Rendered at 03:26:27 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
WarOnPrivacy 3 hours ago [-]
a lookup for _dns.resolver.arpa, a name reserved for ... asking whether an encrypted version exists, and where it can be reached
Neat! Let's try: nslookup _dns.resolver.arpa
[mine] unblound.lan can't find _dns.resolver.arpa: Non-existent domain
[1.1.1.1] can't find _dns.resolver.arpa: Non-existent domain
[8.8.8.8] No internal type for both IPv4 and IPv6 Addresses (A+AAAA)
records available for _dns.resolver.arpa
[9.9.9.9] Name: _dns.resolver.arpa
ButlerianJihad 3 hours ago [-]
You have asked the wrong question. This standard does not describe an “A” or “AAAA” record. Use the "-query" option to nslookup(1). Or, use dig(1).
running my own resolver as system DNS i can confirm apple devices fire _dns.resolver.arpa on every network join, but since verified DDR needs a TLS cert covering the resolver's IP it's effectively public-resolver-only, so for a LAN resolver the right move is just answering NODATA instead of leaking the query upstream.
Neat! Let's try: nslookup _dns.resolver.arpa
https://datatracker.ietf.org/doc/html/rfc9462#name-discovery...
This is a proposed standard. The reserved domain is very new. Widespread deployment is not expected or mandatory.
I figured it was something like that.