Google has added support for the DNS-over-HTTP / 3 (DoH3) protocol in Android 11 and later versions to increase the privacy of DNS queries while providing better performance.
HTTP /3 is the third major version of the Hypertext Transfer Protocol, which is based on QUIC, a multiplexing transport protocol based on UDP, instead of TCP like previous versions.
The new DNS-over-HTTP/3 protocol fixes the «line blocking» problem, which slows down internet data transactions when a packet is lost or retransmitted, something quite common when moving with mobile devices and frequently changing connections.
Android previously supported DNS-over-TLS (DoT) for version 9 to enhance the privacy of DNS queries, but this system inevitably slowed down DNS requests due to the overhead of encryption.
Additionally, DoT requires a full renegotiation of the new connection when changing networks. In contrast, QUIC can continue an uninterrupted connection in a single RTT (the time required for a signal to reach its destination).
See also: Google Photos for web: Shows the backup quality of each image
With DoH3, many of the performance burdens of DoT are gone, and according to Google's measurements, a 24% performance increase for average query times. In some cases, Google has seen performance increases of up to 44%.

Additionally, DoH3 can help with unreliable networks, even outperforming traditional DNS thanks to proactive flow control mechanisms that immediately generate packet delivery failure notifications instead of waiting for timeouts to exceed.
DNS -over-HTTPS is already widely supported by many DNS providers to provide increased privacy when performing DNS requests.
With Google supporting DNS-over-HTTP/3 for Android and DNS-over-QUIC now as the recommended standard, we will likely see increased adoption from DNS soon.
However, as part of the launch of this feature, Android devices will use Cloudflare DNS and Google Public DNS, which already support DNS-over-QUIC.
In the future, Google plans to add support for other DoH3 providers through the use of Discovery of Designated Resolvers (DDR), which automatically selects the best provider for any given configuration.
See also: Google Authenticator: Backtracks and removes 'Click to reveal PIN'
Another point of excellence of DNS-over-HTTP/3 is the use of Rust in its implementation, which led to a lean system consisting of 1,640 lines of code that uses a single runtime thread instead of the four that DoT has.

"We built the query engine using the async framework Tokio to handle new requests, incoming packet events, control signals, and timers simultaneously. In C++, this would likely require multiple threads or a carefully crafted event loop." - Google.
The result is an efficient low‑level system with few dependencies, it is lightweight and uses a memory‑safe language that reduces the number of bugs that attackers can exploit.
At the moment you are reading this article, all Android devices running Android 11 and later versions should use DNS-over-HTTP/3 for Google DNS and Cloudflare DNS (more will be added soon).
Additionally, a subset of Android 10 devices, whose vendors adopted Google Play, will also receive this new feature.
End users do not need to take any action to enable the new feature, as Android will handle this part automatically.
Source: bleepingcomputer.com
