New Features in September 2026
Focus
Focus
Advanced DNS Security Powered by Precision AI®

New Features in September 2026

Table of Contents

New Features in September 2026

Review the new features and platform changes for Advanced DNS Security in September 2026.

DNS Over TLS Support for Advanced DNS Security Resolver

September 2026
Traditional Domain Name System (DNS) queries are transmitted in plaintext, leaving enterprise networks vulnerable to eavesdropping and manipulation. To strengthen your security posture alongside the existing DNS over HTTPS (DoH) support, the Advanced DNS Security Resolver now supports DNS over TLS (DoT) query processing. DoT encrypts DNS queries using TLS over TCP port 853, as specified in RFC 7858, providing an additional encrypted transport option for organizations that prefer TLS-based DNS encryption over HTTPS-based approaches. This capability is provided through the Advanced DNS Security Resolver service, managed seamlessly through Strata Cloud Manager.
The Advanced DNS Security Resolver DoT implementation uses the same dedicated domain as DoH (edge-dns.service.paloaltonetworks.com) and shares the same server certificate infrastructure. The service requires a minimum of TLS 1.2, with TLS 1.3 preferred. Clients must connect using the domain name — connecting by server IP address directly is not supported. The existing rate-limiting, source IP validation, and policy enforcement based on tenant configuration apply to DoT traffic in the same way as DoH traffic. Both IPv4 and IPv6 are supported for DoT connections.
Support for analysis and categorization of DNS payloads contained within DoT requests is available in campus/branch environments that have been registered as connection sources in Strata Cloud Manager.