DNS over HTTPS and DNS over TLS serve to transport encrypted queries between the client and the resolver. Knowing which one is used is important during diagnosis.

Basic approach

DoH transports DNS messages over HTTPS; DoT, on the other hand, uses TLS-based DNS connection. If the browser chooses its own resolver, browser behavior may differ depending on the operating system DNS setting. Encrypted transport does not prevent the selected resolver from processing queries.

Application steps

  1. Examine the secure DNS option in the browser and the operating system DNS setting separately.
  2. Verify how split DNS policy is implemented for corporate internal domains.
  3. When comparing the same domain via browser and command line, record which resolver they use.

Practical example

If the on-premises portal is resolved with nslookup but cannot be found in the browser, the browser may be going to an external DoH provider. In this case, it would be more sustainable to correct the institution's DNS policy rather than adding the address to the hosts file.

Interpret the result correctly

The use of DoH does not anonymize all internet traffic. DNSSEC is also a separate authentication layer. Don't make the choice based on speed alone; The operation of internal names, management policy, and resolver trust should be evaluated together.

Source and follow-up reading

Protocol or command details: RFC 8484. The steps and example scenario are IPScans editorial narrative.