When users browse the internet, their devices must translate website names like example.com into numerical IP addresses so they can connect to the correct server. This process is handled by the Domain Name System, or DNS. While HTTPS encryption protects most of the data exchanged between a user and a website, the initial step of resolving the domain name can still expose what sites are being visited. This has led many to explore ways to better protect their online activities.
The DNS resolver, which translates website names into IP addresses, plays a key role in this process. At home, this resolver is often provided by the user’s Internet Service Provider (ISP). While the ISP does not see the content of the websites being visited or the full URL, it can still observe the domain names and subdomains being queried, as well as the timing of these requests. Over time, this information can be used to infer a user’s online behavior, even if the actual content is protected by HTTPS.
To protect against this, users can choose alternative DNS resolvers like Cloudflare, Quad9, or Google’s public DNS, which may offer better privacy or performance. However, these resolvers still process the queries, and even those that claim not to store user data must temporarily keep the query information in memory before deleting it. To further secure DNS queries, protocols like DNS over HTTPS (DoH) and DNS over TLS (DoT) encrypt the communication between the user’s device and the resolver, preventing intermediaries like ISPs or public Wi-Fi providers from seeing the requested domains or altering the responses.
For even greater privacy, users can use a Virtual Private Network (VPN), which encrypts both DNS queries and the subsequent connection to the website. This hides the final destination from the ISP, but the VPN provider then controls the exit point of the encrypted tunnel. This means the privacy concern shifts to the VPN provider, who may resolve the domain names themselves. To address this, some users combine a VPN with DoH, separating the roles of the resolver and the tunnel. Experimental protocols like Oblivious DNS over HTTPS (ODoH) aim to enhance privacy further by introducing a relay that handles the query without revealing the user’s IP address to the resolver. This approach helps separate the origin of the query from its content, offering an additional layer of protection for online privacy.
DNS Privacy and Encryption: A Multi-Layered Approach to Online Anonymity
AI-rewritten from original reportingHow it works
dnsprivacyvpnencryptionodohdohtls
Original sources:
- 🇫🇷Clubic



