DoH
RU: DoH
DNS over HTTPS (RFC 8484): tunnels DNS queries inside HTTPS on port 443, hiding them from on-path observers who see only encrypted TLS traffic. The tradeoff is centralization: all queries go to a single DoH resolver that can see every hostname a client requests, and filtering DNS at a network level becomes harder.