What's new

DNS DoT, DNSSEC with Rebind Protection - Sanity Check.

AStaUK

Occasional Visitor
For home use is there any benefit to having DNSSEC enabled.

Although I currently have it enabled (along with Rebind protection) I feel that maybe it's overkill and has a detrimental effect on my home internet, as an example both Reddit and Amazon can be slower to load, with Reddit quite often failing or being very slow to load images which doesn't occur with DNSSEC off. I realise that having DNSSEC on is a good way to stop some Man in the Middle attacks which is great in the enterprise area but on my home internet connection is this really a scenario I'm likely to face, if anything was happening at the ISP level I'd be in far bigger trouble.
 
With DoT enabled keep DNSSEC disabled. Your upstream provider of choice does DNSSEC validation and you have encrypted communication with their servers. If you have filtering DNS service upstream returning 0.0.0.0 and Rebind protection enabled you will get possible rebind protection attack messages in logs.
 

Latest threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Back
Top