Skip to content
Book Open access

Securing the Missing Link: Encrypted Recursive-to-Authoritative DNS in the Wild

Oct 2026 · Proceedings of the 2026 ACM Internet Measurement Conference · 1 citation · 74 references

Abstract

DNS resolvers increasingly support various encryption protocols, ensuring their communication with end clients remains confidential. The recursive-to-authoritative link has long been overlooked though, despite multiple reports on traffic analysis and response injection by state censors. The experimental RFC 9539 addresses this confidentiality gap with a unilateral and opportunistic mechanism—recursive resolvers probe nameservers for DNS-over-TLS or DNS-over-QUIC support and, if successful, communicate over the encrypted channel. In this paper, we measure the deployment of RFC 9539 (ADoT/ADoQ, hereafter ADoX) in the wild, covering both recursive resolvers and authoritative nameservers. We identify fewer than 1% (3.1 M) of registered domains supporting ADoX, with one provider accounting for the vast majority of these deployments. Ultimately, our data-driven study informs DNS operators that increasingly consider the adoption of ADoT/ADoQ but lack concrete numbers on the current state of deployment.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.