The DNS Privacy Leak
When you type a web address like wikipedia.org into Google Chrome, your computer must first ask a Domain Name System (DNS) server to translate that English name into a numerical IP address. Historically, this request was sent as completely unencrypted, plain text. This means your Internet Service Provider (ISP), or anyone snooping on public airport Wi-Fi, can easily intercept that request and see exactly which websites you are visiting, even if the website itself uses secure HTTPS encryption. To close this massive privacy loophole, you must force Google Chrome to encrypt the DNS requests themselves.
How to Enable Secure DNS (DNS over HTTPS)
You can force Chrome to encrypt your routing requests via the security dashboard.
- Open the Google Chrome desktop browser.
- Click the three vertical dots (⋮) in the top right corner and select Settings.
- In the left-hand sidebar, click on Privacy and security.
- In the main window, click on Security.
- Scroll down to the “Advanced” section and look for the toggle switch labeled Use secure DNS.
- Toggle this switch to the On position (blue).
Choosing a Secure Provider
By default, Chrome is set to “With your current service provider.” However, many standard ISPs do not actually support encrypted DNS. For guaranteed privacy, you should explicitly choose an encrypted provider.
- Select the second radio button: With.
- Click the dropdown menu next to it.
- Select a trusted, privacy-focused provider from the list, such as Cloudflare (1.1.1.1) or Google (Public DNS).
Your browser will instantly begin routing all DNS requests through an encrypted HTTPS tunnel, rendering your browsing history completely invisible to your ISP.