What is DNS over HTTPS?
Before your phone connects to a site, it asks a DNS server for the site's address (see what is DNS). DNS over HTTPS, or DoH, sends that question inside an ordinary HTTPS connection, the same encrypted channel that protects online banking pages. It is defined in RFC 8484: the DNS question is carried in an HTTPS request to an address such as https://example-resolver.test/dns-query.
The result is the same answer as before. What changes is that the path between your phone and the DNS server is encrypted.
What is the difference between plain DNS, DoT and DoH?
| Plain DNS | DNS over TLS (DoT) | DNS over HTTPS (DoH) | |
|---|---|---|---|
| Encrypted | No | Yes | Yes |
| Port | 53 | 853 | 443 (same as web) |
| Shape on the network | Readable DNS packets | TLS connection on a dedicated port | Looks like normal HTTPS |
| Where you meet it | Default on most networks | Android Private DNS | Browsers, apps, EZOBLOCKER |
The dedicated DoT port is sometimes blocked on corporate, hotel and some mobile networks. DoH uses the same port as web pages, so it is rarely blocked without breaking the web with it.
Why does encrypted DNS matter?
Plain DNS is readable by anyone on the path: the Wi-Fi owner, the network operator or someone sharing a public hotspot. The list of names your phone asks for says a lot about what you do. Plain DNS answers can also be changed on the way, for example to send you to a wrong address.
Encryption addresses both: the questions cannot be read on the way, and the answer is protected against tampering in transit. It does not make the DNS server itself blind, so it matters who the server is and what it keeps.
How does EZOBLOCKER use DoH?
EZOBLOCKER runs a small local tunnel on your phone. The tunnel catches the DNS lookups and forwards them, encrypted with DoH, to EZOBLOCKER's own servers. The servers answer normally for sites you are allowed to open and give a blocked answer for the categories you switched on, for example ads, trackers, gambling or adult sites. The filtering happens on the servers, before anything loads.
What is and is not sent:
- The phone sends only DNS lookups to the servers. Your pages, messages and videos do not go through them.
- The servers keep no record of the sites you visit. Their only knowledge of you is an anonymous device ID, your chosen categories, the addresses in your own list and your subscription status.
- If the servers cannot be reached, site names may briefly go to well-known public DNS services such as Cloudflare or Quad9, so your internet does not cut out.
This is why the system shows a VPN icon: the phone's VPN feature is the only way an app can catch DNS lookups. It is not routing your traffic through a VPN server. See the privacy page for the details.
Can I choose a different DoH provider in EZOBLOCKER?
Yes. Under Advanced > DNS provider you can pick a public provider or type your own DoH address, which must start with https://. In that mode your lookups go to that provider and EZOBLOCKER's categories do not apply. A table of providers and their DoH addresses is in the family DNS servers guide.
How is this different from Android's Private DNS?
Android's Private DNS uses DoT with a hostname. If a hostname is typed there, it takes priority over EZOBLOCKER's filter, so it should be Off or Automatic while you use the app. The steps are in how to set Private DNS on Android.
To confirm your lookups pass through the filter, open the protection check. The DNS changer page gives the overall picture.