RFC 7858 · PROPOSED STANDARD · 2016

Specification for DNS over Transport Layer Security

Overview

RFC 7858, “Specification for DNS over Transport Layer Security”, is a Proposed Standard document published in May 2016 by Z. Hu, L. Zhu, J. Heidemann, A. Mankin, D. Wessels, P. Hoffman. It has since been updated by RFC 8310. The canonical text is published by the RFC Editor.

Abstract

This document describes the use of Transport Layer Security (TLS) to provide privacy for DNS. Encryption provided by TLS eliminates opportunities for eavesdropping and on-path tampering with DNS queries in the network, such as discussed in RFC 7626. In addition, this document specifies two usage profiles for DNS over TLS and provides advice on performance considerations to minimize overhead from using TCP and TLS with DNS.

This document focuses on securing stub-to-recursive traffic, as per the charter of the DPRIVE Working Group. It does not prevent future applications of the protocol to recursive-to-authoritative traffic.

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 7858 is hosted at rfc-editor.org. Available in TXT,HTML.

Relationships to other RFCs
Updated by
RFC 8310
Other RFCs from 2016

Who Is Online

In total there are 91 users online: 0 registered, 83 guests and 8 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: AhrefsBot Applebot Bingbot Facebook Googlebot Other Bot SemrushBot Sogou

Users active in the past 15 minutes. Total registered members: 354