Firefox begins rollout of encrypted DNS over HTTPS (DoH) by default for US-based users to thwart snooping ISPs
US-based Firefox users get encrypted DNS lookups today or within a few weeks. — Firefox will start switching browser users to Cloudflare's encrypted-DNS service today and roll …
Context & Ripple Effects
Mozilla has spent the past year clearing political obstacles for this switch: after declining to enable DoH by default in the UK under ISP and government pressure, it took the fight to Washington, urging Congress to reject ISP lobbying against encrypted DNS in Firefox and Chrome. Today's US rollout is the payoff of that campaign — and it deepens the Mozilla-Cloudflare relationship already visible in the Firefox Private Network VPN beta.
The move extends a decade-long encryption arc inside the browser, from Firefox 37's opportunistic TLS encryption to encrypting the last plaintext layer of a web request: the lookup itself. Notably, the standoff later softened — Comcast became the first ISP to join Firefox's Trusted Recursive Resolver program, suggesting carriers concluded participation beats obstruction.
First-order effects
- US Firefox users' DNS queries move to Cloudflare's resolver, stripping ISPs of visibility into which domains their subscribers look up — the metadata that feeds ad targeting and filtering.
- Cloudflare gains a massive new source of DNS traffic and resolver trust by default, cementing its position as Mozilla's infrastructure partner beyond the VPN beta.
Second-order effects
- ISPs face a choice the coverage already illustrates: fight the default in legislatures, or join the Trusted Recursive Resolver program as Comcast did to keep a role in resolution.
- Google's Chrome comes under pressure to match Firefox's default, since Mozilla's lobbying framed encrypted DNS as a two-browser standard that ISP campaigns were trying to stall.
Third-order effects
- If defaults keep shifting this way, DNS resolution consolidates around a handful of large cloud resolvers chosen by browser vendors rather than access providers — relocating trust (and metadata) from ISPs to browser-and-cloud pairs.
- The ISP lobbying campaign Mozilla flagged in Congress signals a coming regulatory battleground over who controls the network's lookup layer, with the UK's opt-out stance as one model of pushback.
The trend: Browsers are absorbing network-layer functions like DNS from ISPs, shifting default trust from access providers to browser-vendor-chosen cloud resolvers.