alecmuffett / dohot

DoHoT: making practical use of DNS over HTTPS over Tor
BSD 2-Clause "Simplified" License
227 stars 11 forks source link

local DNSSEC validation #4

Open adrelanos opened 2 years ago

adrelanos commented 2 years ago

DoHoT currently doesn't seem to mention and not doing local DNSSEC validation?

DoHoT seems to be based on dnscrypt-proxy which apparently doesn't do local DNSSEC validation. References:

Also cloudflared apparently doesn't do local DNSSEC validation. References:

Thank you for all your work on DNS security!

BTW I am interested in documenting and including it in our security distro: https://www.kicksecure.com/wiki/DNS_Security