Back to blog
dns Published: AEU DNS Newsroom

Internet Society Answers Common Questions on DNS Privacy in New FAQ

Internet Society Answers Common Questions on DNS Privacy in New FAQ

The Internet Society has released a DNS Privacy FAQ, following an earlier post explaining that DNS lookups are not confidential by default and highlighting new protocols designed to fix that.

The Internet Society has released a new resource that answers common questions about DNS privacy. The Domain Name System, or DNS, is often described as the phonebook of the internet: it translates the website names you type into your browser, like example.com, into the numerical IP addresses that computers use to find each other. In a previous post, the organization explained a critical weakness: DNS does not, by itself, provide any confidentiality for DNS transactions. That means when your device asks a DNS resolver to look up a website, the request and response are sent in plain text, allowing anyone on the network path to see which sites you are visiting. The new FAQ is designed to complement that earlier discussion and highlight the most important aspects of keeping DNS queries private.

Why does this matter? Every time you visit a website, your device first sends a DNS query to a resolver, a server that performs the lookup and returns the correct IP address. In traditional DNS, these queries are unencrypted. Your internet service provider, the operator of a public Wi-Fi network, or even a malicious actor on the same network can observe these lookups. That visibility can reveal your browsing habits, enable targeted profiling, or allow someone to redirect you to a fake website. The Internet Society's earlier post noted that DNS has no built-in mechanism for confidentiality, and it mentioned that new protocols have been developed to improve user privacy. The FAQ aims to explain those protocols and what they do.

Among the most important developments are encrypted DNS protocols, which wrap DNS queries in a protective layer of encryption. DNS over HTTPS (DoH) sends DNS queries through the same secure, encrypted connection used by HTTPS websites, making them look like ordinary web traffic and hiding them from network observers. DNS over TLS (DoT) uses a dedicated encrypted channel for DNS, preventing anyone between your device and the resolver from reading the queries. Both approaches prevent snooping on which websites you ask about, although they do not hide the fact that you are using DNS at all. The Internet Society's FAQ likely covers how these protocols work, their benefits, and any limitations or trade-offs. The organization stated that the FAQ highlights and provides answers to the most important aspects of DNS privacy, making it a useful starting point for both everyday users and IT professionals.

For website owners and businesses, the stakes are high. If visitors' DNS queries are exposed, it can undermine trust and create security risks. IT teams need to understand DNS privacy so they can configure their networks and devices to use secure resolvers. The FAQ is also relevant for parents who want to limit what their children's devices expose, for remote workers who rely on public Wi-Fi, and for anyone concerned about their internet provider building a profile of their online activity. The Internet Society's resource is not a technical manual but a set of clear answers aimed at a broad audience.

Putting the guidance into practice starts with choosing a DNS resolver that supports encryption. Many modern operating systems and browsers have built-in options to turn on secure DNS, and you can also configure your home router to use an encrypted resolver for every device on your network. For readers who want a straightforward way to adopt these protections, a privacy-first resolver like AEU DNS offers encrypted DNS over HTTPS and TLS, helping to keep your browsing queries confidential from network snooping without collecting logs. That single service can reduce the risk of DNS monitoring and improve your overall online privacy.

Terms explained

DNS
The Domain Name System, which translates website names into numerical IP addresses that computers use to connect to each other.
Resolver
A server that receives your DNS query and looks up the correct IP address for the website you want to visit.
IP address
A unique number assigned to each device on the internet, used to route information to the right place.
Encryption
A way of scrambling information so that only the intended recipient can read it.
DNS over HTTPS (DoH)
A method of sending DNS queries through the same encrypted connection used for secure websites, hiding them from snooping.
DNS over TLS (DoT)
A method of encrypting DNS queries using a dedicated secure channel, preventing others on the network from reading them.
Plaintext
Information sent without encryption, so anyone who intercepts it can read it.
Confidentiality
Keeping information secret from anyone who is not supposed to see it.

How to protect yourself

  1. Use a DNS resolver that supports encrypted DNS, such as one offering DNS over HTTPS or DNS over TLS, and set it up on your device or router.
  2. Turn on the encrypted DNS option in your web browser if available; many browsers have a built-in setting for secure DNS.
  3. Check your operating system's network settings for a Private DNS or Secure DNS option and enter the address of a trusted encrypted DNS provider.
  4. Avoid using public Wi-Fi networks without encrypted DNS, because other people on the same network can see your unencrypted DNS queries.
  5. Periodically review the privacy policy of your chosen DNS provider to make sure it does not keep logs of your browsing activity.

Source: internetsociety.org

Get private, encrypted DNS