bk99.de entertain the web since 1997

RFC 8484: DNS over HTTPS

Summary

RFC 8484 encapsulates DNS queries in HTTPS and thereby uses existing web transport and authentication mechanisms. DoH makes path-based observation and classic network diagnostics harder at the same time. Choosing the resolver remains a decision of trust.

Ideas

  • DNS messages travel as HTTP requests and responses.
  • TLS protects content and server identity.
  • HTTP/2 can bundle several queries efficiently.

Remarks

  • RFC 8484 has the status “Proposed Standard”; current errata and successor documents should also be checked.

Recommendations

  • Document DoH endpoints and failure behaviour.
  • Prevent uncontrolled bypassing of operational DNS security functions.

References

Read the RFC at the RFC Editor

Search the Web Archive