📡 Encrypted DNS (DoH) Check

Is Encrypted DNS Reachable From Your Network?

Tests whether Cloudflare, Google and Quad9 DNS-over-HTTPS answer from your network, and whether Cloudflare’s resolver validates DNSSEC. Which resolver your system actually uses is what the DNS leak test measures.

🛡
Ready to test
Click “Run DNS Check” to begin
-
DoH reachable /3
📡
Your Network (information)
The network your traffic leaves from - not your DNS resolver, and not scored
Pending ▼
Run the test to see the network your traffic leaves from.
The network name says nothing about who answers your DNS lookups. To see the resolver your system really uses, run the DNS leak test.
☁️
Cloudflare DoH (1.1.1.1)
Whether Cloudflare’s DNS-over-HTTPS service answers a lookup from your network
Pending ▼
Run the test to check Cloudflare DoH availability.
🔍
Google DoH (8.8.8.8)
Whether Google Public DNS answers a DNS-over-HTTPS lookup from your network
Pending ▼
Run the test to check Google DoH availability.
🧩
Quad9 DoH (9.9.9.9)
Whether Quad9 (which also blocks known malware domains) answers a DNS-over-HTTPS lookup from your network
Pending ▼
Run the test to check Quad9 DoH availability.
🔒
Cloudflare’s Resolver Validates DNSSEC
Information, not scored: a property of Cloudflare’s resolver, not of the one your system uses
Pending ▼
Run the test to see whether Cloudflare’s resolver rejects a domain with broken signatures.

Why DNS Encryption Matters

Standard DNS queries are sent in plaintext. Your ISP, network admin, or any observer can see every domain you visit. DNS-over-HTTPS (DoH) encrypts these queries, hiding them inside regular HTTPS traffic.

Some networks block the well-known DoH services so that lookups have to go through their own resolver. This page asks each of the three for example.com over HTTPS and scores only whether it answered. A service that did not answer may be blocked on this network - or the service, an extension or the connection got in the way, which a browser cannot tell apart. Reachable is not the same as in use: whether your browser or system sends its lookups to one of them, or to your ISP, is what the DNS leak test measures.

How to Enable DNS-over-HTTPS

  • Firefox: Settings → Privacy → Enable DNS over HTTPS (choose Cloudflare or Custom)
  • Chrome/Edge: Settings → Security → Use secure DNS (select provider)
  • Windows 11: Network Settings → DNS Server → set to 1.1.1.1 with DoH
  • Router-level: only if the router supports DNS-over-TLS or DoH. Setting plain 1.1.1.1 changes who answers, not whether the query is encrypted