In light of recent ICE/DHS shenanigans in the US
You all don't encrypt your DNS?
DNS over TLS and similar are only encrypted to the first (local) DNS provider, and of course that provider knows the query as well.
It protects against 3rd-party eavesdroppers between you and your primary DNS provider, but does nothing for privacy beyond that.
ODOH could help
Not really, no
in the likely scenario people are using google or cloudflare dns, which is what usually comes by default, i don't think it matters.
No. I don't think the queries from a recursive can be encrypted. Can they?
You all don't encrypt your DNS?
DNS over TLS and similar are only encrypted to the first (local) DNS provider, and of course that provider knows the query as well.
It protects against 3rd-party eavesdroppers between you and your primary DNS provider, but does nothing for privacy beyond that.
ODOH could help
Not really, no
in the likely scenario people are using google or cloudflare dns, which is what usually comes by default, i don't think it matters.
No. I don't think the queries from a recursive can be encrypted. Can they?