<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Doh on Damien Dye&#39;s Blog</title>
    <link>https://blogs.damiendye.uk/en/tags/doh/</link>
    <description>Recent content in Doh on Damien Dye&#39;s Blog</description>
    <generator>Hugo</generator>
    <language>en-GB</language>
    <lastBuildDate>Sun, 27 Sep 2026 09:00:00 +0100</lastBuildDate>
    <atom:link href="https://blogs.damiendye.uk/en/tags/doh/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Resolved: The Resolver You Are Already Running</title>
      <link>https://blogs.damiendye.uk/en/dns/resolved-the-resolver-you-are-already-running/</link>
      <pubDate>Sun, 27 Sep 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/dns/resolved-the-resolver-you-are-already-running/</guid>
      <description>systemd-resolved is on most Linux desktops, caching every lookup and validating none of them. What the stub on 127.0.0.53 does, measured cache figures, turning DNSSEC on, why DNS over TLS works but DNS over HTTPS does not exist, what Fedora, Ubuntu, Debian and RHEL each ship, and why you almost certainly do not need a custom build.</description>
    </item>
    <item>
      <title>DNS Over HTTPS Walks Straight Past Your Controls</title>
      <link>https://blogs.damiendye.uk/en/dns/dns-over-https-walks-past-your-controls/</link>
      <pubDate>Thu, 24 Sep 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/dns/dns-over-https-walks-past-your-controls/</guid>
      <description>DoH sends your DNS lookup to a resolver of the client&amp;#39;s choosing on port 443, which your own resolver never sees, so it cannot block a bad name or log it. Sold as privacy, but DoT gave you that in 2016. What DoH really adds is bypassing the network admin. The mechanism, the malware, who pushed it, the courts now suing the resolvers, and the fix.</description>
    </item>
  </channel>
</rss>
