Is DevAddr encrypted?

maybe a stupid question form a newbie but is it possible that DevAddr would be encrypted or it is always in its clear form?

How would the backend servers know which secret key to use for decryption, when they cannot tell which device the packet belongs to?

As an aside, a DevAddr is not unique: How does a network know a received packet is for them?


