A System for DNS Over HTTPS Deployment and Security Measurement

Jiayu Chen, Dongjie Liu, Yinyan Zhang, Yong Chen, Guanggang Geng · 2025

DNS over HTTPS (DoH) was standardized in RFC 8484 to protect user privacy by encrypting DNS transmissions. With the growing demand for DNS privacy protection, there is a rising need for standardized and secure DoH services. Previous research has limitations in the coverage and efficiency of large-scale DoH deployment measurements. Additionally, the ability of DoH servers in handling DoH recursive queries from clients has not been thoroughly investigated. Malicious DoH servers can return incorrect resolution results or even redirect users to malicious destinations. Furthermore, invalid TLS certificates of DoH servers could pose fundamental security risks to encrypted communications. In this paper, we propose a DoH deployment and security measurement system to address the aforementioned concerns. The system demonstrates a 32.5 % improvement in large-scale DoH measurement efficiency compared to the state-of-the-art method. The system discovers the largest number of standard DoH servers to date, including 20,853 IPv4 DoH servers and 4,746 IPv6 DoH servers. Notably, response analysis reveals that most DoH servers generate responses with security issues. Only 22.88 % of responses containing domain resolution results, while issues such as malicious resolution results, authoritative-side recursion configuration, recursion unavailable, and incorrect response status are observed. Moreover, the system discovers 2,610 invalid certificates associated with 2,002 DoH servers. The proposed system facilitates the efficient discovery of standard DoH servers and the timely identification of associated security issues.

Read the paper · More papers on PaperTik