Private DNS Explained: Encrypt Your DNS Lookups
Private DNS encrypts the lookups your device makes before visiting a site. Learn what it does, its limits, and how to turn it on for your phone or computer.

Every time you open a website, your device first asks a server where that site lives. That lookup is usually sent in plain text, so anyone along the way can see which domains you are asking about. Private DNS fixes part of that problem. This guide explains what it is, what it protects, where it falls short and how to switch it on.
What DNS is
DNS stands for Domain Name System. It works like a phone book for the internet. You type a name such as a website address, and DNS translates it into the numeric IP address computers use to find each other. By default your device asks the DNS server supplied by your internet provider or by the router you are connected to.
Traditional DNS requests are not encrypted. Your provider, the owner of a public Wi-Fi network or anyone else who can watch the connection can see a list of the domains you look up, even if the pages themselves use HTTPS. They cannot see the specific page or the content, but the list of domains can still say a lot about your habits.
What private DNS means
Private DNS is the common name for encrypted DNS. Instead of sending lookups in plain text, your device wraps them in encryption before sending them to a DNS server that supports it. There are two main technologies:
- DNS over TLS (DoT) uses a dedicated connection for encrypted DNS. Android's "Private DNS" setting uses this method.
- DNS over HTTPS (DoH) sends DNS requests inside normal HTTPS traffic, which makes them look like ordinary web traffic. Browsers and some operating systems support it.
Both achieve the same goal: nobody between you and the DNS server can read or tamper with your lookups.
What private DNS protects against
- Snooping on local networks. Someone on the same public Wi-Fi cannot easily watch which domains you look up.
- Tampering. Encrypted DNS makes it harder for a network to quietly redirect your lookups to a wrong address.
- Casual logging by your internet provider. Your provider can no longer read your DNS requests directly.
What private DNS does not do
- It does not hide your IP address. Websites still see where you connect from.
- It does not hide which servers you connect to. Your provider can still see the destination IP addresses, which can reveal a lot even without DNS.
- It does not make you anonymous. The company running your chosen DNS server can see your lookups, so you are moving trust, not removing it.
- It is not a replacement for a VPN. A VPN encrypts all your traffic, while private DNS covers only name lookups.
Private DNS vs VPN
| Feature | Private DNS | VPN |
|---|---|---|
| Encrypts DNS lookups | Yes | Yes, usually through the VPN's own resolver |
| Encrypts all other traffic | No | Yes |
| Hides your IP from websites | No | Yes |
| Speed impact | Usually very small | Small to moderate |
| Setup effort | A setting or two | Install and sign in to an app |
Choosing a DNS provider
Several organizations run public encrypted DNS services, and some also offer extra features such as blocking known malicious domains or filtering adult content. When comparing options, look for:
- Support for DNS over TLS or DNS over HTTPS.
- A published privacy policy that states what is logged and for how long.
- Good reliability and fast response times from your location.
- Optional filtering, if you want protection against malware or unwanted content.
You will need the provider's hostname for the setup, which is listed on its own website. Always copy it from the official source.
How to turn it on
On Android
- Open Settings and go to Network and internet (the exact name varies by phone).
- Choose Private DNS.
- Select "Private DNS provider hostname" and enter the hostname of your chosen provider.
- Save. Android will check the connection and use encrypted lookups on all networks.
Android also offers an Automatic mode that uses encrypted DNS when your network supports it.
On iPhone and Mac
Apple devices support encrypted DNS through a configuration profile or a provider's app. Download the profile only from the provider's official website, then enable it in Settings. You can remove it later from the profiles section if you change your mind.
On Windows 11
- Open Settings, then Network and internet, and select your Wi-Fi or Ethernet connection.
- Choose to edit the DNS server assignment and switch it to manual.
- Enter the provider's IP addresses for DNS.
- Set the DNS encryption option to encrypted only, or encrypted preferred, then save.
In your browser
Most major browsers have a secure DNS or DNS over HTTPS option in their privacy or security settings. You can pick a provider from the list or enter a custom one. This only affects that browser, not other apps.
On your router
Some routers support encrypted DNS, which protects every device on your home network at once. Look in the router's DNS settings or firmware documentation. If it is not supported, set it up on each device instead.
Things to watch out for
- Filtering conflicts. Parental controls, workplace tools or school networks may rely on their own DNS. Changing it can break them or violate a policy.
- Captive portals. Hotel and airport sign-in pages can fail with some encrypted settings. Switch to Automatic or off briefly to sign in.
- Wrong hostnames. If you mistype it, your connection may stop working. Check the spelling and try again.
- Fake instructions. Only follow setup steps from official sources, since a malicious DNS server can send you to fake sites.
Is it worth using?
For most people, yes. It is free, takes a few minutes, has little effect on speed and removes a leak that many people do not know exists. Just keep your expectations realistic. It improves privacy on the local network and from your internet provider's DNS, but it is one small layer, not a full privacy solution.
Final thoughts
Private DNS encrypts the address lookups your device makes before it connects to a site. That makes it harder for others on your network to watch or interfere with them, and it costs you almost nothing. Combine it with HTTPS, strong passwords, two-factor authentication and, where it makes sense, a VPN, and you will cover the most common privacy gaps in everyday browsing.


