The Advanced DNS Security Resolver implementation supports both binary and JSON
formats through GET and POST endpoints, following RFC standards and operating over
HTTP/1.1 and HTTP/2. The service is accessed through a static domain
(https://edge-dns.service.paloaltonetworks.com/dns-query) and authenticates users
through the source IP validation for campus/branch users connecting directly. This
architecture protects sensitive DNS traffic from interception while maintaining
compatibility with existing DNS infrastructure, with built-in security measures
including rate limiting, token validation, and policy enforcement based on tenant
configuration.