Welcome to the DNS Privacy project home page
This site is the home of a collaborative open project to promote, implement and deploy DNS Privacy. The goals of this project include:
- Raising awareness of the issue of DNS Privacy
- Empowering users to take advantage of DNS Privacy tools and resources (client applications, DNS Privacy resolvers)
- Evolving the DNS to support DNS Privacy in particular developing new DNS Protocol standards
- Working towards full support for DNS Privacy in a range of Open Source DNS implementations including: getdns, Unbound, NSD, BIND and Knot (Auth and Resolver)
- Co-ordinating deployment of DNS Privacy services and documenting operational practices
Current contributors to this project include Sinodun IT, NLnet Labs, SalesForce and No Mountain Software.
QUICK START GUIDES
FOR END USERS
- What is the problem? Read up on why DNS Privacy is an issue.
- Clients: Meet 'Stubby' - a experimental DNS Privacy stub resolver for use on client machines.
- Test servers: See information on the current list of DNS Privacy test servers available
FOR OPERATORS
- Implementation status: See the current status of DNS Privacy (using DNS-over-TLS) implementations in various DNS software
- How to run a DNS-over-TLS server: Guides on TLS proxies and key management and tools
- COMING SOON: Guidance on data handling on DNS Privacy servers
See past DNS Privacy work
February 2021
- BIND9 add support for DoH and XoT (XFR-over-TLS) in development release 9.17.10!
- Quad9 public domain name service moves to Switzerland for maximum internet privacy protection
- And becomes the first large scale recursive operator to publishing an RPS: a privacy policy based on RFC8932 (BCP232): Recommendations for DNS Privacy Service Operators: quad9.net/privacy/policy/
- CENTR hold a webinar on deploying DoH
January 2021
- EU NISA Directive may require anyone running a 'DNS privacy service' to register - even if running your own resolver!
- NSA report on use of encrypted DNS - warns against use of third-party DoH resolvers and recommends blocking known DoT/DoH endpoints in many scenarios
- Microsoft confirm Windows 10 21H1 will include DoH
- Mozilla comment period for TRR Consultation extended to 20th Jan
December 2020
Overview of DNS Privacy Status
High level overview of ongoing work on DNS Privacy with monthly updates
DPRIVE Working Group
Catch up with the latest standards being developed to support DNS Privacy: DPRIVE Working group
Reference Material
For a list of useful RFCs, Internet Drafts and presentations see the Reference Material page.
Thanks
Thanks to NLnet Foundation for a donation to support DNS Privacy work. Thanks for past support from Verisign Labs.
Contact
If you are interested in contributing to the project please contact:
- Sara Dickinson (sara@sinodun.com)
- Allison Mankin (allison.mankin@gmail.com)
- Benno Overeinder (benno@NLnetLabs.nl)
JIRA and Bitbucket Access
To submit issues in the issue tracker and contribute to the code repositories create a user account: