What encrypted DNS actually protects
DoH and DoT encrypt exactly one thing: the step where your machine turns a domain name into an IP address. Without it, that lookup travels in plain text and your ISP — or anyone on the same network — can log every domain you visit, regardless of whether the site itself uses HTTPS. With it, those queries go to a resolver of your choice over an encrypted connection, and the ISP's DNS log goes dark.
What it does not do is hide your traffic. The ISP still sees which IP addresses you connect to, the SNI field still broadcasts the hostname of every HTTPS site you open, and websites still see your real IP address and fingerprint. Encrypted DNS closes one leak in a pipe with several. It is worth enabling, and it is nowhere near a VPN.
What a VPN does that DNS never will
A VPN moves the whole pipe: every connection, DNS included, goes through an encrypted tunnel to the provider's server, and the sites you visit see that server's IP instead of yours. That is what makes it useful on public Wi-Fi, for hiding your location, and for reaching networks you would rather not expose your home IP to. The trade is trust: the VPN provider sees everything your ISP used to see, so you are not eliminating the observer — you are choosing a different one. Neither tool subsumes the other:
- With DoH on, your ISP still sees destination IPs and SNI hostnames — just not the DNS lookups
- Your DNS provider sees every domain you resolve, so pick one whose logging policy you actually trust
- Websites see your real IP with encrypted DNS; with a VPN they see the VPN server's IP
- A VPN provider sees all your traffic and timing — it replaces your ISP as the observer
- On public Wi-Fi, only a VPN protects against local snooping of the connection itself
- The two stack: DoH inside a VPN tunnel removes the VPN's own plaintext-DNS side channel
Which one you actually need
For most people at home, encrypted DNS is the cheap, free win: Windows 11 lets you set DoH per adapter in Settings > Network & internet, and browsers can do it independently. A VPN earns its subscription on hostile networks, when your IP itself is the thing you need to hide, or when the network you are on blocks or poisons DNS. If your threat model is that the ISP should not sell your browsing log, start with DoH and honest expectations. If it is that nobody on this network should know what you do, that is a VPN's job — and often both at once.
Questions and Answers
Is DNS over HTTPS as good as a VPN?
No. DoH only hides domain lookups from your ISP; websites still see your real IP and your ISP still sees which IPs you connect to. A VPN hides your IP and encrypts all traffic.
Does a VPN also encrypt DNS requests?
Usually yes — most VPNs route DNS through the tunnel. Exceptions leak through the system resolver, which is why running DoH alongside a VPN is a sensible belt-and-braces setup.
Know what is included before you buy.
The one-time 30-minute trial covers core tools. PRO-labelled features stay locked until a paid license is activated.
Read next
Write to us: [email protected]