1.🚨 Incognito Mode Is Not Enough: Your Browsing Is Still Exposed
Many users believe that: Incognito mode = privacy, HTTPS (the lock icon) = full security. But this is only partially true. Even with HTTPS: Your DNS requests are still sent in plain text. This means:
- Routers can log your activity
- Public WiFi admins can track visited domains
- Attackers can intercept your browsing patterns
👉 Conclusion: HTTPS protects content, but not your destination.
2. 🧠 Understanding DNS: The Hidden Privacy Leak
Let’s simplify DNS with an analogy:
- Website domain = Restaurant name
- DNS server = Food delivery platform
- IP address = Actual location
When you browse:
- You ask DNS: “Where is this website?”
- DNS responds with an IP
- Your browser connects
The problem:
- 👉 Your request to DNS is NOT encrypted
- So others can see: “This user is visiting this specific website”
3. 🔐 The Built-in Solution: DNS over HTTPS (DoH)
Windows 11 includes a powerful feature: 👉 DNS over HTTPS (DoH)
What it does:
- Encrypts DNS queries
- Hides domain names
- Prevents tracking and spying
Key advantages:
- Works system-wide
- No extra software needed
- More reliable than browser extensions
- Completely free
👉 Conclusion: DoH hides where you are going online.
4. 🛠️ Step-by-Step Guide to Enable DoH on Windows 11
Step 1: Open Network Settings
- Open “Settings”
- Go to “Network & Internet”
Step 2: Select Your Network
- Ethernet → Click “Ethernet”
- WiFi → Click “WLAN”
Then open the detailed settings page
Step 3: Edit DNS Settings
- Find “DNS server assignment”
- Click “Edit”
- Switch to “Manual”
- Enable: IPv4, IPv6 (optional but recommended)
Step 4: Configure DoH DNS
- Enter: Preferred DNS: `1.1.1.1`
- Alternate DNS: `1.0.0.1`
- Then: Set “DNS over HTTPS” to: Automatic (encrypted)
- IMPORTANT: Turn off “Fallback to unencrypted requests”👉 This prevents privacy leaks
Step 5: Save Changes
- Click “Save” — setup complete.
5. 🔍 Verification: See the Difference Yourself
Using a packet capture tool:
Before DoH:
- Domain names visible (e.g., google.com)
- DNS queries in plain text
After DoH:
- No domain names visible
- Only encrypted HTTPS traffic (port 443)
👉 Conclusion: Your browsing targets are now invisible.
6. 🎯 Final Takeaway: Real Privacy Without VPN
With this setup, you achieve:
- ✅ Encrypted DNS queries
- ✅ Protection on public WiFi
- ✅ System-wide security
- ✅ Zero cost
👉 Final thought: You don’t need a VPN to significantly improve your privacy—Windows 11 already gives you the tools.
7. Demo Video
You can watch the following demo video by select the subtitle to your preferred subtitle language.