
4/1/2018 · Ólafur Guðmundsson, Marek Vavruša
What this post added
This post introduces Cloudflare's public recursive DNS resolver, 1.1.1.1, built upon the Knot Resolver. It details the goals of speed, security, and privacy, highlighting features like DNS-over-TLS, DNS-over-HTTPS, Query Minimization (RFC7816), and aggressive negative caching (RFC8198). The post also discusses the use of Cloudflare's global Anycast network, pre-filling caches, and an innovative distributed cache strategy to achieve high performance. It mentions the collaboration with APNIC for IP addresses and the use of DNSSEC validation with a mechanism for handling misconfigurations via 'Negative Trust Anchors'.