Explainers

DNS Encryption Alone Won't Shield Your Web Habits

Elias Vance · · 8 min read

⚡ The short answer

Discover why secure DNS is just one piece of the privacy puzzle and how to layer your defenses for true online anonymity.

Read the long version ↓
DNS Encryption Alone Won't Shield Your Web Habits

You’ve done your research. You’ve enabled DNS-over-HTTPS (DoH) or DNS-over-TLS (DoT) in your browser or operating system, confident that you’ve secured a critical layer of your online privacy. The little padlock in your browser reassures you, suggesting a safe, encrypted connection. You assume that because your DNS queries are now encrypted, your internet service provider (ISP) can no longer see what websites you’re visiting. You feel a sense of accomplishment, a quiet victory against corporate snooping.

But here’s the uncomfortable truth: DNS encryption, while a vital step, doesn’t actually hide all your web browsing activity from your ISP or other sophisticated trackers. In my experience, relying solely on DoH or DoT for comprehensive privacy is one of the most common misconceptions people have. It’s like putting a secure lock on your front door but leaving all your windows wide open. While your DNS queries are indeed private, there are many other signals your online activity broadcasts that can be easily intercepted and analyzed, painting a surprisingly clear picture of your internet habits.

Key Takeaways

  • Encrypted DNS (DoH/DoT) only protects DNS queries, not all internet traffic or metadata.
  • Your ISP can still track your browsing through SNI and IP address connections, even with secure DNS.
  • VPNs are essential for comprehensive browsing privacy by encrypting all traffic and hiding your IP.
  • Browser fingerprinting and third-party cookies still pose significant privacy risks, requiring additional mitigation.

Encrypted DNS: A Necessary, But Insufficient Layer of Defense

When you type a website address like quicktechbrief.com into your browser, your computer needs to translate that human-readable name into an IP address (e.g., 192.0.2.1) that computers understand. This translation is handled by the Domain Name System (DNS). Traditionally, these DNS queries are sent unencrypted, meaning anyone on your network path, including your ISP, could see every website you intend to visit.

DNS-over-HTTPS (DoH) and DNS-over-TLS (DoT) address this vulnerability by encrypting your DNS queries. Instead of sending plain text, your request for an IP address is wrapped in an encrypted tunnel, either over the HTTPS protocol (like regular secure web traffic) or directly over TLS. This prevents your ISP from seeing what domains you’re asking about directly. This is a significant improvement, particularly when you’re using public Wi-Fi or concerned about localized censorship. For example, if your government blocks access to certain news sites at the DNS level, DoH can bypass this by routing your encrypted queries to an uncensored DNS resolver.

However, the crucial point is that this encryption only applies to the DNS query itself. Once your browser receives the IP address, it then attempts to establish a connection to that IP address. This subsequent connection is separate from the DNS query and still carries revealing metadata. Your ISP, for instance, still sees the IP addresses you connect to, the volume of data exchanged, and the duration of those connections. Imagine your ISP as a post office: DoH means they can’t read the address label you write on a small, specific letter (your DNS query), but they still see every package you send and receive, their destination, and their size. That’s a lot of information.

The Unencrypted Signals: SNI and IP Address Tracking

Even if your DNS queries are completely hidden, your ISP (and anyone else monitoring your traffic) still has two major avenues to track your browsing: Server Name Indication (SNI) and direct IP address connections.

Most websites today use HTTPS, meaning the content of your communication with the website is encrypted. This is good, but it’s not a silver bullet for privacy. When your browser initiates an HTTPS connection to a website, it sends a Server Name Indication (SNI) in plain text during the initial handshake. The SNI tells the server which specific website you’re trying to reach on an IP address that might host multiple websites. Without the SNI, the server wouldn’t know which website’s certificate to present, and the connection would fail.

So, while the main conversation is encrypted, your ISP still sees the destination domain name in the SNI. This means they still know you’re connecting to quicktechbrief.com, even if they didn’t see the DNS query for it. In my testing, even with DoH enabled, network sniffers can easily pick up SNI requests, revealing the intended website. This is a fundamental part of how HTTPS works in a world of shared IP addresses.

Beyond SNI, your ISP also observes the IP addresses your device connects to. Many websites, especially smaller ones, might reside on a dedicated IP address. Even if multiple sites share an IP, a sophisticated ISP or government entity can correlate your connection to a specific IP with other publicly available information about that IP (e.g., who owns it, what other sites it hosts) to infer what you’re doing. This correlation is particularly effective for tracking connections to services like streaming platforms, social media, or specific news outlets that often use distinct IP ranges.

Why a VPN is Non-Negotiable for True Browsing Privacy

This is where a virtual private network (VPN) becomes absolutely critical. A VPN doesn’t just encrypt your DNS queries; it encrypts all your internet traffic from your device to the VPN server. This means your SNI is also encrypted within the VPN tunnel. Your ISP then only sees an encrypted connection to the VPN server’s IP address, not the actual websites you’re visiting or the SNI for those sites. To your ISP, all your online activity looks like gibberish flowing to a single, anonymous endpoint: your VPN provider.

