Priviy
privacy-basicsCOMP

DNS over HTTPS vs VPN: They Hide Different Halves of the Same Sentence

DoH encrypts the question your device asks. A VPN moves the whole conversation. Neither hides the destination on its own, and both replace one party you must trust with a different one.

By Eric Gerard · Editor · Priviy3 min readPhoto via Pexels

These two get compared as though one were a lighter version of the other. They protect different parts of the same event.

DoH encrypts the question. Your device asks which IP address belongs to a name, and that question travels encrypted instead of in the clear.

A VPN moves the whole conversation. The network you are on sees traffic to the VPN server and nothing else about where it goes afterwards.

What DoH actually removes, and what it leaves

It removes the clearest signal: the name, in plain text, readable by anyone on the path.

What remains after it:

  • The IP address you connect to immediately afterwards. On a site with a dedicated IP, that is the destination, spelled out.
  • The server name during the handshake, still visible on many connections.
  • Timing and volume, which are weak individually and informative in aggregate.

DoH removes one loud signal and leaves several quiet ones. That is a genuine improvement and it is not invisibility.

A frosted glass partition in a black frame, with the blurred but clearly recognisable silhouette of an ornate lantern showing through it, next to a clearer glass panel hung with crossed yellow ribbons and a tassel.
A frosted glass partition in a black frame, with the blurred but clearly recognisable silhouette of an ornate lantern showing through it, next to a clearer glass panel hung with crossed yellow ribbons and a tassel.

The glass does exactly what it promises. You cannot read the detail, and you can still see that it is a lantern, roughly how big, and exactly where it stands. Removing the label is not the same as removing the shape.

The trade nobody mentions

DoH does not delete the record of your lookups. It moves it.

Your internet provider stops seeing them. The resolver you chose starts seeing all of them, and that resolver is usually a large company configured by default in your browser or operating system, which you may never have consciously picked.

That can absolutely be an improvement: a resolver with a published policy and no commercial interest in your browsing beats a provider that logs by regulation. But it is a transfer of trust, not an elimination of it, and choosing well means reading the resolver's policy rather than assuming the encryption did the work.

The same sentence applies to the VPN, for the same reason. Every tool on this page moves who is watching. None of them empties the room.

Stacked red shipping containers photographed head on, their corrugated sides filling the frame, two of them marked with a white logo and the word MAGELLAN.
Stacked red shipping containers photographed head on, their corrugated sides filling the frame, two of them marked with a white logo and the word MAGELLAN.

Sealed, and completely legible. Nobody can see what is inside, and the shipper, the destination and the route are printed on the outside because the system cannot work without them. Encryption is the seal. The writing is the metadata, and it stays.

Which one for which problem

Untrusted network (cafe, hotel, airport): the VPN. The concern is the operator seeing and possibly altering your traffic, and DoH only covers the lookups.

Your own internet provider building a profile: either helps. DoH is lighter and cheaper; the VPN is more complete and moves the trust further.

Censorship by DNS blocking: DoH often works and is the simpler answer, because the block is applied at the resolver you were forced to use.

Wanting sites not to see your location: only the VPN. DoH never touches the address you connect from.

Using both, and the test that matters

Running both is normal and largely automatic: a well-behaved VPN already carries your lookups through the tunnel, which is the job DoH would have done.

The thing worth checking is that they actually go through it. A DNS leak is silent, and the client will show the same green icon whether or not it is happening. That test takes a minute and it is worth more than the choice between these two tools, because a leaking VPN with DoH configured can still hand your provider the list of everywhere you went.

Where both stop

Neither touches what identifies you at the other end. Your login, your cookies, your browser fingerprint. A site you sign into knows exactly who you are whatever route the packets took, and no amount of encryption on this page changes that sentence.

Frequently asked questions

What is the difference between DNS over HTTPS and a VPN?
DoH encrypts one specific thing: the lookup your device performs to turn a domain name into an IP address. A VPN encrypts and reroutes the entire connection, so the network sees only traffic to the VPN server. DoH hides the question you asked. A VPN hides the whole conversation, including which building you walked into. They are not competing products in the same slot, and using both is normal.
Does DNS over HTTPS hide the websites I visit?
Partly, and less than most people assume. Your provider no longer sees the name you looked up, but it still sees the IP address you then connect to, and on many connections the server name is still visible during the initial handshake. For a site with a dedicated IP, the destination is effectively obvious anyway. DoH removes one clear signal and leaves several fainter ones standing.
Is DoH enough on public wifi?
It is better than nothing and it is not what you want there. On an untrusted network the concern is the operator seeing your traffic and potentially tampering with it, and DoH only protects the lookups. HTTPS already protects the contents of most pages. If the network itself is the thing you distrust, the tool that addresses that is the VPN, because it removes the operator's visibility of everything rather than of one step.
Who sees my DNS queries when I use DoH?
The resolver you chose, which is usually a large provider configured by default in your browser or operating system. This is the trade people miss: DoH does not delete the record, it moves it from your internet provider to a company you have probably not thought about. That may well be an improvement, and it is a transfer of trust rather than an elimination of it.
Should I use both DoH and a VPN?
It is a reasonable default and largely automatic. A well-behaved VPN already carries your DNS lookups through the tunnel, which is what DoH would have protected, so the benefit overlaps. What matters more is testing that your lookups actually go through the tunnel rather than leaking around it, because that failure is silent and the interface will show you a reassuring green either way.
Choix éditorial
4.5 / 5

Store your files privately → pCloud

Swiss privacy · 10 GB free · optional zero-knowledge Crypto

Société suisse depuis 2013Satisfait ou remboursé 10jFree 10 GB
Voir l'offre