Encrypted DNS and Protective DNS are being likened to the combination of chocolate and peanut butter, offering enhanced security measures for DNS communication.
Encrypted DNS addresses the vulnerability of communications between DNS stub resolvers and recursive DNS servers by encrypting traffic, preventing snooping and spoofing.
Protective DNS allows administrators to apply policies to prevent the resolution of malicious or suspicious domain names, providing a universal layer of protection for internet-connected devices.
Microsoft has integrated Encrypted DNS and Protective DNS to create a Zero Trust security solution called ZTDNS, which ensures that Windows DNS clients can only query authorized servers and send traffic to vetted destinations.