Every DNS query your Windows 11 machine sends — every domain lookup for every site, app, and service — goes out as plaintext by default. Your ISP, your router, and anyone on the same network can read exactly where you are browsing. DNS over HTTPS (DoH) fixes that by wrapping those queries in encrypted HTTPS traffic, making them indistinguishable from ordinary web requests. Windows 11 has native DoH support built in, but it is off by default and buried under two layers of settings. Here is how to turn it on properly.
What DNS over HTTPS Actually Does
Standard DNS uses UDP port 53 — no encryption, no authentication. DoH sends the same queries over HTTPS (port 443), encrypted with TLS. The DNS resolver still knows what you are looking for, but the path between your PC and the resolver is opaque to everyone in between: your ISP, your workplace network administrator, and malicious actors on public Wi-Fi.
DoH does not make you anonymous. The resolver you choose still sees all your queries. If you use your ISP's resolver with DoH enabled, your ISP still logs everything — just at their server rather than in transit. Choose a privacy-respecting resolver such as Cloudflare, Google Public DNS, Quad9, or NextDNS to get the actual privacy benefit.
Which DNS Servers Support DoH on Windows 11
Windows 11 uses a hard-coded allowlist of resolvers it recognizes automatically. Enter an IP from this list and Windows activates DoH without requiring you to manually supply a URL. The recognized resolvers as of 2026 are:
- Cloudflare: 1.1.1.1, 1.0.0.1, 2606:4700:4700::1111, 2606:4700:4700::1001
- Google: 8.8.8.8, 8.8.4.4, 2001:4860:4860::8888, 2001:4860:4860::8844
- Quad9: 9.9.9.9, 149.112.112.112, 2620:fe::fe, 2620:fe::9
Custom resolvers like NextDNS or AdGuard DNS are not on this allowlist. To use them with system-level DoH, you must register them manually via the registry method in Method 4 below.
Method 1: Windows 11 Settings
This is the right path for most users. It configures DoH for a specific network adapter through the built-in Settings GUI and requires no admin tools or command-line access.
- Open Settings and navigate to Network and internet.
- Click your active connection — either Wi-Fi (then click your network name) or Ethernet.
- Scroll down to DNS server assignment and click Edit.
- Change the dropdown from Automatic (DHCP) to Manual.
- Enable the IPv4 toggle.
- In Preferred DNS, enter your chosen resolver: 1.1.1.1 for Cloudflare, 8.8.8.8 for Google, or 9.9.9.9 for Quad9.
- Under DNS over HTTPS, change the dropdown from Off to On (automatic template).
- In Alternate DNS, enter the secondary IP (for Cloudflare: 1.0.0.1) and set its DoH dropdown to On (automatic template) as well.
- Enable the IPv6 toggle if your network supports IPv6. For Cloudflare enter 2606:4700:4700::1111 as preferred and 2606:4700:4700::1001 as alternate, both set to DoH on.
- Click Save.
The On (automatic template) option means Windows already knows the correct DoH endpoint URL for that resolver. If you see On (manual template), Windows does not recognize that IP and you would need to supply the HTTPS URL yourself — this only happens with custom or unlisted resolvers.
Method 2: Network Adapter Properties
The legacy Control Panel interface at ncpa.cpl lets you set DNS server IPs but does not expose the DoH toggle. Use it as a supplemental step if you prefer the older interface, but you still need to apply the DoH setting through Windows 11 Settings afterward.
- Press Win + R, type ncpa.cpl, and press Enter.
- Right-click your active adapter and choose Properties.
- Select Internet Protocol Version 4 (TCP/IPv4) then click Properties.
- Choose Use the following DNS server addresses and enter your preferred and alternate IPs.
- Click OK to close both dialogs.
After this, open Settings then Network and internet then your connection then DNS server assignment then Edit and confirm the DoH dropdown shows On (automatic template). This extra step is required — the Control Panel path predates DoH support and does not activate it on its own.
