Traditional DNS | DoH |
DNS queries are typically transmitted over UDP or TCP. | DNS queries are transmitted over HTTPS. |
DNS traffic is generally unencrypted. | DNS traffic is encrypted using HTTPS/TLS. |
DNS queries may be visible to intermediaries on the network path. | The contents of DNS queries are protected from passive observation while in transit. |
Commonly uses port 53. | Typically uses HTTPS port 443. |