Back to all posts
August 6, 2026·9 min read·Privacy

Who Sees Your DNS Queries, and What They Can Work Out From Them

People assume DNS queries are too boring to reveal anything. A week of domain names, with timestamps, is one of the most revealing datasets an ordinary person generates.

By Guardino Team · Guardino Technologies

Ask most people whether their DNS queries are private and they will say they had not thought about it, which is fair, followed by a guess that it does not matter much because a domain name is not very interesting.

A single domain name is not very interesting. A week of them, with timestamps, in order, is one of the more revealing datasets an ordinary person produces without noticing.

This is who sees yours, and what that list actually says.

What a query is, briefly

Before your device can connect to anything, it has to turn a name into an address. Your phone asks a resolver "what is the address for example.com," the resolver answers, and only then does a connection open.

That question is separate from the connection, it happens first, and by default it is not encrypted. The two facts together are why this matters.

Who sees it, in order

Your internet provider. On a default setup, your provider hands your device a resolver, and it is theirs. Every lookup from every device in your home passes through it. In many countries providers are legally required to retain connection and DNS metadata for a period measured in months, and in some places they are permitted to use it commercially.

This is the big one, and it is the one almost nobody has deliberately chosen. It is simply the default that arrived with the router.

Anyone on the network path, if the query is unencrypted. A classic DNS query is plain text. On a shared or hostile network, an airport, a hotel, a café, that is readable by anyone positioned to read it. This is a smaller risk than it used to be, but it is a real one and it is entirely removable.

Whoever you switched to, if you switched. Using a public resolver moves the visibility rather than eliminating it. That can be a good trade or a bad one, but it is a trade, and it is worth knowing which company you have handed it to and what their published retention practice says.

Your VPN provider, if you use one. Most VPNs route DNS through their own resolvers. Again: a change of party, not a removal.

Your employer, on a work device or a work network. Usually legitimately and often disclosed, though not always as clearly as it should be.

Whoever runs the network you are on right now. The café wifi, the hotel, the conference. If they run the resolver, they see the queries from every device that joined.

That is a longer list than most people carry in their head, and the notable thing is how few entries on it were chosen deliberately.

What can be read from it

The instinctive defence is that a domain name says very little. Here is what a week of them says, without any page content at all.

Your schedule. The first lookup of the morning and the last of the night bracket your sleep with reasonable accuracy. A gap on Tuesdays at the same hour is a recurring commitment. Weekend patterns differ from weekday ones in ways that identify shift work, parenting, and travel.

Your employer and your work. Company domains, the tools your industry uses, the recruiting sites if you have started looking.

Your health. Repeated lookups of a specific hospital, a condition-specific charity, a pharmacy delivery service, a mental health provider. The page contents are invisible; the category is not, and the category is often the sensitive part.

Your money. Which bank, which broker, whether a debt advice service appeared in the list last March.

Your relationships and beliefs. Dating platforms, a place of worship, a political organisation, a support group.

Your household composition. Children's game and homework domains, a school's site, a nursery's app.

Changes. This is the part people underestimate. The individual entries are one thing; the deltas are another. A week when the work domains stop appearing and a hospital domain starts is a story that reads itself. So is the sudden appearance of a legal advice site, or a moving company, or a job board.

None of this requires sophisticated analysis. It is legible to anyone who opens the file.

What you can actually change

Not everything on the list is removable, but most of it is.

Encrypt the lookups. DNS-over-HTTPS and DNS-over-TLS both stop everyone on the network path from reading your queries in transit. This removes the café, the hotel and the passive observer entirely, and it removes your internet provider's ability to read the lookups as they pass. It is a setting on modern phones and browsers, not a piece of software you install.

Choose your resolver deliberately. Once queries are encrypted, the question narrows to a single party: whoever answers them. That is now one decision instead of an unexamined default, which is a large improvement even before you decide what to choose.

Read what that resolver keeps. This is the part to be careful about, because "we do not log" is a marketing phrase with no fixed meaning. Some services mean nothing at all is written. Some mean nothing linked to your identity. Some mean nothing after a day. Ask what is written, where, for how long, and who can read it, and prefer an answer that is specific over one that is confident.

Consider whether you need logs at all. If you are using a filtering service, there is often a choice about whether per-query records are kept. Keeping them lets you see what was blocked and investigate a problem. Keeping none means there is nothing to hand over, lose or breach. Neither is automatically right, and it is worth being the person who decided rather than the person who accepted a default.

What you cannot change

Something has to answer the question. There is no configuration in which nobody at all learns which domains you asked about, because the answer has to come from somewhere.

The realistic aim is to go from six parties to one, to have chosen that one on purpose, and to have some basis for the choice beyond a logo.

There is one approach worth knowing about that goes further. Oblivious DNS separates the two pieces of knowledge: a relay knows who you are but not what you asked, and the resolver knows what was asked but not who asked it. Neither party holds both halves. It is the closest available thing to nobody seeing your queries, and its practical limitation today is that support is not widespread.

The honest summary

DNS metadata is not the most sensitive data you generate, and it is nowhere near the most sensitive data held about you. It is not worth panicking about.

What makes it worth twenty minutes is that it is unusually easy to improve. The default is bad for no good reason, the fix is a setting rather than a product, and the improvement is real: encrypted lookups to a resolver you picked, with a retention practice you have read.

That is a better position than most people are in, and it takes an evening.

Related reading

Frequently asked questions

If I use HTTPS everywhere, is my DNS still visible?+

Yes, unless you have specifically encrypted DNS as well. HTTPS protects the contents of a page after the connection is made. The name lookup that finds the server happens first and, on a default configuration, travels in the clear to whichever resolver your device was handed. So an observer learns which sites you visited even though they cannot read a word of what you did there. Those are different problems solved by different mechanisms, and having one does not give you the other.

Does a VPN solve this?+

It moves it. A VPN encrypts your traffic to the VPN provider and usually routes your DNS through them too, so your internet provider stops seeing your lookups and the VPN provider starts. Whether that is an improvement depends entirely on which of the two you would rather trust and what their logging practice actually is. It is a change of who, not a removal of the who.

What can actually be inferred from a list of domain names?+

More than most people expect, because the inference comes from the pattern rather than any single entry. Timestamps reveal sleep and work schedules. Repeated lookups of a health service, a bank, a dating platform or a religious organisation reveal the category even though no page content is visible. Absence is informative too: a week where the usual work domains stop appearing suggests illness or leave. None of this requires any clever analysis; it is legible to anyone who reads the list.

Is there any way to have nobody at all see my lookups?+

Not entirely, because something has to answer the question. The realistic goal is to reduce the number of parties from several to one, choose which one that is deliberately rather than accepting whichever was handed to you, and prefer a resolver that keeps as little as possible. Approaches like Oblivious DNS split the knowledge so that the resolver sees the query without knowing who asked, which is the closest available thing to nobody, and it is not yet widely deployed.

Ready

Reclaim your attention.

Set up Guardino in two minutes. Your first 300K queries are on us.

Start your protection

Continue reading