Furthermore, a good VPN hides your true IP address. When you connect to a website through a VPN, the website sees the VPN server’s IP address, not yours. This makes it far more difficult for websites, advertisers, and other third parties to track you across different sites and link your browsing behavior back to your personal identity or location. In my experience running network diagnostics, the difference in exposed metadata between just DoH and DoH with a VPN is stark. With DoH alone, SNI and target IP addresses are still visible. With a VPN, that information is entirely obscured from your local network and ISP.

However, it’s crucial to choose a reputable VPN provider with a strict no-logs policy and strong encryption standards. A poor VPN can itself become a new point of vulnerability, collecting and potentially selling your data. Invest in a paid, audited VPN service rather than relying on free, unproven alternatives.

Beyond Network Layers: Browser Fingerprinting and Third-Party Cookies

Even with a VPN and encrypted DNS, your privacy isn’t fully guaranteed. The internet’s design, particularly how websites interact with your browser, creates additional vulnerabilities. Browser fingerprinting and third-party cookies are two major culprits.

Browser fingerprinting involves collecting a unique combination of attributes from your web browser and device – everything from your screen resolution and installed fonts to your operating system, browser plugins, and even how your graphics card renders specific elements. This data, when combined, can create a remarkably unique ‘fingerprint’ that identifies you even without cookies. It’s often more persistent than cookies, as deleting cookies does nothing to change your browser’s inherent characteristics.

Third-party cookies, meanwhile, are placed on your browser by domains other than the one you are directly visiting. These are typically used by advertising networks to track your browsing habits across multiple websites, building profiles for targeted ads. While many browsers now offer some protection against third-party cookies, they remain a pervasive tracking mechanism.

To combat these, I advocate for a multi-pronged approach: use a privacy-focused browser (like Brave or Firefox with enhanced tracking protection), regularly clear your cookies and browser history, consider anti-fingerprinting browser extensions, and restrict unnecessary permissions for websites. This combination, alongside your VPN and DoH, creates a much more robust privacy posture.

Taking Control: Your Next Steps for Real Privacy

If your goal is to truly shield your web browsing from your ISP and other trackers, relying solely on encrypted DNS isn’t enough. It’s an excellent first step, but it must be part of a broader strategy. I’ve found that the best approach involves layering multiple privacy tools and habits, each addressing a different vector of data leakage.

First, implement DoH or DoT in your browser and operating system. This is fundamental. Most modern browsers like Chrome, Firefox, and Edge offer this in their privacy settings. For operating systems, Windows and macOS also provide options, though they may require a bit more digging.

Second, and critically, use a reputable VPN. This is the only way to encrypt your entire connection and hide your IP address and SNI from your ISP. Ensure it’s a paid service with a no-logs policy that has been independently audited. I routinely switch VPN servers throughout the day to further obfuscate my location and activity patterns, a practice I’ve found significantly increases my digital anonymity.

Third, adopt a privacy-first browser and configure its settings rigorously. Disable third-party cookies, enable strict tracking protection, and explore add-ons that combat browser fingerprinting. Don’t just accept default settings; take an hour to customize them to your privacy preferences.

Finally, cultivate mindful browsing habits. Think before you click on suspicious links, be wary of giving excessive permissions to websites, and regularly review your browser’s privacy controls. No technology can fully protect you if your habits create unnecessary exposure. It’s a continuous process of awareness and adjustment, but the peace of mind knowing your online activities are truly your own is well worth the effort.

Frequently Asked Questions

Can my ISP see my browsing history if I use encrypted DNS?

No, not directly in the way they could with unencrypted DNS. Encrypted DNS (DoH/DoT) prevents your ISP from seeing your specific DNS queries. However, your ISP can still infer your browsing activity by monitoring the IP addresses you connect to and the Server Name Indication (SNI) sent during HTTPS handshakes, which often reveal the domain name you’re visiting.

Does using HTTPS mean my ISP can’t see what websites I visit?

HTTPS encrypts the content of your communication with a website, preventing your ISP from reading the actual data you exchange. However, during the initial connection, your browser still sends an unencrypted Server Name Indication (SNI) which contains the website’s domain name. This means your ISP can still see which website you are connecting to, even if they can’t see what you’re doing on it.

Is a free VPN good enough for privacy if I already use secure DNS?

No. Free VPNs often come with significant privacy risks. Many free services collect and sell user data, inject ads, or have weaker encryption standards. Even with secure DNS, a compromised VPN can expose all your traffic. For true privacy, invest in a reputable, paid VPN service with a strict no-logs policy and a history of independent audits.

How does browser fingerprinting work, and how can I protect against it?

Browser fingerprinting collects unique data about your device and browser (e.g., screen size, fonts, plugins, operating system) to create a unique identifier, allowing trackers to follow you even without cookies. To protect against it, use privacy-focused browsers that actively combat fingerprinting, install anti-fingerprinting browser extensions, and regularly clear your browser’s data. Some browsers like Brave randomize fingerprintable attributes to make tracking harder.

What’s the single most important step for improving online browsing privacy?

While encrypted DNS is important, the single most impactful step is using a reputable VPN. A VPN encrypts all your internet traffic, including DNS queries and SNI, and routes it through a server controlled by the VPN provider. This hides your real IP address and makes all your internet activity appear as encrypted traffic to your ISP, providing a much higher level of anonymity than encrypted DNS alone.

Elias Vance — Security-minded generalist who writes about passwords, scams and account protection.

More briefs like this