Bootstrapping TLS Encrypted ClientHello with DNS Service Bindings
RFC 9848, “Bootstrapping TLS Encrypted ClientHello with DNS Service Bindings”, is a Proposed Standard document published in March 2026 by B. Schwartz, M. Bishop, E. Nygren. The canonical text is published by the RFC Editor.
Abstract
To use TLS Encrypted ClientHello (ECH), the client needs to learn the ECH configuration for a server before it attempts a connection to the server. This specification provides a mechanism for conveying the ECH configuration information via DNS, using a SVCB or HTTPS resource record (RR).
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9848 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9849 TLS Encrypted Client Hello
- RFC 9853 Return Routability Check for DTLS 1.2 and 1.3
- RFC 9880 Semantic Definition Format for Data and Interactions of Things
- RFC 9892 Dynamic Link Exchange Protocol Traffic Classification Data Item
- RFC 9893 Dynamic Link Exchange Protocol Credit-Based Flow Control Messages and Data Items
- RFC 9894 Dynamic Link Exchange Protocol Diffserv Aware Credit Window Extension
- RFC 9895 Dynamic Link Exchange Protocol IEEE 802.1Q Aware Credit Window Extension
- RFC 9896 SVG in RFCs