What are DNSSEC, DoT, DoH, and ADoT?



Benefits of using DNSSEC



What Attacks Does DNSSEC Mitigate?


DNSSEC (Domain Name System Security Extensions) helps prevent various DNS-based attacks. Some of the key threats it mitigates include:

What is the Chain of Trust in DNSSEC?


DNSSEC uses a hierarchical "Chain of Trust" to ensure that DNS records are authentic and untampered. It involves:


DNSSEC DS record

DANE for Email Security


DANE (DNS-Based Authentication of Named Entities) enhances email security by ensuring TLS encryption is enforced and validated through DNSSEC.


What Are DoT, DoH, and ADoT?


DNSSEC primarily ensures data integrity, but it does not provide encryption. This is where DoT, DoH, and ADoT come into play.

DNS over TLS (DoT)


DNS over TLS (DoT) encrypts DNS queries using the Transport Layer Security (TLS) protocol, preventing third parties from monitoring or modifying DNS traffic.

- DoT uses port 853 for secure communication.
- DoT encrypts DNS queries, reducing visibility for on-path observers; networks may still infer which resolver you use and see traffic patterns. - Requires DNS resolvers to support TLS, ensuring privacy for DNS lookups.

DNS over HTTPS (DoH)


DNSSEC, DoT, DoH and ADoT diagram
DNS over HTTPS (DoH) performs DNS queries over HTTPS (port 443), making them indistinguishable from regular HTTPS web traffic.

- DoH prevents ISPs and attackers from inspecting DNS queries.
- It enables DNS resolution within web browsers like Firefox and Chrome.
- Offers better privacy but can be harder for enterprises to monitor and filter.

Authenticated DNS over TLS (ADoT)


ADoT diagram
Authenticated DNS over TLS (ADoT) is an enhancement of DoT, where clients authenticate the DNS resolver before establishing a connection.

- ADoT provides mutual authentication, ensuring users connect to a trusted DNS resolver.
- Unlike DoT and DoH, which assume the resolver is trustworthy, ADoT eliminates man-in-the-middle risks.
- Particularly useful for enterprise and high-security environments.

Which One Should You Use?


- Use DNSSEC for integrity (protects against DNS spoofing).
- Use DoT for encrypted DNS queries while keeping compatibility with traditional resolvers.
- Use DoH for enhanced privacy and bypassing network filtering.
- Use ADoT when security and resolver authentication are critical.

If you want to block malicious domains (phishing, malware, C2) at the DNS layer, see also our Protective DNS Firewall (RPZ) platform.


By implementing DNSSEC, DoT, DoH, and ADoT, you can ensure that your DNS infrastructure is secure, private, and resilient against cyber threats.

Contact Us!

Captcha: captcha
Planisys 2025 © All rights reserved.
-->