FINDING · DETECTION
In DNS over HTTPS deployments evaluated across all constrained IoT scenarios, classifiers achieve near-perfect accuracy identifying DNS frames based on IP address features alone — TLS encryption does not prevent DNS traffic identification when the DNS server IP is distinct from data server IPs. DoH provides weaker DNS traffic obfuscation than well-configured DoC in IoT deployments.
From 2026-lenders-secrets-best-not — Secrets Best Not Shared: DNS Privacy Enhancements for the Constrained IoT · Abstract / §6 · 2026 · arXiv preprint
Implications
- Avoid relying on DoH for DNS traffic obfuscation in any deployment where the DNS resolver's IP is distinguishable from other endpoints — consider routing DNS over the same server IP as application data (single-server topology D1/P1).
- For censorship-circumvention proxies that forward DNS, co-locating the DNS resolver on the same IP/port as the proxy data channel eliminates IP-based DNS identification.
Tags
Extracted by claude-sonnet-4-6 — review before relying.