On Thu, Apr 03, 2014 at 03:04:22PM +0100,
 Tony Finch <[email protected]> wrote 
 a message of 23 lines which said:

> If (big if) you trust the resolver then you have the advantage of
> hiding your iteratve queries in the aggregate behaviour of the
> resolver's other users,

You can have your cake and eat it: run your own resolver and forward
the uncached queries to a shared resolver (your IAP's or Google Public
DNS, as you wish). This is automatically done by the excellent tool
dnssec-trigger, which probes the shared resolver before using it in
forwarding.

Because of the local resolver, you will send less info to the shared
resolver. Because of the shared resolver, you will send less info to
the authoritative name servers. 

_______________________________________________
dns-privacy mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dns-privacy

Reply via email to