Changing your DNS makes browsing safer, but it won’t hide your history from the people who matter most

Changing your DNS makes browsing safer, but it won’t hide your history from the people who matter most

Published Sep 29, 2026, 8:00 PM EDT Umair Khurshid is a technology writer and developer with a strong focus on Linux, FreeBSD, cloud infrastructure, and automation. Before focusing on writing, Umair worked as a developer and DevOps engineer building and automating cloud-native systems. Changing your DNS server is one of those simple networking tweaks that can make browsing safer, but DNS privacy is easy to misunderstand. Changing your DNS provider does not make your browsing history invisible. Your ISP, employer, school, or network administrator may still have other ways to determine which services you are connecting to. DNS only tells your computer where to connect Changing DNS changes the resolver, not the connection itself The basic job of DNS is to translate a domain such as example.com into an IP address that your computer can connect to. When you use your ISP’s DNS server, the ISP handles those lookups. When you configure your device to use Cloudflare or Google, those companies handle them instead. That can be useful for privacy. If you use DNS over HTTPS (DoH) or DNS over TLS (DoT), the query between your device and the resolver is encrypted. Someone monitoring the local network can no longer simply read the DNS packets and see every domain being requested, but DNS does not carry the rest of your web traffic. After resolving example.com, your computer still needs to connect to the resulting IP address. Those packets still have to travel through your ISP if you are using an ordinary internet connection. Changing the DNS resolver does not encrypt those packets, hide their destination IP addresses, or turn your connection into a VPN. Your ISP can still see plenty HTTPS protects content, not necessarily your destination Even when your DNS queries are encrypted, your ISP still sits between your network and the rest of the internet. For a normal HTTPS connection, your ISP cannot simply read the contents of the pages you visit. HTTPS encrypts the actual application data between your browser and the website. However, your ISP can still see the IP addresses your connection communicates with. That can sometimes reveal the service you are using. An IP address shared by thousands of websites may not tell the ISP exactly which site you visited, while an address dedicated to a particular service can provide a much stronger clue. TLS has historically provided another source of information. With traditional TLS connections, the browser can include the hostname it wants to connect to in the ClientHello message through Server Name Indication, or SNI. The contents of the HTTPS session remain encrypted, but the hostname in SNI has historically been visible to someone observing the connection. This is where Encrypted Client Hello, or ECH, comes in. ECH is designed to encrypt sensitive parts of the TLS ClientHello, including information that would otherwise expose the requested hostname through SNI. ECH is an important development, but it is not a universal privacy switch. Its effectiveness depends on support from the browser, server, and surrounding infrastructure. Traffic analysis can provide another source of information. Even when the contents of a connection are encrypted, the size, timing, and direction of packets can reveal characteristics about the connection. An ISP does not necessarily need to read your HTTP requests to know that your device is communicating with a particular service. So encrypted DNS solves a real problem, but it does not make your ISP blind to your internet activity. Changing DNS means trusting someone else The new resolver can still see your queries Another easy-to-miss consequence of switching DNS providers is that queries don't disappear. If you stop using your ISP’s resolver and start using Cloudflare, Cloudflare becomes the resolver receiving those requests. If you use Google Public DNS, Google receives them instead. DoH and DoT protect the queries while they travel between your device and the resolver. The resolver still needs to see the request to answer it. That makes the provider’s privacy policy, logging practices, and jurisdiction relevant. A DNS provider operates under the laws applicable to its business and infrastructure, which can affect how it responds to legal requests for information. This does not mean every public DNS provider keeps an extensive record of everything you do. Their policies differ, and some DNS providers are more privacy-oriented. So who can see what? Privacy depends on who you are trying to hide from If you are using Wi-Fi at a coffee shop and have encrypted DNS and HTTPS enabled, the person running the network cannot simply open a log and read the pages you visited. They can still see that your device is communicating with particular IP addresses, but they cannot normally read the contents of your HTTPS session, such as the pages you viewed. Your ISP has considerably more visibility because it carries your internet traffic. Depending on the connection, the ISP may also see SNI and can analyze connection timing and traffic patterns. In practical terms, changing DNS does not stop your ISP from building a useful picture of your internet activity. A company or school controlling the network can have even more visibility. It can block outside DNS, log connections, or use managed-device software and TLS inspection to inspect traffic. In that environment, changing the DNS setting on your laptop may accomplish nothing because the network can override or ignore it. A VPN changes the situation because your ISP sees an encrypted connection to the VPN rather than the individual destinations inside it, but now the VPN provider is the party you have to trust. It can potentially see the destinations your traffic reaches, and your DNS configuration can still leak information outside the tunnel if the VPN is misconfigured. DNS privacy has limits There is still a practical security benefit to choosing a different resolver. Some services can block known malicious domains, which can prevent your device from connecting to certain malware or phishing sites. Just think of it as choosing a different service to handle DNS rather than as a way to disappear from your ISP’s view. If your goal is to hide where you go online from the network carrying your traffic, you need to protect more than DNS.

Original Source

Read the full article at Howtogeek →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.