DNS over QUIC (DoQ)
¿Qué es DNS over QUIC (DoQ)?
DNS over QUIC (DoQ)A DNS transport (RFC 9250, 2022) that runs DNS queries over QUIC, providing the confidentiality and integrity of DoT/DoH with lower handshake latency, better connection migration, and head-of-line blocking immunity from QUIC.
DNS over QUIC (DoQ), standardized as RFC 9250 in May 2022, is a third privacy-preserving DNS transport alongside DoT (RFC 7858, 2016) and DoH (RFC 8484, 2018). DoQ multiplexes DNS queries over a single QUIC connection, using QUIC's 1-RTT or 0-RTT handshake and its built-in TLS 1.3 encryption. Compared to DoT, DoQ avoids head-of-line blocking by carrying each DNS query in a separate QUIC stream; compared to DoH, it avoids HTTP/2 framing overhead and stays closer to the wire-format DNS that operators are used to. Connection migration (QUIC's ability to survive a client IP change) makes DoQ particularly attractive for mobile clients. Adoption is still mixed — Android resolvers, AdGuard DNS, NextDNS, and several enterprise resolvers support DoQ — but it is part of the broader move to encrypt all DNS traffic. From a security perspective DoQ provides the same confidentiality/integrity properties as DoT/DoH: protects DNS metadata from on-path observers, defeats DNS-injection by ISPs or rogue networks, and pairs with DNSSEC for end-to-end integrity.
● Ejemplos
- 01
An Android 11+ device uses DoQ to its configured Private DNS resolver, benefiting from 0-RTT lookups on already-known servers.
- 02
A privacy-focused resolver such as AdGuard or NextDNS publishes a DoT, DoH, and DoQ endpoint, letting clients pick whichever transport their OS supports.
● Preguntas frecuentes
¿Qué es DNS over QUIC (DoQ)?
A DNS transport (RFC 9250, 2022) that runs DNS queries over QUIC, providing the confidentiality and integrity of DoT/DoH with lower handshake latency, better connection migration, and head-of-line blocking immunity from QUIC. Pertenece a la categoría de Seguridad de red en ciberseguridad.
¿Qué significa DNS over QUIC (DoQ)?
A DNS transport (RFC 9250, 2022) that runs DNS queries over QUIC, providing the confidentiality and integrity of DoT/DoH with lower handshake latency, better connection migration, and head-of-line blocking immunity from QUIC.
¿Cómo funciona DNS over QUIC (DoQ)?
DNS over QUIC (DoQ), standardized as RFC 9250 in May 2022, is a third privacy-preserving DNS transport alongside DoT (RFC 7858, 2016) and DoH (RFC 8484, 2018). DoQ multiplexes DNS queries over a single QUIC connection, using QUIC's 1-RTT or 0-RTT handshake and its built-in TLS 1.3 encryption. Compared to DoT, DoQ avoids head-of-line blocking by carrying each DNS query in a separate QUIC stream; compared to DoH, it avoids HTTP/2 framing overhead and stays closer to the wire-format DNS that operators are used to. Connection migration (QUIC's ability to survive a client IP change) makes DoQ particularly attractive for mobile clients. Adoption is still mixed — Android resolvers, AdGuard DNS, NextDNS, and several enterprise resolvers support DoQ — but it is part of the broader move to encrypt all DNS traffic. From a security perspective DoQ provides the same confidentiality/integrity properties as DoT/DoH: protects DNS metadata from on-path observers, defeats DNS-injection by ISPs or rogue networks, and pairs with DNSSEC for end-to-end integrity.
¿Cómo defenderse de DNS over QUIC (DoQ)?
Las defensas contra DNS over QUIC (DoQ) combinan habitualmente controles técnicos y prácticas operativas, como se detalla en la definición.
¿Cuáles son otros nombres para DNS over QUIC (DoQ)?
Nombres alternativos comunes: DoQ, RFC 9250.
● Términos relacionados
- network-security№ 374
DNS over HTTPS (DoH)
Protocolo que cifra las consultas DNS transportándolas dentro de HTTPS, evitando que un observador en la ruta pueda leer o modificar las búsquedas.
- network-security№ 376
DNS over TLS (DoT)
Protocolo que cifra las consultas DNS dentro de una sesión TLS dedicada, protegiéndolas de escuchas y manipulaciones en la red.
- network-security№ 841
Oblivious HTTP (OHTTP)
An IETF-standardized HTTP-over-HPKE relay protocol (RFC 9458) that decouples client identity from request content by splitting trust between a relay (sees IP, not content) and a gateway (sees content, not IP).
- network-security№ 555
HTTP/3 / QUIC
HTTP/3 (RFC 9114) es la asignacion de HTTP sobre QUIC (RFC 9000), un transporte cifrado basado en UDP que integra TLS 1.3 y multiplexa streams sin bloqueo en cabeza de linea.
- network-security№ 380
DNSSEC
Conjunto de extensiones del DNS que usa firmas digitales para que los resolutores verifiquen la autenticidad e integridad de los registros DNS.
- network-security№ 1279
TLS (Transport Layer Security)
Protocolo criptográfico estandarizado por el IETF que aporta confidencialidad, integridad y autenticación al tráfico entre dos aplicaciones en red.