Tools · Chapter 8
Encrypted DNS Protocols
DoH, DoT, DoQ and DNSCrypt — what each does and how hard it is to deploy.
| Protocol | What it does | Difficulty | Notes |
|---|---|---|---|
| DNS-over-HTTPS (DoH) | Encrypts DNS queries inside standard HTTPS traffic on port 443 | Easy | Indistinguishable from regular web traffic. Supported natively in Firefox, Chrome, and most modern OSes. The most accessible option. |
| DNS-over-TLS (DoT) | Encrypts DNS queries with TLS on port 853 | Easy–Medium | Slightly easier to identify and block than DoH. More clearly separated from web traffic. Common in router configurations. |
| DNS-over-QUIC (DoQ) | Encrypts DNS over the QUIC protocol | Medium | Newer standard, faster than DoT in theory. Support growing. Not yet universal. |
| DNSCrypt | Encrypts and authenticates DNS queries | Medium | Older standard, strong authentication. Less universal than DoH/DoT but excellent where supported. |
Reproduced verbatim from The Privacy Diet, Chapter 8 — “Encrypted DNS: Your Options”. The book explains the reasoning behind each verdict.