RFC 8484: DNS over HTTPS
Summary
RFC 8484 encapsulates DNS queries in HTTPS and thereby uses existing web transport and authentication mechanisms. DoH makes path-based observation and classic network diagnostics harder at the same time. Choosing the resolver remains a decision of trust.
Ideas
- DNS messages travel as HTTP requests and responses.
- TLS protects content and server identity.
- HTTP/2 can bundle several queries efficiently.
Remarks
- RFC 8484 has the status “Proposed Standard”; current errata and successor documents should also be checked.
Recommendations
- Document DoH endpoints and failure behaviour.
- Prevent uncontrolled bypassing of operational DNS security functions.
References
Read the RFC at the RFC Editor
Links to the original source and the Web Archive open in a new tab.