DoT protocol: DNS-over-TLS explained

Every time you open a website, your device asks a DNS server for its address — normally in plain text that anyone on the network can read. DNS-over-TLS (DoT) encrypts those lookups. Here’s how it works and how to switch it on.

By the Dot Protocol engineering team · Updated 11 October 2026

What DoT is

DNS-over-TLS, usually shortened to DoT, is a standard (RFC 7858) for sending DNS queries inside an encrypted TLS connection — the same encryption that protects HTTPS websites. Without it, your DNS lookups travel unencrypted, so your internet provider, the owner of a public Wi-Fi network, or anyone in between can see every site you look up and can even change the answers.

With DoT turned on, those parties can see that you’re talking to a DNS server, but not what you’re asking it.

How it works

  1. Your device opens a TCP connection to the DNS resolver on port 853, the port reserved for DoT.
  2. It checks the resolver’s TLS certificate against the hostname you configured (for example one.one.one.one), so an impostor server can’t answer for it.
  3. DNS questions and answers then flow through the encrypted connection, which stays open for further lookups.

DoT vs DoH

DNS-over-HTTPS (DoH, RFC 8484) solves the same problem by sending DNS inside normal HTTPS traffic on port 443. Both encrypt your lookups equally well; the difference is visibility.

DNS-over-TLS (DoT)DNS-over-HTTPS (DoH)
Port853, dedicated to DoT443, shared with all web traffic
Network admins canSee that DoT is used, and block itHardly tell it apart from browsing
Built intoAndroid (Private DNS), Linux, many routersBrowsers, Windows 11, Apple devices via profiles
Best forWhole-device or whole-network protection you manageNetworks that block port 853

Public DoT servers

You need a resolver that supports DoT. These are free, widely used and support both DoT and DoH:

ProviderDoT hostnameIP addressNotes
Cloudflareone.one.one.one1.1.1.1Fast, privacy-focused
Google Public DNSdns.google8.8.8.8Very reliable
Quad9dns.quad9.net9.9.9.9Blocks known malicious domains; Swiss non-profit
AdGuard DNSdns.adguard-dns.com94.140.14.14Blocks ads and trackers

Android (9 and newer)

Android calls DoT Private DNS, and it applies to the whole phone on Wi-Fi and mobile data.

  1. Open Settings → Network & internet → Private DNS. On Samsung phones it’s under Connections → More connection settings → Private DNS.
  2. Choose Private DNS provider hostname.
  3. Enter a hostname from the table above, such as one.one.one.one, and save.

If you enter a hostname that doesn’t work, Android shows “Couldn’t connect” — check the spelling.

iPhone, iPad and Mac

Apple devices support encrypted DNS (iOS 14 and macOS Big Sur or newer), but there’s no switch for it in Settings. You turn it on in one of two ways:

  • An app from the DNS provider, such as Cloudflare’s 1.1.1.1 app, which installs the setting for you.
  • A configuration profile (.mobileconfig) from the provider. After downloading it, go to Settings → General → VPN & Device Management to install it.

Windows 11

Standard Windows 11 releases encrypt DNS with DoH rather than DoT. It protects you in the same way:

  1. Open Settings → Network & internet, then Wi-Fi or Ethernet, and select your connection’s Hardware properties.
  2. Next to DNS server assignment, select Edit and switch to Manual.
  3. Turn on IPv4, enter 1.1.1.1 as the preferred DNS, and set DNS over HTTPS to On (automatic template).
  4. Save. Repeat for IPv6 with 2606:4700:4700::1111 if you use IPv6.

Linux (systemd-resolved)

On Ubuntu, Fedora and other distributions that use systemd-resolved, edit /etc/systemd/resolved.conf:

[Resolve]
DNS=1.1.1.1#cloudflare-dns.com 1.0.0.1#cloudflare-dns.com
DNSOverTLS=yes

Then restart the service:

sudo systemctl restart systemd-resolved
resolvectl status

The status output should show +DNSOverTLS for your connection.

Routers

Turning on DoT at the router protects every device on your network, including TVs and smart devices that have no setting of their own.

  • ASUS (Asuswrt): WAN → Internet Connection → set DNS Privacy Protocol to DNS-over-TLS and add a server from the table.
  • pfSense and OPNsense: enable DNS-over-TLS forwarding in the Unbound DNS resolver settings.
  • OpenWrt: install the stubby package and point it at your chosen resolver.

Setting this up across an office network? We can do it for you.

Check it’s working

If you use Cloudflare, open one.one.one.one/help. “Using DNS over TLS (DoT)” should say Yes. From a terminal you can also confirm the resolver answers on port 853:

openssl s_client -connect 1.1.1.1:853 -servername cloudflare-dns.com

What DoT doesn’t hide

DoT only protects the lookup. Your internet provider or Wi-Fi owner can still see the IP addresses you connect to, and usually the site names in the TLS handshake. And the DNS provider you pick sees all your queries, so choose one whose privacy policy you trust.

To hide your browsing from the local network and your provider as well, use a VPN. It encrypts all traffic from your device, DNS included.