{"ID":2848506,"CreatedAt":"2026-06-01T04:54:23.091178241Z","UpdatedAt":"2026-06-01T04:54:23.091178241Z","DeletedAt":null,"paper_url":"https://arxiv.org/abs/2510.25352","arxiv_id":"2510.25352","title":"Is Protective DNS Blocking the Wild West?","abstract":"We perform a passive measurement study investigating how a Protective DNS service might perform in a Research \u0026 Education Network serving hundreds of member institutions. Utilizing freely-available DNS blocklists consisting of domain names deemed to be threats, we test hundreds of millions of users' real DNS queries, observed over a week's time, to find which answers would be blocked because they involve domain names that are potential threats. We find the blocklists disorderly regarding their names, goals, transparency, and provenance making them quite difficult to compare. Consequently, these Protective DNS underpinnings lack organized oversight, presenting challenges and risks in operation at scale.","short_abstract":"We perform a passive measurement study investigating how a Protective DNS service might perform in a Research \u0026 Education Network serving hundreds of member institutions. Utilizing freely-available DNS blocklists consisting of domain names deemed to be threats, we test hundreds of millions of users' real DNS queries, o...","url_abs":"https://arxiv.org/abs/2510.25352","url_pdf":"https://arxiv.org/pdf/2510.25352v1","authors":"[\"David Plonka\",\"Branden Palacio\",\"Debbie Perouli\"]","published":"2025-10-29T10:11:08Z","proceeding":"cs.CR","tasks":"[\"cs.CR\",\"cs.NI\"]","methods":"[\"Generative Adversarial Network\"]","has_code":false}
