Is Encrypted DNS Reachable From Your Network?
Tests whether Cloudflare, Google and Quad9 DNS-over-HTTPS answer from your network, and whether Cloudflare’s resolver validates DNSSEC. Which resolver your system actually uses is what the DNS leak test measures.
Why DNS Encryption Matters
Standard DNS queries are sent in plaintext. Your ISP, network admin, or any observer can see every domain you visit. DNS-over-HTTPS (DoH) encrypts these queries, hiding them inside regular HTTPS traffic.
Some networks block the well-known DoH services so that lookups have to go through their own resolver. This page asks each of the three for example.com over HTTPS and scores only whether it answered. A service that did not answer may be blocked on this network - or the service, an extension or the connection got in the way, which a browser cannot tell apart. Reachable is not the same as in use: whether your browser or system sends its lookups to one of them, or to your ISP, is what the DNS leak test measures.
How to Enable DNS-over-HTTPS
- Firefox: Settings → Privacy → Enable DNS over HTTPS (choose Cloudflare or Custom)
- Chrome/Edge: Settings → Security → Use secure DNS (select provider)
- Windows 11: Network Settings → DNS Server → set to 1.1.1.1 with DoH
- Router-level: only if the router supports DNS-over-TLS or DoH. Setting plain 1.1.1.1 changes who answers, not whether the query is encrypted