DoH no!
As was entirely predictable DNS-over-HTTPS has now been implicated in a spam campaign. Google DoH instance was used to access TXT records to control the spam campaign via a bit of javascript on web pages. This isn’t a weakness in DNS or for that matter in DoH, it’s just using Googles DoH as a side channel. They could have achieved the same thing by accessing a specific web page, but that would be more easily blocked or shut down. There are also mobile application, both IOS and android, that are using DoH by default without giving the user a choice in the matter*. At this point if you use DNS as part of your security posture – either via RPZ, pi-hole or some other mechanism ( and if you aren’t you really should ) then you need to be blocking DoH. At present there are over 70 advertised public DoH… Continue reading