Insider Threat Matrix™Insider Threat Matrix™
  • ID: AF029.005
  • Created: 02nd August 2026
  • Updated: 02nd August 2026
  • Contributor: The ITM Team

Unauthorized Encrypted DNS Usage

A subject configures or uses an unauthorized encrypted Domain Name System (DNS) service to prevent organizational infrastructure from observing, recording, filtering, or enforcing domain-resolution activity.

 

Encrypted DNS protocols, including DNS over HTTPS (DoH) and DNS over Transport Layer Security (DoT), protect DNS queries from observation while they travel between the endpoint and the resolver. Although these protocols have legitimate privacy and security applications, their unauthorized use can bypass enterprise DNS servers, DNS filtering, threat-intelligence controls, and domain-level investigative logging.

 

The subject may enable encrypted DNS through browser settings, operating-system configuration, mobile applications, command-line utilities, or third-party resolver software. They may also select a public or personally controlled resolver that is not governed by the organization.

 

This behavior reduces investigators’ ability to determine which domains the subject attempted to access. Network telemetry may show only an encrypted connection to the resolver rather than the individual domain queries conducted through it. Unauthorized encrypted DNS may be used to conceal access to prohibited services, external infrastructure, anonymization platforms, remote-access services, or data-transfer destinations.

 

The use of encrypted DNS alone does not establish improper intent. Investigators should determine whether the resolver was approved, whether organizational DNS controls were deliberately bypassed, and whether the activity coincided with another infringement or anti-forensics behavior.