DNS over HTTPS encrypts Firefox's domain-name lookups to a compatible resolver. That can reduce passive observation of names on the local network, but it changes which DNS service answers. A family filter, corporate split-DNS name or hotel portal may rely on the network's resolver. Mozilla's Default mode can fall back and may disable DoH under certain VPN, parental-control or enterprise conditions; Max insists on secure DNS and shows an error rather than silently falling back.
Before you start
Identify who manages your network and whether it blocks dangerous domains or resolves internal names. If an employer or school controls the device, follow its policy. Remember that encrypted DNS does not encrypt all browsing content, hide your IP from a site or automatically block phishing.Do it step by step
- In Firefox Settings, Privacy & Security, locate DNS over HTTPS and open Advanced settings. Note the current level and provider before changing anything.
- For ordinary home use, try Default first. It can choose secure DNS where available and fall back when needed. Check Mozilla's status display to see whether DoH is actually active on the current network.
- If you want a selected resolver more consistently, consider Increased Protection and test normal websites plus any family-filtered or internal service names. Read the provider's privacy policy; DNS queries move from the local resolver to that provider.
- Use Max only if you accept that resolution may fail when the secure resolver is unavailable or reports no address. Test a known working domain after changing the mode; do not misinterpret every resulting error as a website outage.
- On a managed or filtered network, ask its operator before overriding a resolver. If one internal domain fails, use Firefox's documented site exception or an approved network setting rather than disabling protection globally without diagnosis.
- When leaving the network, check the Firefox DoH state again. Default's behavior can change by network, so the setting label alone does not prove every lookup used encrypted DNS.