October 3, 2026
What your router's default DNS isn't telling you
Most routers ship pointed at your internet provider's DNS by default, and that default comes with zero privacy. Here's what's actually visible on the wire, and what encrypted DNS changes.
The setting nobody changes
When you set up a home router, it almost always arrives with its DNS settings pointed automatically at whatever your internet service provider assigns, usually through a setting called DHCP that hands your router a DNS server address the moment it connects to the network. Nearly nobody changes this, because nearly nobody knows it's there to change. It's one line of configuration buried in an advanced settings page, and the router works fine either way, so there's no obvious prompt to go looking at it.
That single unchanged setting determines who sees every domain name every device in your house looks up, for as long as that device is connected.
What your ISP can actually see
By default, most DNS queries travel across the network in plain text, meaning they are not encrypted. When your laptop asks "what's the address for this site," that request and the answer travel as plain text over the connection between your router and your ISP's DNS server. Anyone with visibility into that traffic, which at minimum includes your ISP, can see the domain name you looked up, when you looked it up, and which device on your network asked.
This is a well-documented property of traditional DNS, not a hidden conspiracy. The DNS protocol was designed in the 1980s, long before privacy on public networks was a serious design consideration, and it has never encrypted queries by default. An ISP that wants to log which domains its subscribers visit can do so simply by watching DNS traffic pass through its own network, since it's typically the ISP's own DNS servers handling the request in the first place.
It's worth being precise about what this does and doesn't reveal. Unencrypted DNS exposes domain names, like "examplebank.com" or "example-health-site.com," not the specific pages you viewed within that site, and not the content of what you typed or read there, since that part of the connection is usually separately encrypted by HTTPS once it's established. But a list of every domain a household visits, timestamped, is still a meaningful amount of information about that household's habits, routines, and interests.
What DNS-over-HTTPS changes
DNS-over-HTTPS, often abbreviated DoH, wraps the same DNS query inside an encrypted HTTPS connection, the same kind of encryption already protecting your online banking or email login. Instead of sending the lookup as plain text that anyone on the network path can read, the query is encrypted end to end between your device and the DNS server answering it.
This closes the specific gap described above. An ISP, or anyone else positioned on the network between you and the DNS server, can see that your device made an encrypted DNS request, but not which domain that request was for. The traffic itself becomes indistinguishable from other encrypted HTTPS traffic. This doesn't make you anonymous on the internet, and it doesn't hide information held by the sites you choose to visit directly, but it does close off casual, network-level logging of every domain you look up.
It's also worth being clear that encryption in transit is a separate question from what the DNS provider itself chooses to do with your queries once it receives them. Switching to an encrypted DNS provider that still logs and sells query history solves the "visible on the network" problem while leaving the underlying privacy problem exactly where it was, just relocated to a different company. The provider you choose still matters as much as the protocol.
Why most router defaults don't use it
Despite DoH being a mature, widely supported standard, most consumer routers still ship with plain, unencrypted DNS as the default, usually pointed straight at the ISP. There isn't a single explanation for this. Standard home routers are commodity hardware running firmware that doesn't change often once it ships, DoH setup usually involves a few extra configuration steps on the router's admin interface, and most ISPs have limited incentive to change a default setting that routes DNS traffic straight back through their own servers.
The practical result is that the privacy gap described above stays open by default for the vast majority of home networks, not because the technology to close it doesn't exist, but because closing it isn't something that happens automatically.
Practical steps you can take today
Closing this gap doesn't require replacing your router or becoming a network administrator. A few concrete options, in rough order of effort:
- Configure DNS-over-HTTPS on individual devices. Modern browsers and operating systems increasingly support DoH natively, letting you point just your laptop or phone at an encrypted DNS provider without touching the router at all.
- Configure DNS-over-HTTPS at the router level. Many routers support changing the upstream DNS server in their admin settings, which applies the change to every device on the network at once, rather than configuring each device individually.
- Choose a DNS provider with a clear policy on data retention. Encryption only protects the query in transit. What happens to the query once it reaches the provider depends entirely on that provider's own practices, so it's worth checking what a provider says it does and doesn't keep.
- Pair encrypted DNS with filtering. Encryption closes the privacy gap. Filtering, built on top of that same encrypted connection, adds a second layer that actively blocks known-dangerous domains before your device connects to them, rather than only hiding the lookup from outside observers.
Koru Shield runs on DNS-over-HTTPS by default, so the encryption step described above isn't an advanced option you have to find and enable, it's simply how the service works from the first setup step. Guided setup instructions are available for iPhone, Android, Windows, Mac, Linux, and routers, each taking about a minute per device.
Protect every device in about a minute.
Start free with always-on, encrypted DNS filtering, no credit card required.