<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Dns on Damien Dye&#39;s Blog</title>
    <link>https://blogs.damiendye.uk/en/categories/dns/</link>
    <description>Recent content in Dns on Damien Dye&#39;s Blog</description>
    <generator>Hugo</generator>
    <language>en-GB</language>
    <lastBuildDate>Sun, 27 Sep 2026 18:00:00 +0100</lastBuildDate>
    <atom:link href="https://blogs.damiendye.uk/en/categories/dns/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>DNSSEC: Protecting Your Traffic From Forgery</title>
      <link>https://blogs.damiendye.uk/en/dns/dnssec-the-root-is-signed-you-are-not/</link>
      <pubDate>Sun, 27 Sep 2026 18:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/dns/dnssec-the-root-is-signed-you-are-not/</guid>
      <description>Counted from the live root zone: 1,351 of 1,438 TLDs are signed, every single gTLD among them. Then it stops. 39 of 2,390 live gov.uk domains, 1 of 9 certificate authorities, and windowsupdate.com has no DS at all. What DNSSEC stops, what is really blocking it, and whether the problem is that we still do not understand DNS.</description>
    </item>
    <item>
      <title>Resolved: The Resolver You Are Already Running</title>
      <link>https://blogs.damiendye.uk/en/dns/resolved-the-resolver-you-are-already-running/</link>
      <pubDate>Sun, 27 Sep 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/dns/resolved-the-resolver-you-are-already-running/</guid>
      <description>systemd-resolved is on most Linux desktops, caching every lookup and validating none of them. What the stub on 127.0.0.53 does, measured cache figures, turning DNSSEC on, why DNS over TLS works but DNS over HTTPS does not exist, what Fedora, Ubuntu, Debian and RHEL each ship, and why you almost certainly do not need a custom build.</description>
    </item>
    <item>
      <title>DNS Over HTTPS Walks Straight Past Your Controls</title>
      <link>https://blogs.damiendye.uk/en/dns/dns-over-https-walks-past-your-controls/</link>
      <pubDate>Thu, 24 Sep 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/dns/dns-over-https-walks-past-your-controls/</guid>
      <description>DoH sends your DNS lookup to a resolver of the client&amp;#39;s choosing on port 443, which your own resolver never sees, so it cannot block a bad name or log it. Sold as privacy, but DoT gave you that in 2016. What DoH really adds is bypassing the network admin. The mechanism, the malware, who pushed it, the courts now suing the resolvers, and the fix.</description>
    </item>
    <item>
      <title>Who Actually Controls DNS</title>
      <link>https://blogs.damiendye.uk/en/dns/who-actually-controls-dns/</link>
      <pubDate>Tue, 25 Aug 2026 14:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/dns/who-actually-controls-dns/</guid>
      <description>The root of the internet is a 1.5 MB text file. Who edits it, who signs it, and what ICANN has done with the power to decide what goes in it.</description>
    </item>
    <item>
      <title>What Happened at Nominet</title>
      <link>https://blogs.damiendye.uk/en/dns/what-happened-at-nominet/</link>
      <pubDate>Tue, 25 Aug 2026 13:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/dns/what-happened-at-nominet/</guid>
      <description>The .uk registry is owned by its members. In March 2021 they voted half the board out. This is what the estate looked like from inside, and how a registry with no regulator ended up being disciplined by the only people who could.</description>
    </item>
    <item>
      <title>Samba4 and Securing AD Records Using DNSSEC</title>
      <link>https://blogs.damiendye.uk/en/dns/samba4-securing-ad-records-with-dnssec/</link>
      <pubDate>Mon, 24 Aug 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/dns/samba4-securing-ad-records-with-dnssec/</guid>
      <description>Every domain-joined machine finds its DC by asking DNS for an SRV record, so the _msdcs locators are the most security-critical records you have. Signing them from a Samba4 DC: BIND with dlz_bind9, inline signing, a hidden primary, dynamic updates kept out of the locator zone, then forcing Windows and Linux clients to validate the signatures.</description>
    </item>
  </channel>
</rss>
