16–17 May 2026 Workshop
Edinburgh International Conference Centre
Europe/London timezone

Opportunistic ADoT deployment: The forgotten ‘big win’

16 May 2026, 16:05
15m
Tinto and Moorfoot (Edinburgh International Conference Centre)

Tinto and Moorfoot

Edinburgh International Conference Centre

The Exchange Edinburgh EH3 8EE Scotland
In-Person Standard Presentation Main Session OARC 46 Day 1

Speaker

Sara Dickinson (Sinodun IT)

Description

RFC 9539 - Unilateral Opportunistic Deployment of Encrypted Recursive-to-Authoritative DNS (also known as ‘Blind Probing’) was published over two years ago and amongst the stated goals were:

  1. Protection from passive attackers for recursive-to-authoritative DNS queries.
  2. A road map for gaining real-world experience at scale with encrypted protections of this traffic.
  3. A bridge to some possible future protection against a more powerful attacker.

Sadly however, it has seen only limited deployment - whilst some open resolvers have adopted it, most authoritative operators are reluctant to do so due to significant operational and performance concerns. As a result, none of the above goals are being fully realised and the real-world experience at scale with encrypted transports has not progressed. The ‘big win’ of shifting as much recursive-to-auth traffic as possible to use at least opportunistic encryption seems stalled at present.

In this presentation we will drill into several related issues:

  1. What are the specific factors preventing adoption of encrypted transports by authoritative servers today and what solutions should the community consider?

  2. What do the criteria look like for establishing encrypted transports as a feasible and scalable solution?

  3. What positive steps can we take to encourage experimentation with and confidence building around encrypted transports today? Can the community create a new roadmap to de-risk encrypted transport deployment and drive future adoption?

  4. How can we better harmonize opportunistic deployment in the existing namespace with future developments to provide the maximum privacy benefit to users?

Talk duration 10 Minutes (+5 for Q&A)

Primary author

Sara Dickinson (Sinodun IT)

Co-authors

Joe Abley (Cloudflare) Johan Stenstam (Swedish Internet Foundation) Leon Fernandez (The Swedish Internet Foundation) Philip Homburg (NLnet Labs)

Presentation materials

There are no materials yet.