Method 3: Group Policy for Enterprise and Pro
On Windows 11 Pro, Enterprise, and Education editions, Group Policy lets you enforce a DoH mode across managed machines and prevents users from disabling it through Settings.
- Press Win + R, type gpedit.msc, and press Enter.
- Navigate to Computer Configuration then Administrative Templates then Network then DNS Client.
- Double-click Configure DNS over HTTPS (DoH) name resolution.
- Set it to Enabled and select a mode:
- Require DoH — DNS queries fail entirely if DoH is unavailable. Maximum security, but will break captive portals and some split-tunnel VPNs.
- Prefer DoH — Falls back to plaintext DNS if DoH fails. Recommended for most managed deployments.
- Prohibit DoH — Disables DoH entirely. Used in environments requiring DNS traffic inspection.
- Also configure the DNS Servers policy under the same DNS Client node to point to a DoH-capable resolver IP.
- Click OK, then open an elevated command prompt and run gpupdate /force to apply immediately without waiting for the next policy refresh cycle.
Group Policy overrides the per-adapter Settings configuration. Once applied, the DoH toggle in Settings will be greyed out for standard users on that machine.
Method 4: Registry for Custom DoH Servers
If you want to use a resolver that is not on Windows built-in allowlist — NextDNS, AdGuard DNS, a self-hosted Unbound instance, or a corporate DoH endpoint — you must register it in the registry before Method 1 will offer the automatic template option for that IP.
Open PowerShell as Administrator and run the following, replacing the IP and URL with your resolver values:
Restart the DNS Client service to load the new registry entry:
Return to Method 1 and enter that IP as your DNS server. Windows will now recognize it and present the automatic template option in the DoH dropdown.
Verifying DoH Is Actually Working
Configuring DoH and confirming it is active are two different things. Use one of these approaches to verify the setup is working end to end.
Cloudflare Help Page
If you chose Cloudflare (1.1.1.1) as your resolver, browse to https://1.1.1.1/help in any browser. When system-level DoH is routing through Cloudflare, the page reports Using DNS over HTTPS (DoH): Yes. If it shows No, your queries are still leaving in plaintext or routing through a different resolver.
PowerShell Verification
Check which DNS servers Windows is actively using for each adapter:
Test that the resolver is responding correctly:
These confirm the resolver is reachable but do not prove DoH is active for all system traffic. A packet capture is the definitive test.
Wireshark Packet Capture
Open Wireshark and start a capture on your active network adapter. Apply the display filter udp.port == 53. Browse several sites, open a few apps, and let background services run for a minute. If you see no UDP port 53 traffic while actively browsing, DoH is working — your queries are leaving on port 443, encrypted. Any plaintext DNS traffic visible under that filter means something on your system is bypassing DoH: commonly a VPN client, a local DNS proxy, or a browser with its own separate resolver configured.
Browser DoH vs. System-Level DoH
This is the most common source of confusion when troubleshooting. Chrome, Firefox, and Edge each have their own built-in DoH implementations, completely independent of Windows 11 system-level setting. Enabling DoH in Windows Settings does not automatically enable it in browsers — and browser DoH does not cover other applications on your machine.
- Firefox: Settings then Privacy and Security then DNS over HTTPS. Firefox defaults to Cloudflare DoH in some regions regardless of the OS DNS setting.
- Chrome: Settings then Privacy and security then Security then Use secure DNS. When set to automatic, Chrome checks if the current system resolver supports DoH and uses it if available.
- Edge: Settings then Privacy, search, and services then Security then Use secure DNS. Same behavior as Chrome — automatic mode defers to the OS resolver.
For the broadest coverage, enable DoH at the system level in Windows Settings. This covers all applications including CLI tools, update services, and anything else making DNS queries — not just browsers. Leave browser DoH on automatic so browsers defer to the operating system rather than creating a split configuration with different resolvers per application.
