Exploring The Missing Half: A Dual-Perspective Measurement of Encrypted Recursive-to-Authoritative DNS
Abstract
RFC 9539 defines a unilateral opportunistic mechanism for deploying encrypted DNS on the recursive-to-authoritative link, yet its real-world deployment and operational behavior remain incompletely characterized. Mapping this ecosystem requires complementary observations of both resolver behavior and authoritative capabilities. In this paper, we present an Internet-scale, dual-perspective measurement of this emerging paradigm. By relating authoritative-side capabilities to resolver-side behavior, we identify operational patterns and potential risks. Our empirical findings reveal three key insights: (i) encrypted authoritative deployment remains concentrated among a small number of hosting providers, while the recursive-to-authoritative DoT egress population is dominated by Google, Quad9, and PCH; (ii) state-management behavior and metadata-protection practices vary across deployments and do not consistently align with RFC 9539's operational guidance; and (iii) current deployment and operational practices can preserve or reintroduce plaintext exposure and leave privacy-relevant traffic metadata observable despite encryption, while slow-request tolerance among tested authoritative servers indicates potential server-side resource pressure from connection holding. Finally, we provide scoped operational recommendations for resolver developers and authoritative DNS operators, alongside directions for protocol refinement.