Back to blog
dns Published: AEU DNS Newsroom

Firefox Considers Enabling Private DNS Lookups by Default

Firefox Considers Enabling Private DNS Lookups by Default

Mozilla already includes encrypted DNS in Firefox but leaves it off by default, and developers are now discussing flipping that switch for everyone.

Recent versions of the Mozilla Firefox web browser quietly introduced a privacy feature that many users may not have noticed. Firefox now supports something called a Trusted Recursive Resolver, which is essentially Mozilla's name for DNS-over-HTTPS (DoH). Despite being built into the browser, the feature remains switched off by default. That could change, because developers inside the Mozilla community have started discussing whether to turn it on for all users automatically.

To understand why this matters, it helps to know what the Domain Name System (DNS) does. DNS is often compared to a phone book for the internet. When you type a website name like example.com, your device asks a DNS server, also called a resolver, to translate that human-friendly name into a numeric IP address that computers use to connect. Traditionally, those DNS queries travel over the network in plain text, meaning anyone on the network path, such as an internet service provider, a Wi-Fi hotspot operator, or a malicious actor, can see which sites you are visiting and potentially alter the response. DNS-over-HTTPS changes this by sending DNS queries inside an encrypted HTTPS connection, the same secure protocol used for online banking and shopping. This hides the queries from network observers and makes it harder to block or tamper with them.

Firefox currently gives users the option to enable DoH manually, but it is not the default. The discussions in the Mozilla developer community are significant because changing the default would automatically route the DNS traffic of a huge number of everyday users through a DoH resolver, potentially one operated by a third party rather than the user's internet provider. This would be a major shift in how browsing privacy is delivered. Instead of requiring each person to find and configure an encrypted DNS service, the browser would handle it automatically for everyone.

However, DoH is not without controversy. An important concern is that it moves control plane, or signalling, messages to a different part of the network stack. In practical terms, DNS queries, which were once sent over a dedicated channel often managed by network administrators, become encrypted web traffic that is much harder for local networks to inspect. This can undermine DNS-based content filtering, parental controls, and enterprise security monitoring that rely on seeing or redirecting DNS requests. For example, a school or business that blocks access to certain categories of websites through its own DNS server would find that a browser using DoH directly may bypass those restrictions unless the browser is configured to respect them. Some network operators also worry about the centralizing effect if a small number of DoH resolver providers become dominant, because they would then see the browsing patterns of millions of users.

For individual users, the privacy benefit is real. Your internet provider or the owner of a public Wi-Fi network would no longer be able to easily log every domain name your browser looks up. That reduces one form of online tracking and profiling. But users should think carefully about which DoH resolver they trust. Any resolver, encrypted or not, can see the websites you visit. So the choice of a resolver with a clear, audited no-logs policy becomes important. For readers who want to take advantage of encrypted DNS without simply accepting whatever the browser picks, a service like AEU DNS offers private, encrypted DNS resolution with a no-logs commitment, giving you both the confidentiality of DoH and a provider you can choose deliberately.

Businesses and IT teams should follow this development closely. If Mozilla eventually enables DoH by default, it could change how DNS traffic flows on corporate networks and affect existing security tools. Teams may need to configure Firefox through group policy or use a DoH-capable resolver inside the organization to maintain visibility. Website owners should also be aware that more users may reach their sites through encrypted DNS, which is unlikely to change their own operations but reinforces the importance of supporting HTTPS everywhere.

For now, the feature remains off by default in Firefox, but the fact that it is being debated publicly means users have time to learn what DoH is, test it manually, and decide what configuration best matches their privacy and security needs. Encrypted DNS is one piece of a larger movement toward making the web more private by default, and staying informed is the first step.

Terms explained

DNS (Domain Name System)
The internet's phone book that turns website names into numeric IP addresses.
DNS-over-HTTPS (DoH)
A way to send DNS requests inside an encrypted HTTPS connection so network snoopers cannot read them.
Recursive Resolver
A server that looks up DNS information on your behalf when your device asks for a website.
Trusted Recursive Resolver
Mozilla's name for a DNS resolver that the browser trusts to handle your encrypted DNS queries.
HTTPS
The secure, encrypted version of the web protocol used to protect data sent between your browser and a website.
Control Plane
The part of network communication that carries setup and signalling messages, such as DNS queries, rather than the actual content you view.

How to protect yourself

  1. Open Firefox, type about:preferences#privacy in the address bar, scroll down to "DNS over HTTPS" and turn it on, then choose a trusted provider or enter a custom one.
  2. Pick a well-known encrypted DNS service that publicly promises not to keep logs of your browsing.
  3. If a website or service stops working after enabling DoH, switch the setting back to "Off" or choose "Default protection" to troubleshoot.
  4. For parents or network administrators, be aware that DoH can bypass local content filters, so configure Firefox through group policy or use a DNS filtering service that supports encrypted DNS.
  5. Keep your Firefox browser updated so you receive the latest privacy and security improvements automatically.
  6. Use only HTTPS websites (look for the padlock) because DoH protects DNS queries but not the actual content of your web traffic.

Source: internetsociety.org

Get private, encrypted DNS