News & Updates

How to Test Google DNS over HTTPS: A Quick Guide

By Julian Ashford 7 min read 4983 views

How to Test Google DNS over HTTPS: A Quick Guide

If you’ve heard the buzz around DNS over HTTPS (DoH) and want to test Google DNS DoH yourself, you’re in the right place. DoH encrypts the classic domain‑name look‑up process, shielding it from eavesdroppers and tampering. Google’s public DoH endpoint (https://dns.google/dns-query) is a popular choice, but confirming it’s actually in use isn’t always obvious. This guide walks you through the why, the what, and the how—no deep networking degree required.

Why Test Google DNS DoH?

Before you dive into commands and apps, consider the payoff. Traditional DNS queries travel in clear text, making them trivial for anyone on the same network to sniff. DoH wraps those queries in TLS, the same protocol that secures your web browsing. Testing ensures that:

  • Your device is really sending DNS requests to Google’s encrypted endpoint.

In short, a quick verification can catch a silent fallback that would otherwise defeat the whole purpose of DoH.

Prerequisites: What You’ll Need

Gather these items before you start:

  • A computer or smartphone running a recent OS (Windows 10+, macOS 10.15+, Android 9+, iOS 14+).
  • Access to a terminal, PowerShell, or a DNS‑testing app.
  • Internet connectivity—preferably not through a corporate proxy that rewrites DNS.
  • If you prefer a GUI, a browser with built‑in DoH support (Chrome, Firefox, Edge).

Most modern browsers already ship with Google DoH as an optional resolver, but you’ll still want a way to confirm the traffic actually hits the right server.

Testing via Command‑Line Tools

Command‑line utilities give you raw visibility and work on virtually any platform. Below are three popular approaches.

1. Using curl to Query the DoH Endpoint Directly

Open a terminal and run:

curl -H 'accept: application/dns-json' 'https://dns.google/dns-query?name=example.com&type=A'

The response is a JSON payload containing the IP address for example.com. If you see a JSON object with a Answer section, the request succeeded over HTTPS.

Tip: Add --trace-ascii - to watch the TLS handshake in real time, confirming that the connection went to dns.google on port 443.

2. dig with the @tls Modifier (Linux/macOS)

Many recent dig builds support the @tls syntax. Try:

dig @dns.google +tls +https example.com A

If the query returns an answer, you’ve successfully spoken DoH to Google. The +tls flag forces TLS, while +https tells dig to use the DoH protocol instead of standard DNS over TCP.

3. PowerShell’s Resolve-DnsName with a Custom Resolver

On Windows, you can point Resolve-DnsName at Google’s DoH endpoint via a small script:

$url = 'https://dns.google/dns-query'

$payload = [System.Text.Encoding]::UTF8.GetBytes('{"name":"example.com","type":1}')

$resp = Invoke-WebRequest -Uri $url -Method POST -Body $payload -ContentType 'application/dns-json'

$resp.Content | ConvertFrom-Json

The output mirrors the JSON you’d see with curl. Though a bit more verbose, this method works even on systems without native DoH tools.

Browser‑Based Checks

Most people interact with DoH through their browsers. Here’s how to verify the setting without leaving the page.

  • Chrome/Edge: Navigate to chrome://net-internals/#dns (or edge://net-internals/#dns). Look for “Secure DNS” and confirm “Google” is listed as the provider.
  • Firefox: Type about:networking#dns and scroll to the “Secure DNS” section. You should see “dns.google” as the active resolver.

To double‑check, open the browser’s developer tools, go to the “Network” tab, and filter for “dns.google”. A successful HTTPS request with a 200 status indicates the browser is indeed using DoH.

Using Third‑Party Apps for Mobile Devices

Mobile OSes often hide DNS settings behind layers of UI, but a few apps make testing painless.

  • Android: Install “DNS over HTTPS” from the Play Store, select Google as the provider, and tap “Test”. The app reports whether the TLS handshake succeeded.
  • iOS: The “Network Analyzer” app includes a DoH test tab. Choose “Google” and run the query; the result shows the raw JSON response.

These tools are especially handy when you need to verify DoH on a device you don’t control via command line.

Interpreting the Results

When you see a JSON response containing an Answer array, you’ve confirmed a successful DoH query. If the request fails with a timeout or a non‑200 status, consider the following culprits:

  • Local firewall or antivirus that blocks outbound TLS on port 443 to unknown hosts.
  • Network that performs DNS interception and forces plain DNS.
  • Outdated OS or browser lacking DoH support.

Fixes range from adjusting firewall rules to updating the client software. In most home setups, simply enabling “Secure DNS” in the browser preferences resolves the issue.

Advanced: Verifying the TLS Certificate

For the ultra‑curious, you can inspect the certificate presented by dns.google. Run:

openssl s_client -connect dns.google:443 -servername dns.google -tls1_2

Scroll to the “Certificate chain” section. You should see Google’s publicly trusted certificate, signed by a recognized CA. Matching the hostname confirms you’re not being MITM‑ed.

FAQ

What is the difference between DNS over HTTPS and DNS over TLS?

Both encrypt DNS queries, but DoH tunnels the traffic through standard HTTPS (port 443), making it harder for network filters to block without disrupting regular web traffic. DNS over TLS (DoT) uses a dedicated port (853), which can be more readily identified and blocked.

Can I use Google DoH on a router?

Yes, many modern firmware options—OpenWrt, AsusWRT‑Merlin, and even some stock firmware—let you specify a DoH server. Enter https://dns.google/dns-query as the URL, enable TLS, and reboot the router.

How do I know my ISP isn’t still seeing my DNS queries?

If the DoH test returns a valid JSON response and your device’s network logs show only HTTPS traffic to dns.google, the ISP can see that you’re contacting Google but not the contents of the queries. For added privacy, combine DoH with a VPN that tunnels all traffic.

Is Google’s DoH service free?

Google offers its public DoH endpoint at no charge for typical consumer use. Excessive automated querying could trigger rate limiting, but ordinary browsing and occasional manual tests stay well within the free tier.

8.8.8.8 Google Public DNS: Fast & Secure DNS Explained
DoH and DoT proxy servers for DNS requests encryption
DNS Speed Test:找出你位置最快的 DNS 伺服器,免費線上測試工具 – 免費資源網
Securing Your Digital Journey: A Guide to DNS Privacy with DoT and DoH

Written by Julian Ashford

Julian Ashford is a Chief Correspondent with more than a decade of experience reporting on public affairs, global events, and developing stories. His coverage emphasizes careful sourcing and practical context, giving readers a clearer understanding of significant events and the forces driving them.


You Might Like