RFC 9539 · EXPERIMENTAL · 2024

Unilateral Opportunistic Deployment of Encrypted Recursive-to- Authoritative DNS

Overview

RFC 9539, “Unilateral Opportunistic Deployment of Encrypted Recursive-to- Authoritative DNS”, is an Experimental document published in February 2024 by D. K. Gillmor, J. Salazar, P. Hoffman. The canonical text is published by the RFC Editor.

Abstract

This document sets out steps that DNS servers (recursive resolvers and authoritative servers) can take unilaterally (without any coordination with other peers) to defend DNS query privacy against a passive network monitor. The protections provided by the guidance in this document can be defeated by an active attacker, but they should be simpler and less risky to deploy than more powerful defenses.

The goal of this document is to simplify and speed up deployment of opportunistic encrypted transport in the recursive-to-authoritative hop of the DNS ecosystem. Wider easy deployment of the underlying encrypted transport on an opportunistic basis may facilitate the future specification of stronger cryptographic protections against more-powerful attacks.

Abstract as published in the RFC, via rfc-editor.org.

What “Experimental” means

Describes a specification that is part of a research or development effort, published so the community can gain experience with it.

Read this RFC

The canonical text of RFC 9539 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.

Other RFCs from 2024

Who Is Online

In total there are 106 users online: 0 registered, 98 guests and 8 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: AhrefsBot Baiduspider Bingbot Facebook Other Bot Other Crawler PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 372