The Domain Name System (DNS) has long been one of the most valuable data sources for lawful interception and network intelligence. DNS queries reveal which websites a user visits, which services they access, and which applications they use — all without requiring access to the content of the communication itself. For decades, DNS traffic has been transmitted in plaintext, making it readily accessible to network-level interception. The emergence of encrypted DNS protocols — DNS over HTTPS (DoH) and DNS over TLS (DoT) — is fundamentally changing this landscape, with significant implications for lawful interception capabilities.
This article examines how DoH and DoT work, why they are being adopted, how they affect lawful interception, and what operators can do to maintain their compliance obligations in an environment where DNS traffic is increasingly encrypted.
The Encrypted DNS Challenge for Operators
Traditional DNS resolution uses UDP port 53, transmitting queries and responses in plaintext. Anyone with access to the network path between the user and the DNS resolver — including the operator, intermediate network elements, and potential eavesdroppers — can observe the DNS queries and determine which domain names the user is resolving.
DNS over TLS (DoT), defined in RFC 7858, encrypts DNS traffic by wrapping it in a TLS connection on TCP port 853. The DNS queries and responses are encrypted in transit, preventing observation by intermediaries. However, the use of a dedicated port (853) makes DoT traffic identifiable at the network level — an observer can determine that DNS resolution is occurring, even though the content of the queries is encrypted.
DNS over HTTPS (DoH), defined in RFC 8484, takes encryption a step further by tunnelling DNS traffic within standard HTTPS connections on TCP port 443. Because DoH traffic is indistinguishable from regular HTTPS web traffic, it is extremely difficult to identify and block at the network level. DoH effectively hides DNS resolution within the vast volume of encrypted web traffic that traverses modern networks.
Both protocols are designed to protect user privacy by preventing the observation of DNS queries by network intermediaries. Major browser vendors — including Mozilla Firefox and Google Chrome — have implemented DoH support, and some operating systems now support DoH and DoT natively. The adoption of encrypted DNS is accelerating, driven by privacy advocacy, browser defaults, and the broader trend toward encrypting all network traffic.
The Impact on Lawful Interception
The encryption of DNS traffic has a direct and significant impact on lawful interception capabilities. DNS query data has traditionally been a key component of intercept-related information, providing investigators with a detailed record of the target’s online activity. When a target visits a website, sends an email, or uses an application, the corresponding DNS queries reveal the domain names involved, even when the content of the communication is encrypted.
With DoH and DoT, operators can no longer observe DNS queries at the network level if the target’s device is configured to use an encrypted DNS resolver that is not operated by the operator. The DNS resolution process is encrypted end-to-end between the device and the resolver, and the operator’s network equipment cannot decrypt the queries without access to the TLS session keys.
This loss of DNS visibility affects both real-time interception and historical data analysis. In real-time interception, the IRI generated for a target’s data session will lack the DNS query information that previously provided context about the target’s online activity. In historical analysis, the absence of DNS logs reduces the operator’s ability to reconstruct a target’s browsing history and service usage patterns from retained data.
The impact is most acute when the target uses a third-party DoH resolver — such as those operated by Cloudflare, Google, or other providers — rather than the operator’s own DNS infrastructure. In this case, the DNS queries are resolved entirely outside the operator’s network, and the operator has no access to them whatsoever. If the target uses the operator’s own DNS resolver with DoT or DoH, the operator retains access to the query data at the resolver level, but not at intermediate network points.
Mitigation Strategies for Operators
Operators cannot prevent the adoption of encrypted DNS, but they can implement strategies to mitigate its impact on lawful interception. The first strategy is to operate their own DoH and DoT resolvers and to encourage or require their subscribers to use these resolvers. If the operator controls the DNS resolver, it retains access to DNS query data, even when the transport between the device and the resolver is encrypted. This approach preserves DNS visibility while still providing subscribers with the privacy benefits of encrypted DNS against third-party observation.
The second strategy involves using alternative data sources to reconstruct the information that DNS queries previously provided. Server Name Indication (SNI) in TLS handshakes provides the domain name of the server that the client is connecting to, and this information has traditionally been transmitted in plaintext. However, the adoption of Encrypted Client Hello (ECH, formerly ESNI) is beginning to encrypt SNI as well, further reducing visibility. IP address analysis can also provide some information about which services a target is accessing, but the widespread use of content delivery networks (CDNs) and shared hosting means that IP-to-domain mapping is often ambiguous.
