How a device finds encrypted DNS by itself
Summary
Provides an in-depth look at DDR (Discovery of Designated Resolvers), a method for devices to obtain encrypted DNS endpoints (DoH, DoT, and DoQ) from their current resolver. It explains the _dns.resolver.arpa query, how resolvers reply with endpoint details and preferences, and the security implications of upgrading from plain DNS. The piece also discusses per-profile behavior, upgrade limitations, and practical deployment notes.