All Products
Search
Document Center

Alibaba Cloud DNS:DNS over HTTPS (DoH)

Last Updated:Aug 28, 2026

Alibaba Cloud HTTPDNS provides RFC 8484-compliant DNS resolution over a TLS-encrypted HTTPS connection, which is ideal for use cases like browsers.

Get the DoT/DoH endpoint

  1. Go to Alibaba Cloud DNS - HTTPDNS.

  2. On the Access Configuration tab, select Method 3: DoT/DoH-based access.

  3. DoT/DoH supports two access methods: short address and custom encrypted address.

    Important

    For higher security, we recommend that you use encrypted address.

  4. Click Add an encrypted URL. In the dialog box, enter a custom string to generate a unique endpoint.

  5. Turn on the switch to enable the encrypted endpoint.

    Warning
    • To stop using DoH to access HTTPDNS, turn off the switch.

    • Use the service suspension feature with caution. After the service is suspended, your account is downgraded to a free user. Billing stops, and console reports and other features become unavailable. Your HTTPDNS service will no longer be covered by an SLA and will be subject to throttling and query rejection.

    • If you restart a suspended service, your original configuration is restored and billing resumes.

DoH for end users

Assume that your DoH endpoint is https://5***4-2h*****ynx3tls.alidns.com/dns-query.

This section shows how to configure DoH in Chrome.

  1. Open Chrome and go to Settings.

  2. In the search box, enter "DNS", and in the search results, click the expand arrow to the right of Security.

  3. Scroll to the bottom of the page. Find the Advanced section and turn on Use secure DNS. Then, enter https://5***4-2h*****ynx3tls.alidns.com/dns-query in the Custom box.

DoH service for developers

Developers must generate a DoH HTTP request according to the standards in RFC 8484 and send it to the DoH service address.

DoH can use both the GET and POST methods. When the POST method is used, the DNS query message is included in the message body of the HTTP request. When the GET method is used, a single variable named "dns" is assigned the base64url-encoded content of the DNS request.

Code examples (Python and Golang)

To initiate a DoH query using the GET method, the binary DNS message is first base64url-encoded to obtain the DNS query parameter. This parameter is used to construct the complete DoH HTTP URL, which is then sent via an HTTP request to retrieve the DNS response message.

  • The following Python code shows how developers can use DoH to query the domain alibaba.com.

    import dns.message
    import requests
    import base64
    import json
    doh_url = "https://5***4-2h*****ynx3tls.alidns.com/dns-query"
    domain = "alibaba.com"
    rr = "A"
    result = []
    message = dns.message.make_query(domain, rr)
    dns_req = base64.urlsafe_b64encode(message.to_wire()).decode("UTF8").rstrip("=")
    r = requests.get(doh_url + "?dns=" + dns_req,
                     headers={"Content-type": "application/dns-message"})
    for answer in dns.message.from_wire(r.content).answer:
        dns = answer.to_text().split()
        result.append({"Query": dns[0], "TTL": dns[1], "RR": dns[3], "Answer": dns[4]})
        print(json.dumps(result))

    The output is as follows:

    $ python test_doh.py
    [{"Answer": "106.11.XXX.XXX", "Query": "alibaba.com.", "RR": "A", "TTL": "133"}]
  • The following Go code shows how developers can use DoH to query the domain alibaba.com.

    package main
    import (
            "encoding/base64"
            "fmt"
            "github.com/miekg/dns"
            "io/ioutil"
            "net/http"
            "os"
    )
    func main() {
           query := dns.Msg{}
           query.SetQuestion("www.taobao.com.", dns.TypeA)
           msg, _ := query.Pack()
           b64 := base64.RawURLEncoding.EncodeToString(msg)
           resp, err := http.Get("https://5***4-2h*****ynx3tls.alidns.com/dns-query?dns=" + b64)
           if err != nil {
                fmt.Printf("Send query error, err:%v\n", err)
                os.Exit(1)
           }
           defer resp.Body.Close()
           bodyBytes, _ := ioutil.ReadAll(resp.Body)
           response := dns.Msg{}
           response.Unpack(bodyBytes)
           fmt.Printf("Dns answer is :%v\n", response.String())
    }

    The output is as follows:

    Sent Get query https://dns.alidns.com/dns-query?dns=xzEBAAABAAAAAAAAA3d3dwZ0YW9iYW8DY29tAAABAAE
    Dns answer is :;; opcode: QUERY, status: NOERROR, id: 5***3
    ;; flags: qr rd ra; QUERY: 1, ANSWER: 3, AUTHORITY: 0, ADDITIONAL: 1
    ;; QUESTION SECTION:
    ;www.taobao.com.        IN       A
    ;; ANSWER SECTION:
    www.taobao.com. 15      IN      CNAME   www.taobao.com.danuoyi.tbcache.com.
    www.taobao.com.danuoyi.tbcache.com.     15      IN      A       221.229.XXX.XXX
    www.taobao.com.danuoyi.tbcache.com.     15      IN      A       221.229.XXX.XXX
    ;; ADDITIONAL SECTION:
    ;; OPT PSEUDOSECTION:
    ; EDNS: version 0; flags: ; udp: 4096