DoT (DNS over TLS)

Also known as: DNS-over-TLS

DNS over TLS (RFC 7858) encapsulates DNS queries inside a TLS 1.2+ session on TCP/853, providing confidentiality and integrity between resolver and client. In mobile networks DoT is relevant for UE-to-resolver privacy and for protecting inter-DNS traffic in the packet core, but also complicates lawful interception and DNS-based security controls.

Categories: Core NetworkSecurity ControlsProtocols and Standards

DoT in context

The mobile core carries subscriber sessions, mobility and policy. In 4G it is the EPC (MME, HSS, S/PGW); in 5G it is the Service-Based Architecture with AMF, SMF, UPF, AUSF, UDM and the NRF.

Security controls span signaling firewalls (SS7/Diameter/GTP screening), transport encryption (IPsec, TLS, PRINS), identity and access on OSS/BSS, and monitoring at both packet and log level. Controls are audited against GSMA FS.11/FS.19/FS.20/FS.36.

To place DoT in the wider telecom-security picture, review AES, OpenSSL, N3IWF, TNGF, EAP-AKA′ and SEAF — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.