Firefox activates DNS over HTTPS for US users by default
The privacy push, which encrypts all web traffic, has angered ISPs and regulators


Mozilla has begun the rollout of encrypted DNS over HTTPS (DoH) by default for all its US-based Firefox users after working for years to upgrade the Domain Name System (DNS) protocol.
Over the next few weeks, Firefox users will be able to use the DoH protocol by default while surfing the web, meaning their web traffic will be fully encrypted. This technology blocks third-party interception and also prevents Internet Service Providers from maintaining visibility over users’ activity.
DNS, which remains unchanged since the 80s, has been long-considered an insecure protocol that, while fundamental to the internet’s structure, allows for threats such as man-in-the-middle attacks.
The archaic database links a URL to an IP address, with browsers able to identify the websites for users by matching the two when a query is made. Because there is no encryption, however, other devices may intercept these queries and potentially collect this data.
DNS lookups are often sent to servers that can allow third-parties to gain access to users search and browsing history without their knowledge. It’s one of the key methods that ISPs deploy when implementing tools like web blockers.
“Today, we know that unencrypted DNS is not only vulnerable to spying but is being exploited, and so we are helping the internet to make the shift to more secure alternatives,” Mozilla said.
“We do this by performing DNS lookups in an encrypted HTTPS connection.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
“This helps hide your browsing history from attackers on the network, helps prevent data collection by third parties on the network that ties your computer to websites you visit.”
Mozilla’s DoH implementation involves routing users’ web traffic to a DNS server hosted by either Cloudflare or NextDNS depending on their preference, instead of DNS servers hosted by ISPs and networking companies.
The DoH protocol will be configured by default for US users over the next few weeks, although users outside of the US may activate this level of encryption by accessing the settings menu. This is an option in the connection settings menu.
This privacy-focused move typifies the approach Mozilla has taken in recent years to fine-tuning and differentiating its Firefox browser from a host of competing applications, such as Google Chrome and Microsoft Edge.
Chrome, however, also allows users to adopt DoH, although this will have to be manually configured, unlike for US users in Firefox, and soon across the rest of the world, who will enjoy DoH security by default.
RELATED RESOURCE
Digital Risk Report 2020
A global view into the impact of digital transformation on risk and security management
Microsoft, similarly, embraced this protocol in November, announcing it would work to implement more secure technology into its products. This would start with plans to upgrade its servers to use the DoH protocol.
The shift to DoH is expected to anger ISPs, who in the UK previously branded the company an ‘internet villain’ for simply considering implementing the protocol.
Service providers, and regulators like Ofcom, or the FCC in the US, have relied on the DNS protocol for a host of functions, such as implementing content blockers. The mass implementation of DoH would render such tools useless as ISPs would lose all visibility over their customers’ web traffic.

Keumars Afifi-Sabet is a writer and editor that specialises in public sector, cyber security, and cloud computing. He first joined ITPro as a staff writer in April 2018 and eventually became its Features Editor. Although a regular contributor to other tech sites in the past, these days you will find Keumars on LiveScience, where he runs its Technology section.
-
Spanish spyware outfit uncovered, develops exploits for Windows, Chrome, and Firefox
News Google was only able to discover the company after an anonymous submission was made to its Chrome bug reporting programme
By Zach Marzouk
-
Firefox 95 boosts protection against zero-day attacks
News Mozilla's browser now takes a more granular approach to walling off code
By Danny Bradbury
-
Mozilla to end support for Firefox Lockwise password manager
News Replacement service already lined up as browser specialist continues to streamline business
By Bobby Hellard
-
Firefox available on Microsoft Store for first time
News Gecko-based browser arrives after Microsoft removes restrictions
By Danny Bradbury
-
Why I’m leading a browser double life
Opinion There are benefits to using more than one browser
By Barry Collins
-
Mozilla fixes two Firefox zero-days being actively exploited
News Critical vulnerabilities allow attackers to execute arbitrary code or trigger crashes
By Carly Page
-
How to enable private browsing on any browser to keep your search history secret
In-depth Whether it's Google Chrome, Mozilla Firefox, or Microsoft Edge, here’s how to enable private browsing on every major browser
By Connor Jones
-
Best web browsers 2023: Firefox vs Google Chrome vs Microsoft Edge
Vs Firefox vs Edge vs Chrome - discover which comes out on top in the ultimate battle to crown the very best browser
By Darien Graham-Smith