Skip to content
Discussion options

You must be logged in to vote

Abstract

This document provides a technical comparison between DNSCrypt, DNS over TLS (DoT), and DNS over HTTPS (DoH).
While DoT and DoH are standardized by the IETF, DNSCrypt—now also formalized as an IETF draft—continues to demonstrate superior technical properties:

  • No insecure bootstrap procedure
  • Lower latency and higher efficiency, even versus DoH over QUIC
  • No dependence on the global TLS Public Key Infrastructure (PKI)
  • True decentralization (no corporate control)
  • Flexible and extensible protocol design
  • Built-in authenticity and optional anonymization

This paper argues that DNSCrypt remains the most secure, efficient, and independent approach to encrypted DNS, while DoH and DoT suff…

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@mflsim
Comment options

Answer selected by jedisct1
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants