Traditional Domain Name System (DNS) queries are transmitted in plaintext, leaving
enterprise networks vulnerable to eavesdropping and manipulation. To strengthen your
security posture alongside the existing DNS over HTTPS (DoH) support, the
Advanced DNS Security Resolver now supports DNS
over TLS (DoT) query processing.
DoT encrypts DNS queries using TLS over TCP port 853, as specified in RFC 7858,
providing an additional encrypted transport option for organizations that prefer
TLS-based DNS encryption over HTTPS-based approaches. This capability is provided
through the Advanced DNS Security Resolver service, managed seamlessly through
Strata Cloud Manager.
The Advanced DNS Security Resolver DoT implementation uses the same dedicated domain
as DoH (edge-dns.service.paloaltonetworks.com) and shares the same server
certificate infrastructure. The service requires a minimum of TLS 1.2, with TLS 1.3
preferred. Clients must connect using the domain name — connecting by server IP
address directly is not supported. The existing rate-limiting, source IP validation,
and policy enforcement based on tenant configuration apply to DoT traffic in the same
way as DoH traffic. Both IPv4 and IPv6 are supported for DoT connections.
Support for analysis and categorization of DNS payloads contained within DoT requests
is available in campus/branch environments that have been registered as connection
sources in Strata Cloud Manager.