Overview PROXYv2 protocol support has been added in the BIND 9.| ISC
DNS zone transfers are transmitted in cleartext, which gives attackers the opportunity to collect the content of a zone by eavesdropping on network connections. The DNS Transaction Signature (TSIG) mechanism is specified to restrict direct zone transfer to authorized clients only, but it does not add confidentiality. This document specifies the use of TLS, rather than cleartext, to prevent zone content collection via passive monitoring of zone transfers: XFR over TLS (XoT). Additionally, this...| IETF Datatracker
DNS over HTTPS Update It has been a long time since our last blog on the BIND 9 DNS-over-HTTPS (DoH) implementation.| www.isc.org