DNS over HTTPS: Encrypting the Last Mile of Resolution
The real friction was not technical — it was political. ISPs monetized DNS telemetry. Governments mandated resolution logging. The idea of encrypting a protocol that was designed to be public felt counterintuitive to people who confused “observable” with “manageable.” But the foundation was laid: the spec existed, the resolver existed, and the need was undeniable.
The backlash was immediate. ISPs filed complaints. The UK’s Open Rights Group debated whether encrypted DNS would undermine parental controls and content filtering. Governments in Australia and India raised national security concerns. The irony was thick: the same entities that had been passively collecting DNS data for years suddenly claimed encryption would harm their ability to protect citizens. What they meant was it would harm their ability to collect data on citizens.
A New Problem Emerged
Encrypted Client Hello, the TLS extension that hides the SNI field, was blocked by China’s Great Firewall and by enterprise DLP tools that relied on hostname inspection. The censorship and surveillance apparatuses adapted faster than the privacy community expected. ECH was effective but politically radioactive — governments framed it as a threat to lawful interception and child safety. The result was a patchwork: DoH worked in liberal democracies, was throttled in authoritarian states, and was outright blocked in a few.
The Real Evolution
The real evolution was in threat modeling. Red teams stopped probing DNS as a primary vector — not because it disappeared, but because encryption forced them to find harder targets. OSINT practitioners pivoted to passive DNS databases and certificate transparency logs. The arms race moved upstream: now the battle was over DoH resolver trust, not query privacy. Who runs your resolver matters more than whether your queries are encrypted.
DNS over HTTPS solved the eavesdropping problem but created a new one: resolver centralization. When everyone routes through Cloudflare or Google, the resolver becomes a single point of observation. The privacy win of encrypted queries is partially offset by the concentration of resolution infrastructure. The next frontier is decentralized resolution — DANE, blockchain-based DNS, and peer-to-peer resolvers that eliminate the single-trusted-node model entirely.
For practitioners, the takeaway is simple: enable DoH everywhere, but do not stop there. Pair it with DNSSEC validation, ECH where supported, and a resolver you actually trust — ideally one you run yourself. The last mile is encrypted. The trust model is yours to define.
The practical setup has also matured significantly. Most major Linux distributions now ship with systemd-resolved configured for DoH out of the box. Cloudflare’s 1.1.1.1 resolver supports DoH with DNSSEC validation enabled by default. Quad9 offers a privacy-focused alternative that blocks malware and phishing at the resolver level. The configuration burden has dropped from a custom script to a single flag in your network manager. If you have not enabled encrypted DNS on your machines yet, the time is long past due.