Your DNS Is Hiding in HTTPS - This Is Why It Matters
Akamai Technologies, Wednesday, September 2nd, 2026
Unmanaged DNS over HTTPS hides queries inside port 443 traffic, and Akamai argues for controlled enterprise resolvers instead of blocking.
Akamai argues that encrypted DNS is now a default in operating systems and browsers, so organizations should adopt a controlled DNS over HTTPS strategy rather than trying to block it.
The security problem is that DoH masks DNS queries inside ordinary HTTPS traffic on port 443, letting malware hide command-and-control channels and exfiltrate data through DNS tunneling while bypassing controls that watch plaintext port 53.
The post recommends first gaining visibility into encrypted DNS through firewall and proxy logs, then building detections for endpoints that reach unapproved DoH providers.
It closes with a three-step protective DNS architecture: restrict DoH to designated enterprise resolvers, configure OSes and browsers to use them, and apply threat intelligence at the DNS layer.