What DoT is
DNS-over-TLS, usually shortened to DoT, is a standard (RFC 7858) for sending DNS queries inside an encrypted TLS connection — the same encryption that protects HTTPS websites. Without it, your DNS lookups travel unencrypted, so your internet provider, the owner of a public Wi-Fi network, or anyone in between can see every site you look up and can even change the answers.
With DoT turned on, those parties can see that you’re talking to a DNS server, but not what you’re asking it.
How it works
- Your device opens a TCP connection to the DNS resolver on port 853, the port reserved for DoT.
- It checks the resolver’s TLS certificate against the hostname you configured (for example
one.one.one.one), so an impostor server can’t answer for it. - DNS questions and answers then flow through the encrypted connection, which stays open for further lookups.
DoT vs DoH
DNS-over-HTTPS (DoH, RFC 8484) solves the same problem by sending DNS inside normal HTTPS traffic on port 443. Both encrypt your lookups equally well; the difference is visibility.
| DNS-over-TLS (DoT) | DNS-over-HTTPS (DoH) | |
|---|---|---|
| Port | 853, dedicated to DoT | 443, shared with all web traffic |
| Network admins can | See that DoT is used, and block it | Hardly tell it apart from browsing |
| Built into | Android (Private DNS), Linux, many routers | Browsers, Windows 11, Apple devices via profiles |
| Best for | Whole-device or whole-network protection you manage | Networks that block port 853 |
Public DoT servers
You need a resolver that supports DoT. These are free, widely used and support both DoT and DoH:
| Provider | DoT hostname | IP address | Notes |
|---|---|---|---|
| Cloudflare | one.one.one.one | 1.1.1.1 | Fast, privacy-focused |
| Google Public DNS | dns.google | 8.8.8.8 | Very reliable |
| Quad9 | dns.quad9.net | 9.9.9.9 | Blocks known malicious domains; Swiss non-profit |
| AdGuard DNS | dns.adguard-dns.com | 94.140.14.14 | Blocks ads and trackers |
Android (9 and newer)
Android calls DoT Private DNS, and it applies to the whole phone on Wi-Fi and mobile data.
- Open Settings → Network & internet → Private DNS. On Samsung phones it’s under Connections → More connection settings → Private DNS.
- Choose Private DNS provider hostname.
- Enter a hostname from the table above, such as
one.one.one.one, and save.
If you enter a hostname that doesn’t work, Android shows “Couldn’t connect” — check the spelling.
iPhone, iPad and Mac
Apple devices support encrypted DNS (iOS 14 and macOS Big Sur or newer), but there’s no switch for it in Settings. You turn it on in one of two ways:
- An app from the DNS provider, such as Cloudflare’s 1.1.1.1 app, which installs the setting for you.
- A configuration profile (
.mobileconfig) from the provider. After downloading it, go to Settings → General → VPN & Device Management to install it.
Windows 11
Standard Windows 11 releases encrypt DNS with DoH rather than DoT. It protects you in the same way:
- Open Settings → Network & internet, then Wi-Fi or Ethernet, and select your connection’s Hardware properties.
- Next to DNS server assignment, select Edit and switch to Manual.
- Turn on IPv4, enter
1.1.1.1as the preferred DNS, and set DNS over HTTPS to On (automatic template). - Save. Repeat for IPv6 with
2606:4700:4700::1111if you use IPv6.
Linux (systemd-resolved)
On Ubuntu, Fedora and other distributions that use systemd-resolved, edit /etc/systemd/resolved.conf:
[Resolve]
DNS=1.1.1.1#cloudflare-dns.com 1.0.0.1#cloudflare-dns.com
DNSOverTLS=yes
Then restart the service:
sudo systemctl restart systemd-resolved
resolvectl status
The status output should show +DNSOverTLS for your connection.
Routers
Turning on DoT at the router protects every device on your network, including TVs and smart devices that have no setting of their own.
- ASUS (Asuswrt): WAN → Internet Connection → set DNS Privacy Protocol to DNS-over-TLS and add a server from the table.
- pfSense and OPNsense: enable DNS-over-TLS forwarding in the Unbound DNS resolver settings.
- OpenWrt: install the
stubbypackage and point it at your chosen resolver.
Setting this up across an office network? We can do it for you.
Check it’s working
If you use Cloudflare, open one.one.one.one/help. “Using DNS over TLS (DoT)” should say Yes. From a terminal you can also confirm the resolver answers on port 853:
openssl s_client -connect 1.1.1.1:853 -servername cloudflare-dns.com
What DoT doesn’t hide
DoT only protects the lookup. Your internet provider or Wi-Fi owner can still see the IP addresses you connect to, and usually the site names in the TLS handshake. And the DNS provider you pick sees all your queries, so choose one whose privacy policy you trust.
To hide your browsing from the local network and your provider as well, use a VPN. It encrypts all traffic from your device, DNS included.