ADoX in the Wild

Measuring the deployment of encrypted recursive-to-authoritative DNS (RFC 9539)

See the deployment statistics

Latest news

April 9, 2026

We added the ADoX deployment statistics for March 2026.

Our measurements are performed monthly and updates will be published on this website.

April 2, 2026

This website is up, welcome!

Deployment statistics

Last updated: June 15, 2026

As of May 2026, 2 root server operators (B, H), 5 top-level domains (.gr, .kg, .arpa, .ελ, .cy), and 3,164,119 registered domains support some form of ADoX. This deployment is driven by 4 nameserver IPs at the root level, 12 at the TLD level, and 2,682 NS IPs across registered domains.

Our measurements are performed once per month. We gather a comprehensive list of domains from various sources, including the IANA root zone database of top-level domains, ICANN CZDS, passive DNS, CT logs, and zone transfers. We use zdns to map domain names to NS records, followed by A/AAAA requests to get nameserver IPs. Next, we attempt to establish ADoT and ADoQ connections with each nameserver, disabling certificate validation (as allowed by the RFC 9539). Once we identify the nameservers supporting encryption, we resolve all the domains they are authoritative for over the supported encrypted channel. We define a domain name ADoX-enabled if at least one of its nameservers returns the NOERROR DNS response to our SOA query sent over ADoT or ADoQ.

Below we aggregate biggest ADoX nameservers by their suffix, for example, ns1.one.com, ns2.one.com, and ns3.one.com are represented as *.one.com. Note that a single operator can use multiple suffixes, e.g., wedos.cz and wedos.eu.

# Operator ADoT domains Operator ADoQ domains
1. *.one.com 1,423,067 *.one.com 1,423,067
2. *.timeweb.ru 406,331 *.hostnet.nl 401,777
3. *.timeweb.org 406,293 *.wedos.eu 233,829
4. *.hostnet.nl 401,777 *.wedos.cz 233,690
5. *.wedos.eu 274,088 *.wedos.com 233,647
6. *.wedos.cz 274,041 *.g1-dns.com 83,130
7. *.wedos.com 273,864 *.g1-dns.one 83,130
8. *.nazwa.pl 147,073 *.antagonist.net 43,782
9. *.jino.ru 100,825 *.antagonist.nl 43,782
10. *.g1-dns.com 83,130 *.desec.org 15,321
11. *.g1-dns.one 83,130 *.agonet.it 2,953
12. *.namebay.com 71,573 *.ipandmore.net 2,627
13. *.antagonist.net 43,782 *.ipandmore.hosting 2,627
14. *.antagonist.nl 43,782 *.ipandmore.cloud 2,627
15. *.webhosting.dk 22,857 *.ipandmore.email 2,627
16. *.webspacecontrol.com 20,355 *.aspnix.com 1,449
17. *.mywebtonet.com 17,971 *.x4w.net 1,400
18. *.desec.org 15,313 *.rhx.info 1,398
19. *.iq.pl 14,901 *.rollernet.us 897
20. *.glbns.com 14,584 *.asiainfo.kg 769

The table below shows the highest-ranked ADoX domains according to the Tranco list. As of May 2026, Tranco contains 5,646 ADoT and 1,690 ADoQ domains.

Rank ADoT domain Rank ADoQ domain
5. facebook.com 105. root-servers.net
11. instagram.com 160. one.one
14. fbcdn.net 1968. yasyadong.tv
27. wikipedia.org 2131. one.com
34. whatsapp.net 3550. archive-it.group
53. whatsapp.com 4342. eu.org
69. wa.me 4539. i-fourc.com
90. cdninstagram.com 6255. sport1.de
105. root-servers.net 8008. digitalaudience.io
129. cdn77.org 9466. hostnet.nl

Domains

We set up two domains - dot.adox-deployment.com and doq.adox-deployment.com - with nameservers that support ADoT or ADoQ. The easiest way to test how it works is with kdig. Below is the ADoT example:

$ kdig @91.98.28.152 dot.adox-deployment.com +tls +norec

;; TLS session (TLS1.3)-(ECDHE-X25519)-(RSA-PSS-RSAE-SHA256)-(AES-256-GCM)
;; ->>HEADER<<- opcode: QUERY; status: NOERROR; id: 14208
;; Flags: qr aa; QUERY: 1; ANSWER: 1; AUTHORITY: 0; ADDITIONAL: 1

;; EDNS PSEUDOSECTION:
;; Version: 0; flags: ; UDP size: 1232 B; ext-rcode: NOERROR
;; EDE: 0 (Other): 'This is a test ADoT nameserver'

;; QUESTION SECTION:
;; dot.adox-deployment.com.		IN	A

;; ANSWER SECTION:
dot.adox-deployment.com.	60	IN	A	65.21.183.116

And the ADoQ domain:

$ kdig @91.98.27.230 doq.adox-deployment.com +quic +norec

;; QUIC session (QUICv1)-(TLS1.3)-(ECDHE-X25519)-(RSA-PSS-RSAE-SHA256)-(AES-256-GCM)
;; ->>HEADER<<- opcode: QUERY; status: NOERROR; id: 0
;; Flags: qr aa; QUERY: 1; ANSWER: 1; AUTHORITY: 0; ADDITIONAL: 1

;; EDNS PSEUDOSECTION:
;; Version: 0; flags: ; UDP size: 1232 B; ext-rcode: NOERROR
;; EDE: 0 (Other): 'This is a test ADoQ nameserver'

;; QUESTION SECTION:
;; doq.adox-deployment.com.		IN	A

;; ANSWER SECTION:
doq.adox-deployment.com.	60	IN	A	65.21.183.116

The domains were configured as follows:

  • Each domain is reachable only via its corresponding encryption protocol (DoT or DoQ).
  • Do53 is completely disabled.
  • TLS certificates are self-signed.
  • The domains are not DNSSEC-signed.

Papers

Securing the Missing Link: Encrypted Recursive-to-Authoritative DNS in the Wild

To be published:

Oct, 2026

PDF

Contact

If you want to find out more about this project please contact me at yevheniya.nosyk@korlabs.io.