The third strategy is to implement interception at the application layer or at the device level, rather than relying solely on network-level data. This approach is beyond the scope of traditional telecommunications interception but is being explored by some law enforcement agencies as a response to the increasing encryption of network traffic. For operators, this is not a practical solution, but it is part of the broader context in which encrypted DNS should be understood.
A fourth strategy involves regulatory and policy engagement. Some governments have considered or implemented requirements for operators to block access to third-party DNS resolvers or to require the use of the operator’s own DNS infrastructure. These approaches are controversial and raise questions about network neutrality, user freedom, and technical feasibility, but they represent one policy response to the challenge of encrypted DNS.
The Broader Encryption Trend
Encrypted DNS is part of a broader trend toward the encryption of all network traffic, driven by privacy concerns, security best practices, and the default configurations of major software platforms. TLS 1.3, ECH, QUIC, and other technologies are progressively encrypting more of the metadata and content that network-level interception has traditionally relied upon. Each step in this encryption trend reduces the visibility available to operators and, by extension, to lawful interception.
Operators must recognise that the network-level visibility they have historically enjoyed is declining and will continue to decline. The response to this trend cannot be purely technical — it requires engagement with regulators, standards bodies, and law enforcement to develop new approaches to lawful interception that account for the realities of a heavily encrypted network environment.
At the same time, operators must continue to deliver whatever interception data they are technically capable of providing. The encryption of DNS does not eliminate the operator’s legal obligation to intercept; it changes the scope of what can be intercepted. Operators must be transparent with law enforcement about these limitations and must ensure that their LI systems are updated to handle the reduced visibility gracefully — generating IRI that accurately reflects what is available, rather than producing incomplete or misleading data.
Implications for Compliance and Reporting
The loss of DNS visibility has implications for how operators report on their interception capabilities and for how regulators assess compliance. Operators should proactively communicate with their national regulatory authority about the impact of encrypted DNS on their LI capabilities, documenting the specific data elements that are no longer available and the steps they are taking to mitigate the impact.
Regulators in some jurisdictions may need to update their technical requirements and expectations to account for the reality of encrypted DNS. Operators can play a constructive role in this process by providing technical expertise and practical insights to inform regulatory development. The worst outcome for all parties would be a regulatory expectation that operators provide data they are technically unable to access — a situation that creates compliance risk without delivering investigative value.
סיכום
Encrypted DNS represents a significant shift in the balance between privacy and surveillance capability in telecommunications networks. DoH and DoT protect user privacy by preventing the observation of DNS queries by network intermediaries, but they also reduce the visibility available to lawful interception systems. Operators must adapt by implementing their own encrypted DNS resolvers, leveraging alternative data sources, engaging with regulators on evolving requirements, and ensuring that their LI systems accurately reflect the data that is actually available. The trend toward comprehensive network encryption is irreversible, and operators that adapt proactively will be better positioned to maintain compliance and to provide meaningful support to law enforcement within the constraints of the evolving technical landscape.
The debate around encrypted DNS also highlights the tension between individual privacy rights and the legitimate needs of law enforcement. Finding the right balance requires collaboration between technologists, policymakers, civil society, and law enforcement. Operators sit at the intersection of these interests and have a unique responsibility to ensure that technical capabilities, legal obligations, and privacy protections are aligned. By actively participating in standards development, regulatory consultations, and industry forums, operators can help shape solutions that respect privacy while preserving the ability of democratic societies to conduct lawful surveillance in accordance with the rule of law.
מאמרים קשורים
לקריאה נוספת בנושאים קשורים, עיין במאמרים הבאים:
- חיתוך רשת ב-5G SA: כיצד הדבר מסבך (ויכול לפשט) את מיקוד ה-LI
- AI-Assisted LI: What Automation Means for Operators and Law Enforcement Workflows
- IRI לעומת CC: מה המשמעות המעשית של מידע הקשור ל-Intercept
משאבים חיצוניים
המשאבים החיצוניים הבאים מספקים מידע רקע נוסף ומסמכים רשמיים:



