If you want to try out DNS-over-TLS then instructions are listed below.

Alternatively

Try DNS-over TLS 

Grab a DNS-over-TLS client tool:

Query a public NSD server patched to support DNS-over-TLS:

Decode in Wireshark

 

  • The starttls.verisign.com zone is signed
  • The verisignlab.com server also supports TCP Fast open, as do both drill and digit.