1. Current Location: Home >  Router Encyclopedia >  What does encrypted DNS mean? Even after changing the DNS, I still got rushed to answer. I caught a bag and finally realized that UDP 53 was a postcard

What does encrypted DNS mean? Even after changing the DNS, I still got rushed to answer. I caught a bag and finally realized that UDP 53 was a postcard

Encrypted DNS schematic: plaintext DNS runs on UDP53, like a postcard that can be answered halfway; DoH and DoT put the diversion strip into an envelope; browser secure DNS, Android private DNS, and router each have their own switches

last time, I wrote about optical modem changing DNS, and at the end I tossed out the line, 'The only solution to quick answers is encrypted DNS,' but I didn't elaborate further. Later, people started asking: What is encrypted DNS? I've changed my DNS to 223.5.5.5, but why do some websites still lead to strange places? This time, I checked the bag and switches one by one, explaining everything clearly.

first look at what this postcard looks like

to get to the point: every time you type a website, the 'asking for directions' sent by the browser is on port 53 of UDP, not encrypted .

I used Python to query 223.5.5.5 and typed out the returned original byte to check. After the 12-byte header, the URL you asked for is immediately followed — broken down into segments by point, length plus content, blatantly placed in the bag. From what I found, www.shunot.com three words in ByteFlow are readable with the naked eye, without even decoding. Whatever you ask, whatever it answers, every device on this road can see it clearly.

no one has taken this seriously because everyone just assumes, 'If you want to look, just watch it—it's just an IP address.' But if you can see it, you can make changes. And this plain road is not short: the home optical modem, corridor equipment, and the operator's metropolitan area network all the way, every hop is worth passing. web pages have long been in HTTPS envelopes, but the 'Ask for Directions' note has always been a postcard, walking naked.

encrypted DNS does just one thing: put postcards into envelopes. After installation, when you grab packets from outside, you can only see a connection to port 443, which looks exactly like the traffic you use when browsing web pages. It answers whatever questions you ask, but you can't see it from outside or get in.

How does

buzzer happen

DNS this agreement was designed to be especially polite: you shout, and whoever answers first gets the credit. Normally, the DNS you asked for answers first, but on the plaintext route, any device along the way can get a fake one before the real answer is delivered. Your browser can't tell real from fake, first come, first served, and you'll end up getting led into the trench.

want to verify if someone is rushing to answer, without installing any tools, 114 has set up a dedicated detection domain:

nslookup whether.114dns.com 223.5.5.5

the official IPs returned were the 114 official ones; If you return to 127.0.0.1 or another strange address, congratulations, someone is rushing to answer on your road. Last time, after my cousin changed her DNS, the ads stopped for two months and popped up again. That's the reason—her DNS was correct, but the real issue was that the plaintext route was still in place, and people rushing to answer kept trying different ways to insert it.

By the way, the ones rushing to answer aren't necessarily the operators. Company networks, hotel WiFi, and unknown public networks all dare to do this. This is a completely different matter from router being hacked DNS DNS being tampered with; rushing to answer is like someone intercepting you on the road—one checks home, the other checks the road.

DoH and DoT, two crypto postal workers

There are two ways to

envelopes; sooner or later, you'll come across these two abbreviations, so recognize the face first.

one is called DoH, which puts DNS queries into HTTPS and runs through port 443, mixing with web traffic. The advantage is it's hidden; it's hard to remove it by itself—typing 443 is like blocking the entire webpage. The other is DoT, where you set up port 853 and use dedicated encrypted DNS—clearly separated, easy to manage and block. That's why company network administrators block private DNS with a single seal: the 853 dedicated port is too conspicuous, and the firewall rules take it away; And DoH is mixed in with the crowd; if you want to fight it, you have to take the webpage down with you.

I shook my hand on port 853 of 223.5.5.5 and pulled out the certificate: CN is *.alidns.com, the issuer is Alibaba, and the verification passed. This is another benefit of encryption— who you are connecting to, the certificate the final say. In plaintext mode, the responder can pretend to be any DNS reply, but in encrypted mode, it cannot deliver a verifiable certificate and cannot be spoofed.

home scenarios, you don't need to memorize terminology; just remember one sentence: Android's "private DNS" uses DoT, while the browser's "secure DNS" mostly uses DoH. The envelopes are different—they all contain your own asking instructions.

three switches each with one tube layer, don't expect a single one-piece package

this is the easiest thing to get confused by tutorials: the three switches have completely different ranges for each layer, so opening the wrong layer is equivalent to not opening at all.

