<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Dns-Over-Https on krash.dev</title><link>https://krash.dev/tags/dns-over-https/</link><description>Recent content in Dns-Over-Https on krash.dev</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 14 Aug 2026 08:29:09 +0530</lastBuildDate><atom:link href="https://krash.dev/tags/dns-over-https/rss.xml" rel="self" type="application/rss+xml"/><item><title>DNS Over HTTPS (DoH): What, Why, and How It Works</title><link>https://krash.dev/posts/dns-over-https/</link><pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate><guid>https://krash.dev/posts/dns-over-https/</guid><description>&lt;p&gt;You&amp;rsquo;re at a coffee shop. You join the free Wi-Fi, type &lt;code&gt;bank.example.com&lt;/code&gt;, and start checking your balance. The connection to your bank is locked behind that reassuring little padlock — TLS, encrypted, private.&lt;/p&gt;
&lt;p&gt;Except the &lt;em&gt;question you asked first&lt;/em&gt; wasn&amp;rsquo;t private at all.&lt;/p&gt;
&lt;p&gt;Before your browser could open that encrypted tunnel, it had to ask a simple question:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;strong&gt;&amp;ldquo;What&amp;rsquo;s the IP address for bank.example.com?&amp;rdquo;&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;&lt;p&gt;That question — a DNS lookup — left your laptop unencrypted, in a 40-year-old format (&lt;a href="https://datatracker.ietf.org/doc/html/rfc1035" target="_blank" rel="noopener noreferrer"&gt;RFC 1035&lt;/a&gt;
), for anyone on that Wi-Fi (and your ISP, and a few hops in between) to read, log, or quietly change.&lt;/p&gt;</description></item></channel></rss>