What you need to know
DNS over HTTPS protects client-to-resolver traffic, but unmanaged external resolvers can bypass enterprise filtering, logging, caching, internal naming, and split-DNS behavior.
Potentially affected
Organizations managing recursive DNS, browsers, operating systems, mobile devices, VPN clients, roaming endpoints, internal DNS zones, or network-based DNS protections.
DSE recommendation
Inventory resolver behavior, select designated enterprise resolvers, configure managed clients, constrain unauthorized paths, preserve DNS telemetry, and test every operating location.
Encrypted DNS can protect a user’s query from observation or manipulation between the client and resolver. In an enterprise, the design must also preserve approved resolution, internal names, policy enforcement, and evidence needed to investigate malicious activity.
The benefit and the tradeoff
Source fact: NIST SP 800-81 Rev. 3 covers DoH, DoT, and DoQ as encrypted transports for DNS messages between supported endpoints. Encryption protects that DNS transport path; it does not encrypt the later application connection, prove that the destination is safe, or replace DNSSEC validation of DNS data.
Source fact: NIST addresses enterprise control of resolver selection and DNS logging. It explains that encrypted DNS sent to an unauthorized external resolver can bypass the enterprise’s local recursive resolver and recommends restricting unauthorized use of public DNS services.
DSE analysis: depending on the deployed architecture, that bypass can also remove enterprise filtering or caching, disrupt internal-name or split-DNS behavior, and disclose query data to a provider outside the approved path. Validate these consequences on the actual browsers, operating systems, applications, VPNs, networks, and resolvers before enforcing a restriction.
Encrypted DNS and protective DNS solve different problems. An approved resolver may offer both, but encryption by itself does not apply malicious-domain policy or preserve the investigation evidence an organization needs.
Choose a deliberate enterprise path
Source fact: NIST’s deployment guidance supports organization-designated DNS services, managed encrypted-DNS configuration, and policy restrictions on unapproved resolver paths. It also emphasizes retaining DNS logs and protecting the privacy and integrity of DNS operations. Enforcement must account for the protocol and platform behavior actually in use.
DSE recommendation: inventory recursive resolvers, internal zones, split-DNS behavior, DHCP and VPN assignments, mobile and roaming paths, browsers, operating systems, and applications that can choose their own resolver. Record which systems are managed, which require exceptions, and which cannot provide adequate DNS logs.
- Select approved resolver paths and configure managed clients through supported enterprise policy.
- Where operationally appropriate, constrain unauthorized port 53 DNS, port 853 DoT, and known unapproved DoH paths.
- Enable resolver and host or device DNS telemetry so encryption does not remove all investigation context.
- Validate DNSSEC and any protective-DNS functions independently of transport encryption.
- Test internal and external names, VPN, home, branch, guest, mobile, failover, resolver outage, and recovery scenarios.
Applicability and limits
SP 800-81 Rev. 3 is current technical guidance, but browser, operating-system, resolver, firewall, mobile-management, and VPN controls remain product-specific. NIST added a July 10, 2026 planning note pointing to potential errata. Review that note and current vendor documentation before enforcement. Blocking a resolver without proving alternate resolution can interrupt production services.
Official reference
NIST SP 800-81 Rev. 3 — current NIST guidance for encrypted DNS, resolver control, public-provider restrictions, DNS logging, and protective DNS.
Review the official source
NIST SP 800-81 Rev. 3: Secure Domain Name System (DNS) Deployment Guide · Published March 19, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE