bk99.de entertain the web since 1997

RFC 7858: DNS over TLS

Summary

RFC 7858 describes encrypted DNS transport over TLS between a client and a recursive resolver. Transport encryption protects the path, not against the chosen resolver. Encryption can reduce observation and centralise trust.

Ideas

  • TLS protects queries against passive eavesdropping and tampering on the path.
  • A dedicated port separates DoT from classic DNS.
  • Persistent connections save repeated handshakes.

Remarks

  • RFC 7858 has the status “Proposed Standard”; current errata and successor documents should also be checked.

Recommendations

  • Choose resolvers by privacy and operating model.
  • Monitor certificates, latency and fallback behaviour.

References

Read the RFC at the RFC Editor

Search the Web Archive