The DNS (Domain Name System), sometimes referred to as the “phonebook for the internet,” was first created back in 1983 and has been a critical foundation of the modern internet ever since.
In November 2023, 40 years after the DNS was first proposed, a series of new standards bringing enhanced capabilities to DNS resolution was published by the Internet Engineering Task Force (IETF). The IETF is the organization responsible for internet standards including the DNS. Among the new standards that have been finalized are:
- RFC 9461 on Service Binding Mapping for DNS Servers
- RFC 9462 on Discovery of Designated Resolvers (DDR)
- RFC 9463 on DHCP and Router Advertisement Options for the Discovery of Network-designated Resolvers (DNR)
"These RFCs all came from the Adaptive DNS Discovery (ADD) working group, which is focused on the work of making it safe and easy for clients to get an encrypted connection to send DNS questions over," Shane Kerr, lead engineer at NS1, an IBM company, told SDxCentral.
[Related: IBM releases NS1 Connect to help enterprises optimize DNS connectivity]
How more encryption options are improving DNSFor much of the 40-year history of DNS, a query to a DNS resolver that would match an IP address to a domain name would be sent in the clear, without any form of encryption.
In recent years, as security and privacy concerns have continued to grow about online communications in general, there has been a growing movement to encrypt everything — including DNS queries.
Kerr noted that the IETF has already standardized three different ways a client can use encryption to talk to a DNS resolver including: DNS over TLS (DoT), DNS over HTTPS (DoH) and DNS over QUIC (DoQ).
However, using those approaches today usually requires manual configuration from a user, which is not ideal.
"These new RFCs provide a foundation that will allow your phone, laptop and other devices to automatically use encryption for DNS," Kerr said. "This is a critical step in improving privacy on the internet."
Andrew Campling, director at 419 Consulting, told SDxCentral that the three new IETF standards are important as they collectively allow client software such as browsers to provide far greater choice in the selection of DNS resolvers, including those that support encrypted transports.
"RFC 9461 provides the mapping for the DNS service type, allowing DNS servers to offer alternative endpoints and transports, whereas RFCs 9462 (DDR) and 9463 (DNR) provide endpoints with the capability to discover encrypted resolvers," Campling explained. “This means that endpoints are not reliant on software having resolver details hard-coded into them and should support much greater choice, ultimately benefiting users."
While the new RFCs were only recently finalized, there is also ready support for some of the new standards across vendor services. According to Campling, a range of companies have already announced support for DDR, including Cisco, Microsoft, Apple, Quad9 and Cloudflare.
He noted that support for DNR is less advanced as the implementation has only recently been finalized; however, Microsoft is already testing it in Windows 11 and a number of developers from various organizations including Microsoft, Apple and BT Group successfully demonstrated interoperability during a hackathon at the recent IETF 118 meeting.
DNS at 40: The foundation on which the internet worksThe new RFCs are just one part of continued ongoing efforts to improve DNS.
Campling noted that the IETF community meets in person three times a year and has multiple working groups focused on work related to DNS.
"One area where I would like to see further progress is related to policy rather than technology; specifically, the policies adopted by resolver operators to protect the personal data of users," Campling said. "To that end, I’ve worked with colleagues from across the industry to develop and document best practices in the form of the European Resolver Policy."
Campling added that although the policy is focused on European resolver operators, building on legislation including GDPR, any organization can adopt it.
"Longer term, we need to ensure that the core internet infrastructure remains resilient and diverse, noting that some recent developments have accelerated the trend toward centralization," Campling said.
Life after 40: Challenges remain for DNSIt’s hard to dispute the incredible success of DNS over the last four decades.
"DNS is arguably the most successful database in history," Kerr said. "It has scaled from thousands of computers to billions of computers, and there is no reason that it will not be able to continue to scale as long as needed."
Kerr added that DNS overall is also extremely reliable, both for users and domain holders. That said, there are a few challenges for DNS, since it’s so old. He noted that adoption of critical new technologies such as IPv6 and DNSSEC has been slow. Traditional DNS has terrible privacy implications, which are being addressed, but adoption of improvements in that area are also slow.
[Related: Why IPv6 matters for SD-WAN and why vendors are certifying their products]
"Luckily, work started at the last IETF in Prague and has a chance to improve the pace at which DNS can evolve," Kerr said. "This is not yet in the stage where drafts have even been submitted for review, but ideas and designs are being discussed by interested experts."
Comments