

Your ISP can see what websites you visit. But even if you change DNS server it can still see that if you don’t use either a VPN or DoH/DoT.
So it’s a good idea to use DoH or DoT. It’s an improvement but it’s far from perfect because the DNS server you’ll pick will see what site you visit, you have to trust them. And your ISP still has other ways to see which site you visit.




Yes, that’s why I ended with:
Even with secure DNS they can still see the domain name with the SNI, which is probably more reliable than an IP address. Last I checked very few websites used ECH. I would still argue that it’s better to have encrypted DNS requests than non-encrypted ones.