switch who weaknesses who you are
Browser Security DNSChrome Set → Privacy and Security → Security→ Use Security DNS Focus on the Browser WeChat and Various Apps Without Worrying About It
Android private DNS settings → network and internet→ private DNS is activated on the whole device if you fill in the wrong information and can't access the internet, iOS doesn't have this access
Router-side encryption DNS basically no home firmware, OpenWrt plugins FamilyMart including IoT devices high entry barrier, ordinary firmware is out of reach

browser layer is the easiest to get started. In Chrome's custom box, enter https://dns.alidns.com/dns-query. Note that it only recognizes domain names; if you enter a pure IP like 223.5.5.5, it will not recognize it. Firefox needs to be opened manually in the settings; our network environment doesn't push it by default. There's a pitfall: If you fill in this box incorrectly, it doesn't report an error and quietly returns to plaintext. You think it's open, but actually it hasn't.

Android 9.0 and later has a "private DNS," the path is shown in the table above. Enter the hostname as dns.alidns.com or Tencent's dot.pub_. Don't accidentally add the HTTPS prefix—that is the DoT hostname, not the URL. iOS doesn't even have this setup portal. If you want system-level encryption and install a description file, that's far beyond what ordinary people can handle. My suggestion is that Apple users can just use the browser layer to get to the end.

the router layer is the most awkward. After searching all the home backends for Xiaomi Mercury, I couldn't find this feature. router DNS modified, it was still the plaintext version. If you want your whole family to encrypt the camera, including the vacuum cleaner, you have to flash OpenWrt and install plugins. I mentioned this threshold in my post about choosing public DNS in , and it's not worth flashing your phone for this. There's also the reality: even if the router encrypts this layer, the IoT device's built-in DNS can't be blocked. Whether this layer is enabled or not is the "big deal," not the "entirety."

the cost of the matter must be settled on the table

crypto isn't for nothing; I tested it twice.

first item is delay. On the same machine, plaintext UDP takes 13 to 52 milliseconds to query two public DNS providers, while DoH takes 62 to 77 milliseconds to create a new connection — all that comes out is TLS handshakes. Fortunately, both browsers and systems reuse connections: the first time you ask for directions, you seal the envelope properly, then use the same envelope afterwards. You don't have to reseal every domain. So in real experience, the only real experience is a few dozen milliseconds slower, and the perception when browsing web pages is unnoticed. If you really care, try to choose a DNS as close as possible (domestic Alibaba and Tencent), since the handshake part is already short.

second is scheduling. Using Alibaba and Tencent's encrypted DNS domestically doesn't really matter—it can see your real exit and send a photo to your nearest node that needs it. But if you use those overseas encrypted DNS systems like 1.1.1.1 or 8.8.8, video sites might set up a remote node, and watching videos will spin in circles. This pitfall was covered in the CDN article. So the domestic environment is always like Alibaba's, don't blindly trust overseas addresses.

another pitfall: some company and campus networks block both 853 and custom DoH. After entering the Android private DNS list, you find your phone can't access the internet. Don't panic—delete it and restore it. It's not that the phone is broken, but the network administrator won't allow it.

Who should drive, who shouldn't mess around

to be honest: this is not a switch everyone should turn on.

your situation should you open a
nslookup it is found that you rush to answer questions and keep jumping ads, this is the cure-
medicine. If you have no symptoms don't prescribe it just for the sake of prescribing it; using Mingwen is fine too
phone has been running for years with a proxy not used. The agent has already taken over the parsing
and the home smart home is full of router layers that can't be reached, so just accept it. IoT traffic control can't be managed

there's another easy expectation to hold onto: encrypted DNS fixes "tampering on the road"—it can't fix the ads that pop up on the website itself, nor the built-in promotions in certain apps you install. After launching, not a single ad was lost. First, think about where the ads actually came from—don't take the wrong medicine and get sick.

to wrap things up in order: first check the order on whether.114dns.com, and if no one answers quickly, it's dismissed; After finding out, I tried opening the browser layer for a few days, but ads popped up before I accessed my phone's private DNS; Family-friendly encryption is a matter for those willing to mess with OpenWrt. By the way, if the changes don't take effect DNS it's not all because of rushing to answer; half is because the cache hasn't expired. First, identify the root cause before acting.

Read More


Copyright Notice Scan to read on mobile
All Rights Reserved: 《SHUNOT》 => 《What does encrypted DNS mean? Even after changing the DNS, I still got rushed to answer. I caught a bag and finally realized that UDP 53 was a postcard》
Article URL: https://www.shunot.com/en/lybk/1159.html
Unless otherwise stated, all articles are original by 《SHUNOT》. Reposting is welcome! Please indicate the original URL when reposting, thank you.

Contact Us

Online Consultation: Click here to send me a message

WeChat ID: master_135

Scan to follow