Encrypted DNS (DoH) inside the engine, so your network cannot see which sites you look up
The Settings screen has offered an Encrypted DNS resolver dropdown for a while, but it was cosmetic: the engine still asked the operating system to resolve every hostname, in the clear, so anyone on your network (or your ISP) could watch the list of sites you visit even when the pages themselves are encrypted. This release makes that dropdown real. The engine now performs DNS-over-HTTPS (RFC 8484) itself: it builds a DNS query, sends it to your chosen provider over TLS, and reads the answer back, so the lookups are encrypted and indistinguishable from ordinary HTTPS traffic. It is built like the rest of the stack, hand-written with no new dependencies, and it bootstraps to each provider by a curated anycast IP so it never needs a plaintext lookup to FIND the resolver. a no-logs default and other well-known resolvers are wired; any failure falls back to the OS resolver so a page never fails to load because of DoH. Proven live against a real resolver. This closes the scorecard caveat that there was no DoH inside the engine itself. Networking moves 53 to 54 and Security 38 to 39; overall holds at 52.