TLS in Recursor Mode?

Hi,

to answer this question: No, using DNS over TLS does not work while running in recursor mode.

It is neither being standardised nor an easy task to implement: Running a full recursive resolver requires DNS queries to nameservers you don’t even know about before a user is making a DNS query. That way, there is no way to establish a trusted TLS connection (since you have no FQDN/SNI information at hand). Worse, plenty of nameservers will not be reachable via TLS - but opportunistically falling back to plain text introduces performance issues and contradicts the security intention.

To cut it short: Sorry, DoT is not possible in recursive mode.

Thanks, and best regards,
Peter Müller

1 Like