DNS over HTTPS (DoH)

A protocol that carries DNS queries and answers inside an encrypted HTTPS session, hiding them from observers on the path but also from the organisation's own DNS monitoring.

DNS over HTTPS, specified in RFC 8484 (2018), sends a client’s name lookups to a resolver as ordinary HTTPS requests. Because the exchange rides inside TLS, an observer between the client and the resolver can neither read the lookups nor alter the answers in transit. Its sibling, DNS over TLS (RFC 7858), does the same job on a dedicated port, which makes it easy to identify and block; DoH shares the port used by web traffic and blends in with it.

The distinction candidates commonly blur is between protecting the channel and protecting the data. DoH gives confidentiality and integrity for the hop between client and resolver only. It does not prove that the resolver’s answer is genuine: that is the job of DNSSEC, which signs the records themselves and encrypts nothing. DoH also has a governance cost. A browser or a piece of malware using an external DoH resolver bypasses the enterprise DNS servers, their filtering and their logs, which weakens egress monitoring and can hide command-and-control lookups.

Exam relevance: a scenario is likely to turn on which property is needed. Hiding lookups from eavesdroppers points to DoH; proving that an answer was not forged points to DNSSEC. Where lost visibility is the concern, the likely response is directing endpoints to approved internal resolvers.