DNS Privacy
Links
DNS Privacy Project homepage
DPRIVE
getdns
NLnet Labs
Sinodun
The following servers are configured to support TLS on port 1021 and STARTTLS on port 53 for testing purposes.
Open resolver
Hosted by the getdns API implementation project at getdnsapi.net (running a patched version of Unbound):
The zone is named starttls.verisignlabs.com and it has A, AAAA, and TXT records for names from 'A' to 'Z'.
The IP address of the server is currently 173.255.254.151.
Server key file is available to download here: nsd.key
The zone is signed
If you want to decode the DNS packets in Wireshark (use 1.12.1 or later) to get support TLSv1.2
Obtain the server key file
Configure the key in wireshark in Edit->Preferences