DNS over HTTPS (DoH) vs DNS over TLS (DoT): Router Setup Guide
Both DNS over TLS (DoT, RFC 7858 on TCP port 853) and DNS over HTTPS (DoH, RFC 8484 on TCP/UDP port 443) encrypt your home's DNS lookups so your ISP cannot log visited domains or hijack queries. Configure DoT natively on ASUSWRT, Synology SRM, or pfSense/OPNsense Unbound, or configure DoH on MikroTik RouterOS, OpenWrt, UniFi OS, and AdGuard Home.
- Stops ISP Port 53 Snooping & Hijacking: Standard UDP/TCP Port
53DNS travels in plaintext, allowing ISPs to log every domain you resolve or transparently redirect1.1.1.1:53to their own DNS servers. - DoT (`TCP 853` — RFC 7858): Runs binary DNS directly inside a dedicated TLS 1.3 tunnel on port
853; lower protocol overhead and preferred for router/firewall forwarders like Unbound and Stubby. - DoH (`HTTPS 443` — RFC 8484): Wraps DNS queries inside standard HTTP/2 or HTTP/3 (`QUIC`) traffic on port
443, making DNS queries indistinguishable from normal web browsing on restrictive networks. - Block Client Bypass (`use-application-dns.net`): If you run encrypted DNS on your router, block WAN outbound ports
53and853so smart TVs with hardcoded Google DNS (`8.8.8.8`) can't bypass your router.
Why Changing Your Router DNS to 1.1.1.1 or 9.9.9.9 Is Not Enough
Many privacy-conscious users log into their router's WAN settings, change the primary DNS server from their ISP's default to Cloudflare (`1.1.1.1`) or Quad9 (`9.9.9.9`), and assume their browsing history is private. Unfortunately, standard DNS over UDP/TCP Port 53 is completely unencrypted plaintext. Even when you query `1.1.1.1:53`, every router hop inside your ISP's network can read the exact domain name in the packet payload.
Worse, several residential ISPs and cellular carriers use transparent DNS proxies (Destination NAT on Port 53): they intercept any outbound packet destined for port `53`—regardless of whether it is addressed to `1.1.1.1` or `8.8.8.8`—and silently answer it from the ISP's own resolver to monetize analytics or inject NXDOMAIN search pages. Encrypting DNS at the router with DNS over TLS (DoT) or DNS over HTTPS (DoH) verifies the upstream server's cryptographic X.509 certificate, making ISP interception impossible.
DoT (Port 853, RFC 7858) vs DoH (Port 443, RFC 8484): Technical Differences
While both protocols use **TLS 1.3** encryption to protect DNS queries and validate server certificates, they operate at different layers of the stack:
- DNS over TLS (DoT — IETF RFC 7858): Establishes a dedicated TLS session over TCP Port 853 and sends raw RFC 1035 wire-format DNS messages prefaced by a 2-byte length field. Because it skips the HTTP layer entirely, DoT has slightly smaller packet headers and allows network administrators to clearly identify, prioritize (QoS), or firewall DNS traffic on port `853`.
- DNS over HTTPS (DoH — IETF RFC 8484): Encapsulates DNS wire-format queries inside standard HTTPS GET or POST requests (`application/dns-message`) over Port 443 using HTTP/2 multiplexing or HTTP/3 (`QUIC` over UDP 443). Because port `443` carries all web traffic, an ISP or hotel firewall cannot block DoH without breaking the entire internet.
- DNS over QUIC (DoQ — RFC 9250): A newer standard supported by AdGuard and NextDNS over UDP Port 853 that eliminates TCP head-of-line blocking and completes 0-RTT/1-RTT handshakes faster than TCP DoT.
Step-by-Step Router Setup: ASUSWRT, UniFi, MikroTik, OpenWrt & pfSense
You only need to configure whichever encrypted protocol your router firmware supports natively—all devices on your LAN will send fast local Port 53 queries to your router (`192.168.1.1`), and the router encrypts them upstream:
- ASUS Routers (ASUSWRT / Merlin — Native DoT): Navigate to WAN > Internet Connection > WAN DNS Setting. Set DNS Privacy Protocol to
DNS-over-TLS (DoT), chooseStrictmode (validates TLS certificate), and select presets for Cloudflare (`1.1.1.1` / `one.one.one.one`) or Quad9 (`9.9.9.9` / `dns.quad9.net`). - Ubiquiti UniFi (UniFi Network 8.x+ — Native DoH): Go to Settings > Security > Protection > DNS Shield, select Auto or Manual, and pick
Cloudflare-DNS,Quad9, or enter a custom NextDNS DoH Stamp. - MikroTik RouterOS v7 (Native DoH): Download the CA root store (`https://curl.se/ca/cacert.pem`), import it via `/certificate import file-name=cacert.pem`, and run `/ip dns set use-doh-server=https://cloudflare-dns.com/dns-query verify-doh-cert=yes servers=""`.
- pfSense / OPNsense (Unbound DoT): Go to Services > Unbound DNS > DNS over TLS, add `1.1.1.1@853` with Verify CN `one.one.one.one`, and enable Forwarding Mode.
Preventing Smart TV DNS Leaks & Verifying Encrypted DNS
Enabling DoH or DoT on your router only protects devices that actually use your router (`192.168.1.1`) as their DNS server. Smart TVs (LG webOS, Samsung Tizen, Google TV/Chromecast), Roku boxes, and IoT cameras frequently ignore DHCP DNS assignments and send plaintext queries directly to hardcoded 8.8.8.8:53.
