Modern internet privacy relies on combining Encrypted Client Hello with secure DNS protocols like DoH, DoT, and DoQ to prevent ISPs from tracking your browsing activity and domain lookups.
Key Points
- Encrypted Client Hello (ECH), standardized in RFC 9849, hides the destination hostname during the initial TLS handshake to prevent metadata leaks.
- DNS-over-HTTPS (DoH), DNS-over-TLS (DoT), and DNS-over-QUIC (DoQ) provide encrypted transport layers to secure DNS queries between devices and resolvers.
- Android 17 and modern desktop browsers have integrated broad support for ECH, making hostname encryption a standard feature of the web stack.
- Switching DNS providers does not automatically enable encryption; users must specifically configure "Secure DNS" or "Private DNS" settings to ensure traffic is protected.
- Choosing a DNS resolver is a privacy decision, as providers like Quad9 or Cloudflare maintain different policies regarding data logging, malware filtering, and jurisdiction.