to them again, just not to a resolver operator. pick your poison based on which adversary sits higher in your threat model, the resolver operator or the isp.

sources

[ home ]

.::  eof  ::.