| Where Can I Use
This? | What Do I Need? |
You can configure the Advanced DNS Security Resolver to analyze and categorize DNS payloads
contained within encrypted DNS traffic requests to DNS hosts using DoT. DNS over TLS
(DoT) is a security protocol that encrypts DNS queries using TLS over TCP port 853,
preventing eavesdropping and manipulation of DNS traffic between the client and
resolver. DoT is specified in RFC 7858, with operational guidance in RFC 8310.
The Advanced DNS Security Resolver DoT implementation uses the same dedicated domain as DNS
over HTTPS (edge-dns.service.paloaltonetworks.com). The service requires a minimum
of TLS 1.2, with TLS 1.3 preferred. Clients must connect using the domain name —
connecting by server IP address directly is not supported. Mutual TLS (mTLS) is not
supported.