Menu

How a device finds encrypted DNS by itself
📰
35

How a device finds encrypted DNS by itself

Reading 0:00
15s threshold

A device is normally configured with a single IP address for its DNS resolver. That address reaches the resolver over plain, unencrypted DNS, which is all a bare IP address can describe. Encrypted DNS requires more: a hostname to check the certificate against, a port, and a protocol. None of that fits in the settings box, and none of it can be worked out from the address already sitting there. DDR, short for Discovery of Designated Resolvers, gives a resolver a way to publish those details to any device already talking to it. How the question works The question is a lookup for _dns.resolver.arpa , a name reserved for this purpose and answered by whichever resolver the device is currently using. It amounts to asking whether an encrypted version exists, and where it can be reached. A resolver that has one replies with the hostname, port, and protocol of each encrypted endpoint it offers, and marks each with a preference.…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More