Home  >  Article  >  DNS over TLS is now available for Windows 11 Insiders, here's how to enable it

DNS over TLS is now available for Windows 11 Insiders, here's how to enable it

PHPz
PHPzforward
2023-04-16 12:40:081550browse

Microsoft has launched build 25158 in the Windows 11 Dev Channel and Windows Server 2022 Preview. For the former, this build includes a host of new features, including different search styles, notification badges in widgets, CD ripping in the media player, and more. Meanwhile, as usual, Windows Server 2022 doesn’t even have an update log.

Another feature briefly mentioned in Microsoft's announcement blog post is DNS over TLS (DoT), a networking enhancement now available to Insiders.

If you are wondering what DoT is, it is an alternative to DNS over HTTPS (DoH) and is designed for use with encrypted web traffic. DoH, already present in Windows 11 and Windows Server 2022, enables DNS traffic to be routed over port 443 as an HTTPS stream. Meanwhile, DoT routes encrypted DNS traffic through a TLS tunnel on dedicated port 853. While DoT provides better network performance in some use cases, you do lose some of the flexibility that DoH provides.

If all of this sounds interesting to you, here is Microsoft's tutorial for enabling DoT, currently available for Windows 11 and Windows Server Insiders, build 25158:

  1. Go to Settings -> Network (this should load a view of the current default network connection)
  2. Click on Wi-Fi or Ethernet (probably the first row)
  3. Click " Hardware Properties" (probably the bottom row)
  4. In the "DNS Server Assignment:" row, click the "Edit" button
  5. Turn on the "IPv4" and/or "IPv6" switches
  6. Type the IP address of the DoT server you want to test into the "Preferred DNS" text box
  7. Save and confirm that "(Unencrypted)" appears in the "IPv4 DNS" configuration list near the bottom of this view Server:" line

Run these commands in the command prompt with administrator privileges:

##netsh dns add global dot=yes

netsh dns add encryption server=[the-ip-address-configured-as-the-DNS- resolver]<em> dothost=: autoupgrade=yes</em>

ipconfig /flushdns

It should be noted that port 853 is currently the only one that can be used for DoT The specified port currently does not support custom configuration.

The above is the detailed content of DNS over TLS is now available for Windows 11 Insiders, here's how to enable it. For more information, please follow other related articles on the PHP Chinese website!

Statement:
This article is reproduced at:yundongfang.com. If there is any infringement, please contact admin@php.cn delete