为何Google和CloudFlare的DNS-over-HTTPS不支持返回DNSSEC的DS RRSIG?
Why Google and Cloudflare's
DoH APIs Omit DS RRSIG Records Great question—this is a tricky one since neither provider has publicly detailed their reasoning, even after direct outreach. Let’s break down some plausible technical and operational angles that might explain why the DS RRSIG field is intentionally excluded from their responses:
- TLS layer redundancy: When using
DoH, the connection itself is secured via TLS. For most clients, the established HTTPS trust chain already verifies the resolver’s authenticity, making direct validation of theDS RRSIGredundant. Including this field would add unnecessary payload size without providing meaningful additional security for typical use cases. - Resolver-side validation optimization: Google and Cloudflare’s resolvers perform full
DNSSECvalidation internally. Since they’ve already verified theDS RRSIGas part of their own resolution process, passing this raw signature data along to clients isn’t required—clients relying on the resolver’s validated results don’t need the signature to confirm validity. - Performance and scalability: Both providers handle millions of
DoHqueries per second. Omitting non-essential fields likeDS RRSIGhelps keep response payloads lean, reducing bandwidth usage and improving overall query throughput for their global resolver networks. - Client compatibility: Some simpler
DoHclients may not properly parse or handleDS RRSIGrecords, leading to unexpected errors or unnecessary validation overhead. Excluding the field could be a deliberate choice to ensure broader compatibility across a wide range of client implementations.
It’s definitely frustrating that we don’t have an official answer from either team, but these are the most logical hypotheses based on DNSSEC and DoH best practices.
内容的提问来源于stack exchange,提问作者Paul Shapiro
相关产品推荐
相关产品推荐

