Securing the Missing Link: Encrypted Recursive-to-Authoritative DNS in the Wild
Abstract
DNS resolvers increasingly support various encryption protocols, ensuring their communication with end clients remains confidential. The recursive-to-authoritative link has long been overlooked though, despite multiple reports on traffic analysis and response injection by state censors. The experimental RFC 9539 addresses this confidentiality gap with a unilateral and opportunistic mechanism—recursive resolvers probe nameservers for DNS-over-TLS or DNS-over-QUIC support and, if successful, communicate over the encrypted channel. In this paper, we measure the deployment of RFC 9539 (ADoT/ADoQ, hereafter ADoX) in the wild, covering both recursive resolvers and authoritative nameservers. We identify fewer than 1% (3.1 M) of registered domains supporting ADoX, with one provider accounting for the vast majority of these deployments. Ultimately, our data-driven study informs DNS operators that increasingly consider the adoption of ADoT/ADoQ but lack concrete numbers on the current state of deployment.