RFC 8094 · EXPERIMENTAL · 2017

DNS over Datagram Transport Layer Security

Overview

RFC 8094, “DNS over Datagram Transport Layer Security”, is an Experimental document published in February 2017 by T. Reddy, D. Wing, P. Patil. The canonical text is published by the RFC Editor.

Abstract

DNS queries and responses are visible to network elements on the path between the DNS client and its server. These queries and responses can contain privacy-sensitive information, which is valuable to protect.

This document proposes the use of Datagram Transport Layer Security (DTLS) for DNS, to protect against passive listeners and certain active attacks. As latency is critical for DNS, this proposal also discusses mechanisms to reduce DTLS round trips and reduce the DTLS handshake size. The proposed mechanism runs over port 853.

Abstract as published in the RFC, via rfc-editor.org.

What “Experimental” means

Describes a specification that is part of a research or development effort, published so the community can gain experience with it.

Read this RFC

The canonical text of RFC 8094 is hosted at rfc-editor.org. Available in TXT,HTML.

Other RFCs from 2017

Who Is Online

In total there are 126 users online: 0 registered, 122 guests and 4 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: AhrefsBot Applebot Other Bot SemrushBot

Users active in the past 15 minutes. Total registered members: 354