Tag
A new DNS TXT record convention, defined by RFC 10023, allows domain owners to signal that their domain is for sale without disrupting their live site, with support for price and contact tags.
This article explains Discovery of Designated Resolvers (DDR), a protocol that lets devices automatically discover encrypted DNS endpoints. It describes how the query works, how resolvers respond, and the limitations of opportunistic upgrades from plain DNS.
A comprehensive technical reference for SPF record syntax per RFC 7208, covering mechanisms, qualifiers, modifiers, macros, and evaluation rules.
Explains what DMARC actually protects against, clarifying its narrow scope relative to SPF and DKIM, and why it is not a spam or phishing filter.
A CipherCue analysis of 67,336 domains finds that 68.4% still do not enforce DMARC, despite the standard being public since 2012, with many domains stuck in monitoring mode due to the difficulty of authenticating all legitimate email sources.
The author red-teamed their sandbox for running untrusted AI code and found that everything held except DNS, indicating a potential vulnerability.
A blog post by Georg Lukas detailing how to set up an authoritative dnsmasq container on a MikroTik RouterOS device for dual use as authoritative DNS and forwarding cache, with considerations for flash storage and container configuration.
This paper proposes ToolDNS, a framework that retrofits semantic tool discovery onto the DNS infrastructure, achieving scalable O(log N) resolution and reducing search space by 95.26% on a benchmark of over 33,000 real-world tools across multiple protocols.
A blog post explaining how to configure SSH to automatically use a bastion host only when the target hostname is not resolvable locally, using the Match directive and getent command.
A heap buffer overflow vulnerability in Dnsmasq (CVE-2026-2291) allows remote code execution via a malicious upstream DNS server. The issue was introduced in version 2.73 and fixed in 2.92rel2 and 2.93.
Vint Cerf is advising Innovation Labs on developing an open standard (DNSid) for identifying and auditing AI agents on the open internet, aiming to create accountability and interoperability as autonomous agents become more prevalent.
Cloudflare explains how they named their name servers (Bob and Lola) to solve a conflict resolution problem during signup and prevent users from adding extra name servers incorrectly.
DNSGlobe is a Rust terminal application that queries 34 DNS resolvers worldwide in parallel to check and display propagation status on a world map, with watch mode for continuous monitoring.
Explains how to enhance VPN disguise by modifying Shadowrocket's DNS and proxy settings to avoid detection by domestic apps and even fool banking apps.
Cloudflare's free 1.1.1.1 + WARP service encrypts and optimizes network connections to improve speed and privacy. It supports all platforms and can be used without registration.
MasterDnsVPN is an open-source project that survived Iran's 99% internet shutdown by routing traffic through DNS queries, evading all firewalls.
A home network investigation reveals a seven-year-old bug in Charter's authoritative DNS that causes the hostname aa.ns.charter.com to resolve to 0.0.0.0, leading to blocked queries in Pi-hole.
Armadillo is a self-hosted DNS server written in Gleam for homelab use. It checks local records first and forwards unknown queries to an upstream resolver, with a configurable zone file and ETS caching.
A guide on setting up your own DNS over HTTPS (DoH) service to enhance privacy and security by encrypting DNS queries.
A comprehensive interactive guide that helps users choose a public DNS resolver based on priorities like privacy, malware blocking, parental controls, speed, and jurisdiction, with a full comparison table and research-backed decision notes.