Skip to content
Book Open access

Exploring The Missing Half: A Dual-Perspective Measurement of Encrypted Recursive-to-Authoritative DNS

Oct 2026 · Proceedings of the 2026 ACM Internet Measurement Conference · 0 citations · 49 references

Abstract

RFC 9539 defines a unilateral opportunistic mechanism for deploying encrypted DNS on the recursive-to-authoritative link, yet its real-world deployment and operational behavior remain incompletely characterized. Mapping this ecosystem requires complementary observations of both resolver behavior and authoritative capabilities. In this paper, we present an Internet-scale, dual-perspective measurement of this emerging paradigm. By relating authoritative-side capabilities to resolver-side behavior, we identify operational patterns and potential risks. Our empirical findings reveal three key insights: (i) encrypted authoritative deployment remains concentrated among a small number of hosting providers, while the recursive-to-authoritative DoT egress population is dominated by Google, Quad9, and PCH; (ii) state-management behavior and metadata-protection practices vary across deployments and do not consistently align with RFC 9539's operational guidance; and (iii) current deployment and operational practices can preserve or reintroduce plaintext exposure and leave privacy-relevant traffic metadata observable despite encryption, while slow-request tolerance among tested authoritative servers indicates potential server-side resource pressure from connection holding. Finally, we provide scoped operational recommendations for resolver developers and authoritative DNS operators, alongside directions for protocol refinement.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.