Hello,

here is a followup benchmark test, same setup, but 1000 queries
collected from an office network replayed via "dig" (with duplicates and
all, so the cache is being used).

| Protocol                              | Time (Seconds)  | Privacy | DNSSEC |
|---------------------------------------+-----------------+---------+--------|
| DNS-over-TLS (Unbound+dnsfwd+stunnel) |              10 | ++      | +      |
| local Unbound with DNSSEC             |              11 | -       | +      |
| local Unbound without DNSSEC          |              11 | -       | -      |
| DNS-over-TLS (dnsfwd+stunnel)         |              21 | ++      | -      |
| DNS-over-TLS (Unbound+stunnel)        |              24 | ++      | +      |
| Google DNS (UDP)                      |              30 | --      | +      |
| DNS-over-TLS (Unbound buildin TLS)    |              40 | ++      | +      |
| DNS-over-DNSCrypt (ns0.dnscrypt.is)   |              81 | ++      | +      |
| DNS-over-Tor                          |             103 | ++      | -      |

Looks not too bad.

Carsten Strotmann

_______________________________________________
dns-privacy mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dns-privacy

Reply via email to