3 ms·
Does your local resolver not have to query an upstream provider? Is that recursive query private?
by lftl 7y ago
Does your local resolver not have to query an upstream provider? Is that recursive query private?
- StreamBright 7y agoYou can configure it two ways: - full recursive (meaning you are going to query the root servers and all the other servers until you get your answer) - custom upstream provider who is not a surveillance company The first is as secure as the protocol to use to query. You can use DoT to make it more secure. "DNS over TLS (DoT) is a security protocol for encrypting and wrapping Domain Name System (DNS) queries and answers via the Transport Layer Security (TLS) protocol. The goal of the method is to increase user privacy and security by preventing eavesdropping and manipulation of DNS data via man-in-the-middle attacks." The second case is a bit better when DoT is not available for all the nameservers, using Cloudflare's DNS service as an upstream gives you what you want (it also supports DoT AFAIK). As far as I am concerned DoT is the way to go and the best would be if all DNS servers support that all the way to the root servers and I could run my home service with ad filtering on while other people could just use Cloudflare or whoever they want and not leaking out what they are querying for companies in between. DoH is pointless in my opinion if you have DoT.