DNS over TLS

From Wikipedia, the free encyclopedia
Jump to navigation Jump to search

DNS over TLS (DoT) is a security protocol for encrypting and wrapping Domain Name System (DNS) queries and answers via the Transport Layer Security (TLS) protocol. The goal of the method is to increase user privacy and security by preventing eavesdropping and manipulation of DNS data via man-in-the-middle attacks.

DNS over TLS is covered by two Standards Track IETF RFCs: RFC 7858 and RFC 8310.[1][2] As of 2018, Cloudflare, Quad9, Quadrant Information Security and CleanBrowsing are providing public DNS resolver services via DNS over TLS.[3][4][5][6] In April 2018, Google announced that Android P will include support for DNS over TLS.[7] DNSDist, from PowerDNS also announced support for DNS over TLS in its latest version 1.3.0.[8] BIND users can also provide DNS over TLS by proxying it through stunnel.[9] Technitium DNS Server has announced support for DNS over TLS in its latest version 1.3.[10] Unbound supports DNS over TLS since 22 January 2018.[11][12]

DNS over TLS - Public DNS Servers

DNS over TLS server implementations are already available for free by some public DNS providers.[6] Three implementations are offering production services:

Provider IPs Blocking Domain Features
No cloudflare-dns.com DNS over TLS on port 853.[13] DNSSEC validation
Malicious domains dns.quad9.net DNS over TLS on port 853.[14] DNSSEC validation
Adult content family-filter-dns.cleanbrowsing.org DNS over TLS on port 853.[15] DNSSEC validation
Malicious domains security-filter-dns.cleanbrowsing.org DNS over TLS on port 853.[15] DNSSEC validation
Quadrant Information Security
No dns-tls.qis.io DNS over TLS on port 853.[16] DNSSEC validation

See also

External links

  • DNS Privacy Project: dnsprivacy.org


  1. ^ Duane, Wessels; John, Heidemann; Liang, Zhu; Allison, Mankin; Paul, Hoffman. "Specification for DNS over Transport Layer Security (TLS)". tools.ietf.org. Retrieved 2018-04-08.
  2. ^ Tirumaleswar, Reddy; Daniel, Gillmor; Sara, Dickinson. "Usage Profiles for DNS over TLS and DNS over DTLS". tools.ietf.org. Retrieved 2018-04-09.
  3. ^ "How to keep your ISP's nose out of your browser history with encrypted DNS". Ars Technica. Retrieved 2018-04-08.
  4. ^ "DNS over TLS - Cloudflare Resolver". developers.cloudflare.com. Retrieved 2018-04-08.
  5. ^ "Quad9, a Public DNS Resolver - with Security". RIPE Labs. Retrieved 2018-04-08.
  6. ^ a b "Troubleshooting DNS over TLS".
  7. ^ "DNS over TLS support in Android P Developer Preview". Google Security Blog. April 17, 2018.
  8. ^ "DNS-over-TLS". dnsdist.org. Retrieved 25 April 2018.
  9. ^ "Bind - DNS over TLS".
  10. ^ "Configuring DNS Server For Privacy & Security". blog.technitium.com. Retrieved 2018-07-19.
  11. ^ "Unbound version 1.7.3 Changelog".
  12. ^ Aleksandersen, Daniel. "Actually secure DNS over TLS in Unbound". Ctrl blog. Retrieved 2018-08-07.
  13. ^ "CloudFlare - DNS over TLS".
  14. ^ "Quad9 - DNS over TLS".
  15. ^ a b "CleanBrowsing - DNS over TLS".
  16. ^ "Quadrant - DNS over TLS".

Retrieved from "https://en.wikipedia.org/w/index.php?title=DNS_over_TLS&oldid=867095486"
This content was retrieved from Wikipedia : http://en.wikipedia.org/wiki/DNS_over_TLS
This page is based on the copyrighted Wikipedia article "DNS over TLS"; it is used under the Creative Commons Attribution-ShareAlike 3.0 Unported License (CC-BY-SA). You may redistribute it, verbatim or modified, providing that you comply with the terms of the CC-BY-SA