DoH (DNS over HTTPS)

Also known as: DNS-over-HTTPS

DNS over HTTPS (RFC 8484) carries DNS queries inside HTTPS on TCP/443, making them indistinguishable from ordinary web traffic. For mobile operators DoH bypasses on-path DNS filtering, parental controls and lawful DNS logging when UEs or apps use third-party resolvers, and it changes the threat model for DNS-based malware detection.

Categories: FraudProtocols and StandardsInternet and Routing

DoH in context

Telecom fraud costs operators an estimated $40+ billion per year. Common vectors include IRSF, Wangiri callback scams, SIM box bypass, PBX hacking and A2P grey routing.

Telecom security is written into standards from 3GPP, GSMA, ETSI, IETF and ITU-T. Understanding which body owns which specification, and how they interlock, is essential for both design and audit work.

To place DoH in the wider telecom-security picture, review 3G, 3GPP, A5/1, BGP, Digital Signature and GSMA Permanent Reference Documents (IR Series) — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.