You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
DoH and DoT encrypt the query the same way. DoH only differs in blending with port 443 traffic, which helps against networks that block port 853.The resolver IP is visible either way, so the privacy gain is marginal.
Against the resolver, they are identical, to a network observer well that's different.
Anyways wiring an extra daemon (e.g: dnscrypt, cloudflared, ...) would be considered more of post-install versus systemd-resolved which we already ship/configure, if that makes sense.
describe the request
It would be amazing if we could be able to choose a DNS server that works system-wide.
For example using Quad9 DNS system-wide would make the system more secure and private in my opinion.