Encrypted DNS protects the resolver path, not the destination
Encrypted DNS hides your lookups from everybody between you and the resolver you chose.
It does not hide them from the resolver, which now knows everything, and it does not hide where you subsequently connect. So it moves visibility rather than removing it, from your internet provider to whoever runs the DNS service. That may be an improvement depending on who you would rather trust. It is not invisibility.
More on DNS and domains
- DNS is a directory, not proof of safetyIt only answers where
- DNSSEC signs answers but does not hide themA sealed postcard
- Registrar compromise can outrank server securityIt all hangs from one fitting
- Registrar locks add friction to domain theftThe pin that makes them stop
- Dangling DNS can point to somebody else's resourceYour plate, their locker
- Subdomain takeover begins with abandoned ownershipNobody minding the stall
