Rendered at 11:18:28 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
Utilera 6 hours ago [-]
A device that only exposes an IP field can use DDR without extra user configuration, but it still has to implement DDR and an encrypted DNS protocol in the first place...
WarOnPrivacy 11 hours ago [-]
a lookup for _dns.resolver.arpa, a name reserved for ... asking whether an encrypted version exists, and where it can be reached
Neat! Let's try: nslookup _dns.resolver.arpa
[mine] unblound.lan can't find _dns.resolver.arpa: Non-existent domain
[1.1.1.1] can't find _dns.resolver.arpa: Non-existent domain
[8.8.8.8] No internal type for both IPv4 and IPv6 Addresses (A+AAAA)
records available for _dns.resolver.arpa
[9.9.9.9] Name: _dns.resolver.arpa
ButlerianJihad 11 hours ago [-]
You have asked the wrong question. This standard does not describe an “A” or “AAAA” record. Use the "-query" option to nslookup(1). Or, use dig(1).
running my own resolver as system DNS i can confirm apple devices fire _dns.resolver.arpa on every network join, but since verified DDR needs a TLS cert covering the resolver's IP it's effectively public-resolver-only, so for a LAN resolver the right move is just answering NODATA instead of leaking the query upstream.
Neat! Let's try: nslookup _dns.resolver.arpa
https://datatracker.ietf.org/doc/html/rfc9462#name-discovery...
This is a proposed standard. The reserved domain is very new. Widespread deployment is not expected or mandatory.
I figured it was something like that.