Common Misdiagnoses
DoH is set but queries still appear in plaintext: The most likely cause is that the DoH setting was applied to one adapter while traffic is routing through another. A laptop running both Wi-Fi and Ethernet needs DoH configured on each adapter separately. Confirm which adapter carries your default route with route print in a command prompt or Get-NetRoute -DestinationPrefix 0.0.0.0/0 in PowerShell, then verify DoH is set on that specific adapter in Settings.
Captive portals stop appearing: Hotels, airports, and coffee shops use DNS hijacking to redirect you to a login page. With DoH active and set to Require mode, the hijack attempt fails silently and the portal page never appears. Set the DoH dropdown temporarily to Off, authenticate to the captive portal, then re-enable DoH. Windows 11 22H2 and later includes captive portal detection logic that attempts a temporary plaintext fallback, but it does not succeed in all environments.
VPN bypasses DoH: Most VPN clients push their own DNS servers when the tunnel connects, overriding Windows DNS settings for the duration of the session. If your VPN routes all DNS through its tunnel, your Windows DoH configuration is silently bypassed. Configure DoH within the VPN client if it supports the feature, or choose a VPN provider with native encrypted DNS such as Mullvad or ProtonVPN.
IPv6 DNS still unencrypted: The DoH toggle applies per-protocol in Method 1. If you configure DoH for IPv4 but skip the IPv6 section, DNS queries over IPv6 interfaces leave as plaintext on dual-stack networks. Enable and configure both the IPv4 and IPv6 toggles to fully cover both protocol stacks.
2026 Update: Router-Level DoH and DNSSEC
Modern home routers now support DoH forwarding at the gateway level, encrypting DNS for every device on the network — smartphones, smart TVs, IoT devices — without per-device configuration. ASUS routers running firmware 3.0.0.4.388 and later offer DoH under Advanced Settings then LAN then DNS Director. TP-Link Deco and Omada access points added DoH in 2025 firmware releases. On open-source firmware, OpenWrt supports DoH via the stubby or unbound packages, and DD-WRT includes DoH forwarding in builds from 2024 onward. If your router supports gateway-level DoH, that approach covers every device on your network without touching individual machine settings.
DNSSEC complements DoH rather than replacing it. DoH encrypts the transport path between your machine and the resolver. DNSSEC uses cryptographic signatures published in DNS zones to validate that responses have not been tampered with — protecting against cache poisoning and spoofing attacks even when the query path is in plaintext. Quad9 (9.9.9.9) enforces DNSSEC validation by default, making it a strong choice when you want both encrypted transport and response integrity verification simultaneously. For the full protocol details, see RFC 8484, the DNS over HTTPS specification.
Windows 10 and DoH
Windows 10 does not have native DoH support in the Settings UI — the feature was introduced exclusively in Windows 11. On Windows 10 your options are: enable DoH within each browser individually, run a local DoH proxy such as cloudflared as a Windows service listening on 127.0.0.1 port 53 and point Windows DNS to that address, or configure DoH forwarding at the router for network-wide coverage. An undocumented DohWellKnownServers registry path exists in Windows 10 20H2 and later and partially activates DoH through the DNS Client service, but it lacks the GUI controls and is not officially supported by Microsoft.
Keeping DoH Configured Long-Term
The DoH setting applied in Method 1 is tied to the network adapter, not to individual Wi-Fi network profiles. Connecting to a different Wi-Fi SSID does not reset your DoH configuration — your resolver choice and encryption mode persist on that adapter across all networks it connects to. Configuration does not carry over when you change physical adapters: a new USB-to-Ethernet dongle, a replacement Wi-Fi card, or a docking station network adapter will need DoH configured from scratch after installation.
For IT administrators managing a fleet, combine Group Policy enforcement (Method 3) with DHCP Option 6 pointing to the same DoH-capable resolver IPs. Group Policy enforces the DoH mode and prevents user overrides; DHCP Option 6 ensures correct resolver IPs are present even after adapter resets. Group Policy re-applies at each refresh interval — typically every 90 minutes — keeping the configuration consistent across the fleet without manual intervention on each machine.