Encrypted DNS in 2026: DoH, DoT, DoQ and DoH3 protocol comparison β including DNS hijacking attack vectors and what each protocol actually prevents
26 May 2026 at 15:16
The security angle on encrypted DNS is often oversimplified. DoH prevents ISP-level snooping and basic DNS hijacking, but doesn't protect against a compromised resolver. DoT is easier to detect and block, which has real implications for threat actors trying to exfiltrate via DNS. DoQ is interesting from a security perspective because QUIC's connection ID migration makes traffic correlation harder. Article includes benchmark data and practical server config β but mostly written for the "which threat model does each protocol address" question.
[link] [comments]