Skip to content
A name lookup passing through systemd-resolved's stub listener into a cache, a validator and an encrypted transport, with the validator and the encryption switched off

Resolved: The Resolver You Are Already Running

systemd-resolved is running on most Linux desktops right now, caching every lookup and validating none of them. This walks the resolution path from nss-resolve to the two stub listeners, measures what the cache is worth on a real machine, turns DNSSEC on and shows the three verdicts it can return, and explains why validation is off by default when upstream ships it on. Then a census of how little of the web is actually signed, DNS over TLS and its strict-versus-opportunistic trap, and the DNS over HTTPS support that has been requested since 2018 and still does not exist. Ends with what Fedora, Ubuntu, Debian and the RHEL family each ship, how to wire it into each one, and why the features your distro disabled are defaults rather than missing code.

27th September 2026 Β· 38 min Β· 8443 words Β· Damien Dye