DDR (Discovery of Designated Resolvers) enables devices to automatically discover encrypted DNS endpoints by querying the resolver they are already using for the _dns.resolver.arpa record. This allows seamless transition to DoH, DoT, or DoQ with proper certificate validation and profile-specific filtering applied from the first query.
Background
DNS over HTTPS (DoH), DNS over TLS (DoT), and DNS over QUIC (DoQ) are encrypted DNS protocols that improve privacy and security. DDR is an IETF standard mechanism for automatically discovering these encrypted endpoints.
- Source
- Lobsters
- Published
- Aug 7, 2026 at 10:02 PM
- Score
- 6.0 / 10