Secure DNS, often called DNS over HTTPS in browser settings, encrypts the lookup your browser makes before it opens a website. It can stop many people on the same network from reading or changing that domain lookup. It does not make you anonymous, hide every site connection, fix unsafe websites, or replace a VPN.
What Secure DNS actually does
Before a browser can load a site, it has to turn a domain name into a server address. That lookup is DNS. Traditional DNS can expose the domain being requested while it travels between your device and a resolver. Secure DNS changes that transport path by sending the lookup through an encrypted channel, commonly DNS over HTTPS.
That protection is useful on shared Wi-Fi, school networks, hotel networks, public hotspots, and home networks where another device or router may be able to observe ordinary DNS requests. It protects the lookup channel, not everything that happens after the lookup.
What Secure DNS protects
- Basic DNS lookup visibility: a local observer has a harder time reading the exact domain lookup in transit.
- Simple DNS tampering: encryption makes it harder for a network path to quietly change a DNS answer before it reaches the browser.
- Some public Wi-Fi snooping: the network may still see connections, but the raw DNS request is less exposed.
- Resolver choice: a custom provider lets you decide which DNS service receives those lookups.
What Secure DNS does not hide
Secure DNS is narrow protection. The website can still see your visit. Your internet provider or network may still see connection metadata. A signed-in account, cookies, browser storage, fingerprinting, extensions, and app telemetry can still connect activity to you.
- It is not a VPN and does not reroute all traffic through another exit.
- It does not turn an unsafe site into a safe one.
- It does not replace HTTPS for the page connection.
- It does not erase tracking by accounts, cookies, ads, apps, or browser extensions.
Chrome Secure DNS settings
Chrome describes Secure DNS as a way to encrypt information during the site lookup process. Chrome turns Secure DNS on by default in automatic mode. If automatic mode has trouble, Chrome can fall back to unencrypted DNS. If you choose a custom provider, Chrome says it will not default to unencrypted mode for that provider, so a provider outage may show an error instead.
On Chrome, look under privacy and security settings for Use secure DNS. Automatic mode is usually the safest first choice for everyday users because it keeps compatibility with more networks. A custom provider is useful when you intentionally want that resolver, but it also means that provider receives the DNS questions.
Firefox DNS over HTTPS settings
Firefox calls the feature DNS over HTTPS and offers protection levels. Default protection can use local providers and may turn DoH off when a VPN, parental control, enterprise policy, or network signal tells Firefox not to use it. Increased, Max, and Custom protection are stricter options, but stricter settings can also break some networks or show warnings when the resolver cannot answer.
If Firefox shows DoH as not active, check whether the network, VPN, parental controls, enterprise device policy, or chosen provider is causing the fallback. That status is a clue, not a reason to turn off every privacy setting.
Automatic mode or custom provider?
Use automatic mode if you want a practical privacy upgrade without making network troubleshooting harder. Use a custom provider only when you trust that provider more than the default path and understand its logging, filtering, and reliability behavior.
A custom DNS provider is not automatically more private. It changes who handles the lookup. Before choosing one, read the provider policy and decide whether you want filtering, malware blocking, family controls, or the least possible logging.
When Secure DNS can cause problems
Secure DNS can get in the way on networks that depend on their own DNS behavior. Captive portals, company devices, school devices, parental-control setups, filtered networks, and some hotel Wi-Fi logins may expect the browser to use the local resolver first.
If only one network breaks, do not panic. Try the network sign-in page, confirm the device clock, test another browser, switch from a custom provider back to automatic mode, and then retry the site. If the device is managed, the setting may be locked by policy.
Best setup for most people
- Keep Chrome, Firefox, and the operating system updated.
- Turn on Secure DNS or DNS over HTTPS in the browser privacy settings.
- Start with automatic or default protection.
- Use a custom provider only after reading its privacy and reliability policy.
- Turn on HTTPS-only or always-use-secure-connections mode separately.
- Review extension permissions, cookies, and account privacy because Secure DNS does not control those.
Common mistakes
Mistake one: treating Secure DNS like a VPN. It does not hide your IP address from websites and does not cover every app on your device.
Mistake two: assuming a custom provider means total privacy. A custom provider may be better for your needs, but it still receives DNS queries.
Mistake three: turning it off forever after one Wi-Fi problem. If a hotel or school network breaks, switch temporarily, then restore the setting when you leave that network.
Mistake four: ignoring the rest of the browser. Secure DNS does not replace HTTPS-only mode, cookie partitioning, or extension permission checks.
FAQ
Is Secure DNS the same as DNS over HTTPS?
In Chrome, Secure DNS is the browser label for encrypted DNS lookup behavior. Firefox uses the clearer label DNS over HTTPS. The exact controls differ by browser.
Should I turn Secure DNS on?
For most personal devices, yes, start with automatic or default protection. It gives a useful privacy upgrade with fewer broken-network surprises than a strict custom setup.
Does Secure DNS hide browsing from my internet provider?
It can hide ordinary DNS lookup contents from parts of the network path, but it does not hide every connection detail or make websites unable to identify you.
Why does a site stop loading after I choose a DNS provider?
The provider may be unreachable, blocked by the network, slow to answer, or returning no address for that domain. Switch back to automatic/default mode and test again before changing unrelated settings.
Related browser privacy checks
Secure DNS protects one layer. For the broader setup, compare HTTPS-only mode, cookie partitioning, browser extension permissions, and the Browser & Privacy desk.



