Secure DNS client over HTTPS (DoH)
DNS queries between DNS server and DNS client are normally in plain text format. But starting from Windows Server 2022, DNS queries can pass through secure HTTP (HTTPS) connections. This prevents someone from modifying/accessing DNS data in transit. Please note this setting is only for DNS clients. Windows DNS Server does not support DoH queries. Therefore, you should not enable DoH in domain-joined computers. If there is DNS traffic between a domain-joined computer and the AD domain server, we need to consider securing IPSec connections. At the moment, Google and Cloudflare DNS servers support DoH queries.