<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Protective-Dns on Damien Dye&#39;s Blog</title>
    <link>https://blogs.damiendye.uk/en/tags/protective-dns/</link>
    <description>Recent content in Protective-Dns on Damien Dye&#39;s Blog</description>
    <generator>Hugo</generator>
    <language>en-GB</language>
    <lastBuildDate>Thu, 24 Sep 2026 09:00:00 +0100</lastBuildDate>
    <atom:link href="https://blogs.damiendye.uk/en/tags/protective-dns/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>DNS Over HTTPS Walks Straight Past Your Controls</title>
      <link>https://blogs.damiendye.uk/en/dns/dns-over-https-walks-past-your-controls/</link>
      <pubDate>Thu, 24 Sep 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/dns/dns-over-https-walks-past-your-controls/</guid>
      <description>DoH sends your DNS lookup to a resolver of the client&amp;#39;s choosing on port 443, which your own resolver never sees, so it cannot block a bad name or log it. Sold as privacy, but DoT gave you that in 2016. What DoH really adds is bypassing the network admin. The mechanism, the malware, who pushed it, the courts now suing the resolvers, and the fix.</description>
    </item>
  </channel>
</rss>
