ADoX in the Wild

Measuring the deployment of encrypted recursive-to-authoritative DNS (RFC 9539)

See the deployment statistics

Latest news

April 9, 2026

We added the ADoX deployment statistics for March 2026.

Our measurements are performed monthly and updates will be published on this website.

April 2, 2026

This website is up, welcome!

Deployment statistics

Last updated: August 9, 2026

As of July 2026, 2 root server operators (H, B), 6 top-level domains (.cy, .ελ, .arpa, .kg, .gr, .lu), and 2,989,901 registered domains support some form of ADoX. This deployment is driven by 4 nameserver IPs at the root level, 14 at the TLD level, and 2,776 NS IPs across registered domains.

Our measurements are performed once per month. We gather a comprehensive list of domains from various sources, including the IANA root zone database of top-level domains, ICANN CZDS, passive DNS, CT logs, and zone transfers. We use zdns to map domain names to NS records, followed by A/AAAA requests to get nameserver IPs. Next, we attempt to establish ADoT and ADoQ connections with each nameserver, disabling certificate validation (as allowed by the RFC 9539). Once we identify the nameservers supporting encryption, we resolve all the domains they are authoritative for over the supported encrypted channel. We define a domain name ADoX-enabled if at least one of its nameservers returns the NOERROR DNS response to our SOA query sent over ADoT or ADoQ.

Below we aggregate biggest ADoX nameservers by their suffix, for example, ns1.one.com, ns2.one.com, and ns3.one.com are represented as *.one.com. Note that a single operator can use multiple suffixes, e.g., wedos.cz and wedos.eu.

# Operator ADoT domains Operator ADoQ domains
1. *.one.com 1,392,854 *.one.com 1,392,853
2. *.timeweb.ru 400,442 *.hostnet.nl 391,412
3. *.timeweb.org 400,410 *.wedos.eu 230,894
4. *.hostnet.nl 391,412 *.wedos.cz 230,785
5. *.wedos.eu 270,120 *.wedos.com 230,682
6. *.wedos.cz 270,068 *.g1-dns.com 81,376
7. *.wedos.com 269,895 *.g1-dns.one 81,376
8. *.nazwa.pl 141,281 *.antagonist.nl 42,810
9. *.g1-dns.com 81,376 *.antagonist.net 42,810
10. *.g1-dns.one 81,376 *.desec.org 16,462
11. *.antagonist.nl 42,810 *.agonet.it 2,948
12. *.antagonist.net 42,810 *.ipandmore.cloud 2,505
13. *.namebay.com 36,362 *.ipandmore.hosting 2,505
14. *.webhosting.dk 22,278 *.ipandmore.net 2,505
15. *.mywebtonet.com 22,274 *.ipandmore.email 2,505
16. *.freeola.net 18,984 *.aspnix.com 1,413
17. *.webspacecontrol.com 17,864 *.rhx.info 1,384
18. *.desec.org 16,454 *.x4w.net 1,384
19. *.iq.pl 14,715 *.rollernet.us 882
20. *.glbns.com 14,388 *.lynet.eu 711

The table below shows the highest-ranked ADoX domains according to the Tranco list. As of July 2026, Tranco contains 6,003 ADoT and 1,828 ADoQ domains.

Rank ADoT domain Rank ADoQ domain
5. facebook.com 95. root-servers.net
11. instagram.com 159. one.one
15. fbcdn.net 1848. one.com
30. wikipedia.org 3926. codeberg.org
32. whatsapp.net 4305. eu.org
58. whatsapp.com 6478. sport1.de
72. wa.me 7898. digitalaudience.io
73. cdninstagram.com 8089. hostnet.nl
95. root-servers.net 10061. lectio.dk
123. cdn77.org 10146. ulluwebseries.one

Domains

We set up two domains - dot.adox-deployment.com and doq.adox-deployment.com - with nameservers that support ADoT or ADoQ. The easiest way to test how it works is with kdig. Below is the ADoT example:

$ kdig @91.98.28.152 dot.adox-deployment.com +tls +norec

;; TLS session (TLS1.3)-(ECDHE-X25519)-(RSA-PSS-RSAE-SHA256)-(AES-256-GCM)
;; ->>HEADER<<- opcode: QUERY; status: NOERROR; id: 14208
;; Flags: qr aa; QUERY: 1; ANSWER: 1; AUTHORITY: 0; ADDITIONAL: 1

;; EDNS PSEUDOSECTION:
;; Version: 0; flags: ; UDP size: 1232 B; ext-rcode: NOERROR
;; EDE: 0 (Other): 'This is a test ADoT nameserver'

;; QUESTION SECTION:
;; dot.adox-deployment.com.		IN	A

;; ANSWER SECTION:
dot.adox-deployment.com.	60	IN	A	65.21.183.116

And the ADoQ domain:

$ kdig @91.98.27.230 doq.adox-deployment.com +quic +norec

;; QUIC session (QUICv1)-(TLS1.3)-(ECDHE-X25519)-(RSA-PSS-RSAE-SHA256)-(AES-256-GCM)
;; ->>HEADER<<- opcode: QUERY; status: NOERROR; id: 0
;; Flags: qr aa; QUERY: 1; ANSWER: 1; AUTHORITY: 0; ADDITIONAL: 1

;; EDNS PSEUDOSECTION:
;; Version: 0; flags: ; UDP size: 1232 B; ext-rcode: NOERROR
;; EDE: 0 (Other): 'This is a test ADoQ nameserver'

;; QUESTION SECTION:
;; doq.adox-deployment.com.		IN	A

;; ANSWER SECTION:
doq.adox-deployment.com.	60	IN	A	65.21.183.116

The domains were configured as follows:

  • Each domain is reachable only via its corresponding encryption protocol (DoT or DoQ).
  • Do53 is completely disabled.
  • TLS certificates are self-signed.
  • The domains are not DNSSEC-signed.

Papers

Securing the Missing Link: Encrypted Recursive-to-Authoritative DNS in the Wild

To be published:

Oct, 2026

PDF

Contact

If you want to find out more about this project please contact me at yevheniya.nosyk@korlabs.io.