… | | | 2 = TLS [ RFC7858 ] | | | | | 3 = DTLS [ RFC8094 ] | | | | | 4 = HTTPS [ RFC8484 ] | | | | | 15 = Non-standard transport (see | | | | | below) | | | | | Values 5-14 are reserved for future | | | | | use. | | | | | Bit 5. 1 if trailing bytes in Query | | | | | packet. See S…
…might also be considered privacy-enabling, such as those running DNS-over-HTTPS RFC8484 or DNS-over-QUIC RFC9250 DNS-over-TLS (DoT): DNS over TLS as defined in RFC7858 and its successors. DNS-over-HTTPS (DoH): DNS over HTTPS as defined in RFC8484 and its successors. DNS-over-QUIC…
… define the way DNS messages can be transmitted over QUIC. DNS over HTTPS (DoH) RFC8484 can be used with HTTP/3 to get some of the benefits of QUIC. However, a lightweight direct mapping for DoQ can be regarded as a more natural fit for both the recursive to authoritative and zon…
…e server IP addresses. However, encrypted DNS mechanisms such as DNS over HTTPS RFC8484 , DNS over TLS/DTLS RFC7858 RFC8094 , and DNS over QUIC RFC9250 provide mechanisms for clients to conceal DNS lookups from network inspection, and many TLS servers host multiple domains on the…
…ht encapsulate DNS messages, which use the "application/dns-message" media type RFC8484 . In creating a new, encrypted media types, specifications might define the use of string "application/dns-message request" (plus a zero byte and the header for the full value) for request enc…
…ch as plaintext client DNS queries or visible server IP addresses. However, DoH RFC8484 and DPRIVE RFC7858 RFC8094 provide mechanisms for clients to conceal DNS lookups from network inspection, and many TLS servers host multiple domains on the same IP address. Private origins may…
…ght also be considered privacy-enabling, such as those running DNS over HTTPS [ RFC8484 ]. . Zones This section defines terms that are used when discussing zones that are being served or retrieved. Zone: "Authoritative information is organized into units called ZONEs, and these z…
…vers and outsider adversaries, see for instance Confidentiality RFC7858 RFC8446 RFC8484 RFC9000 . And RFC6973 discusses associated traffic analysis threats. The focus in this document is on the primary protocol participants, such as a server in a client-server architecture or a s…
…his document does not pursue the use of DNS over HTTPS, commonly called "DoH" ([RFC8484]), in this context because a DoH client needs to know the path part of a DoH endpoint URL. Currently, there are no mechanisms for a DNS recursive resolver to predict the path on its own, in an…
…C4027 dns+json application/dns+json RFC8427 dns-message application/dns-message RFC8484 dots+cbor application/dots+cbor RFC9132 dpop+jwt application/dpop+jwt RFC9449 dskpp+xml application/dskpp+xml RFC6063 dssc+der application/dssc+der RFC5698 dssc+xml application/dssc+xml RFC569…
…C4027 dns+json application/dns+json RFC8427 dns-message application/dns-message RFC8484 dots+cbor application/dots+cbor RFC9132 dpop+jwt application/dpop+jwt RFC9449 dskpp+xml application/dskpp+xml RFC6063 dssc+der application/dssc+der RFC5698 dssc+xml application/dssc+xml RFC569…
… RFC9880 Unassigned 435-552 application/dns-message application/dns-message 553 RFC8484 ][ RFC9953, Section 4.1 Unassigned 554-600 application/uccs+cbor application/uccs+cbor 601 RFC9781, Section 6.4 Unassigned 602-835 application/voucher+cose (TEMPORARY - registered 2022-04-12, …
… RFC9880 Unassigned 435-552 application/dns-message application/dns-message 553 RFC8484 ][ RFC9953, Section 4.1 Unassigned 554-600 application/uccs+cbor application/uccs+cbor 601 RFC9781, Section 6.4 Unassigned 602-835 application/voucher+cose (TEMPORARY - registered 2022-04-12, …
…C4027 dns+json application/dns+json RFC8427 dns-message application/dns-message RFC8484 dots+cbor application/dots+cbor RFC9132 dpop+jwt application/dpop+jwt RFC9449 dskpp+xml application/dskpp+xml RFC6063 dssc+der application/dssc+der RFC5698 dssc+xml application/dssc+xml RFC569…
…C4027 dns+json application/dns+json RFC8427 dns-message application/dns-message RFC8484 dots+cbor application/dots+cbor RFC9132 dpop+jwt application/dpop+jwt RFC9449 dskpp+xml application/dskpp+xml RFC6063 dssc+der application/dssc+der RFC5698 dssc+xml application/dssc+xml RFC569…