This table lists the current status of DNS-over-TLS related features in the latest stable releases of a selection of commonly used DNS software.
Client - Stub
Client - Recursive
|Server - Recursive||Server - Auth|
|Port based TLS||2015||2015|
|TCP fast open**||2015|
Most of the implementations above use only the STARTTLS/CH/TXT query text to negotiate the upgrade to TLS by default (the TO bit proposed in the draft in NOT used since it is not assigned by IANA, but may be available as an option in some implementations).
* getdns uses libunbound in recursive mode
** available on linux only
*** Pipelining and OOOP are not applicable for synchronous applications