OpenNIC, DNSCrypt and DNSSEC

Discuss securing DNS servers and threats/attacks.
Postby Simon »

Hi all,
Lately I have been looking and securing my DNS requests by means of DNSCrypt and DNSSEC and would have a few questions/remarks

According to its Wikipedia page

In addition to private deployments, the DNSCrypt protocol has been adopted by several public DNS resolvers, the vast majority being members of the OpenNIC network, as well as virtual private network (VPN) services.

Yet, on what seem to serve as central repository listing DNSCrypt enabled resolver, I was surprised to find only 3 entries (ipv4), two being Fusl anycast servers and one from TurmaBox.

Is that correct? OpenNIC does have extra DNSCrypt servers, doesn't it?
Side remark, Fusl server (OpenNIC in general) do (should) resolve .bit domains while listed as not

I could not find any OpenNIC servers being DNSSEC aware, will the be implemented at some point in time?

Re: OpenNIC, DNSCrypt and DNSSEC

Postby verax »

The OpenNIC servers list shows which servers support DNSCrypt: (yellow flag)

Any DNS server that has been updated in the last 5 years is DNSSEC _aware_, but DNSSEC validating is a different story. Currently I'm not aware of anywhere that lists ones that do validation, if any even do.