To enforce 100% network-wide encryption: (1) Create a NAT Port Redirect (DNAT) Rule: Intercept any LAN packet targeting `!192.168.1.1` on UDP/TCP Port 53 and redirect it to `192.168.1.1:53`. (2) Block Outbound Port 853: Drop outbound WAN traffic from LAN clients to `TCP/UDP 853` so devices cannot use rogue external DoT resolvers. (3) Disable Browser Third-Party DoH Override (Optional): If you use NextDNS, Pi-hole, or AdGuard Home for LAN ad-blocking, return `NXDOMAIN` for `use-application-dns.net` so Firefox and Chrome use your router's encrypted DNS instead of bypassing your local ad blocker. Finally, visit https://1.1.1.1/help or https://on.quad9.net to confirm Using DNS over TLS (DoT) / HTTPS (DoH) = Yes.
Public Encrypted DNS Resolvers: Exact DoT & DoH Router Configuration Reference
| DNS Provider & Policy | IPv4 / IPv6 Bootstrap IPs | DoT TLS Hostname (Port 853) | DoH Endpoint URL (Port 443) |
|---|---|---|---|
| Cloudflare (Standard Fast) | 1.1.1.1, 1.0.0.1 / 2606:4700:4700::1111 | one.one.one.one (or 1dot1dot1dot1.cloudflare-dns.com) | https://cloudflare-dns.com/dns-query |
| Cloudflare Malware Block | 1.1.1.2, 1.0.0.2 / 2606:4700:4700::1112 | security.cloudflare-dns.com | https://security.cloudflare-dns.com/dns-query |
| Quad9 (Malware + DNSSEC) | 9.9.9.9, 149.112.112.112 / 2620:fe::fe | dns.quad9.net | https://dns.quad9.net/dns-query |
| NextDNS (Custom Ad-Block) | 45.90.28.0, 45.90.30.0 | https://dns.nextdns.io/ | |
| AdGuard DNS (Ad + Tracker) | 94.140.14.14, 94.140.15.15 | dns.adguard-dns.com | https://dns.adguard-dns.com/dns-query |
| Mullvad DNS (No-Log Privacy) | 194.242.2.2 / 2a07:e340::2 | dns.mullvad.net | https://dns.mullvad.net/dns-query |
Router DoH / DoT Setup & Leak-Prevention Checklist
- Enable DNS over TLS (DoT on Port 853) or DNS over HTTPS (DoH on Port 443) in your router WAN/Security settings using Strict Certificate Verification.
- Enter both the numeric Bootstrap IP (e.g., 1.1.1.1 or 9.9.9.9) and the exact TLS Subject Alternative Name (one.one.one.one or dns.quad9.net).
- Ensure your router's DHCP server distributes only the router's own LAN IP (e.g., 192.168.1.1) as the DNS server to client devices.
- Create a firewall NAT redirect (DNAT) rule forcing any rogue client UDP/TCP Port 53 traffic (such as hardcoded 8.8.8.8 on smart TVs) back to 192.168.1.1:53.
- Enable DNSSEC validation alongside DoT/DoH so DNS answers are verified for both transport privacy and cryptographic origin authenticity.
- Test your configuration at https://1.1.1.1/help (for Cloudflare) or https://on.quad9.net (for Quad9) to confirm encrypted transport is active.
Frequently Asked Questions
Which is faster on a home router: DNS over TLS (DoT) or DNS over HTTPS (DoH)?
Both reuse persistent TLS 1.3 connections (keep-alive sessions), so after the initial 25–40 ms handshake, subsequent cached and uncached queries take the exact same time as standard DNS (1 to 15 ms). DoT has slightly smaller packet overhead than HTTP/2 DoH, while DoH over HTTP/3 (QUIC) recovers faster on lossy wireless links.
Does DNS over HTTPS or DNS over TLS hide the websites I visit from my ISP completely?
DoH and DoT prevent your ISP from seeing your DNS lookups or hijacking domain resolutions, but when your browser subsequently connects to the web server on TCP port 443, the TLS 1.3 handshake still often transmits the domain name in the Server Name Indication (SNI) field unless the website supports Encrypted Client Hello (ECH). However, encrypted DNS stops bulk DNS logging and transparent DNS hijacking.
Should I configure DoH in my web browser AND on my router at the same time?
If you do not run a local DNS blocker (like Pi-hole or AdGuard Home), leaving browser DoH on is fine. However, if you run Pi-hole, AdGuard Home, or local LAN hostnames (like nas.home.arpa) on your router, disable browser-level DoH in Chrome/Firefox so browsers query your local router first, and let your router or Pi-hole forward queries upstream over DoT/DoH.
What is the difference between Strict Mode and Opportunistic Mode in router DoT settings?
Strict Mode verifies the upstream DNS server's TLS certificate against its hostname (e.g., dns.quad9.net) and refuses to fall back to plaintext Port 53 if an attacker intercepts port 853. Opportunistic Mode accepts any self-signed certificate and silently downgrades to unencrypted Port 53 if port 853 is blocked—always select Strict Mode.
Related Home Network Security & Engineering Guides
- How to Secure Home WiFi (12-Step Hardening Guide) — Harden your home WiFi network in 12 practical steps. Enable WPA3-SAE encryption, disable WPS and UPnP, isolate IoT VLANs, and lock down router admin access.
- Router Default Password Safety & Credential Hardening — Eliminate default router credentials before botnets hijack your gateway. Separate admin passwords from WiFi WPA3 keys and enforce LAN HTTPS management.
- Router Firewall Settings Explained (SPI, NAT & Rules) — Master your router firewall settings. Configure Stateful Packet Inspection (SPI), disable broken SIP ALG for VoIP, block WAN pings, and secure IPv6 rules.
- How to Secure Smart Home & IoT Devices on Your Network — Isolate untrusted smart TVs, cameras, and plugs on a dedicated IoT WiFi VLAN. Enable mDNS UDP 5353 reflection for AirPlay and block risky WAN callbacks.