Uploaded April 2026 | Updated September 2026, 4 hours ago
In this interview, we sit down with Ross Gibson, an engineer at Infoblox and contributor to the latest NIST guidance on DNS security, to break down what modern DNS protection really looks like. We explore the key differences between DNSSEC, DoH (DNS over HTTPS), DoT (DNS over TLS), and DoQ (DNS over QUIC)—what they do, how they work, and when to use each. We also explore Protective DNS and how it is helping secure systems using analysis on client requests.
Whether you're a network engineer, security analyst, or just looking to deepen your understanding of DNS, this conversation offers practical insights straight from someone helping shape industry best practices.
Get the book!
The Hidden Potential of DNS in Security
amzn.to/48XpK9o
🔗 Want to go deeper? Get $50 off my Wireshark Certified Analyst course here:
packetschool.teachable.com/l/pdp/official-wireshark-certified-analyst?coupon_code=PACKETHEAD50
0:00 Intro - Who is Ross?
1:26 NIST Update!
2:29 Why is DNS still under attack?
5:30 Securing DNS today
6:15 What is DNSSEC?
9:50 Clients don't use DNSSEC
10:50 Encrypting DNS - Different methods
12:50 DoT vs DoH
16:50 Monitoring encrypted DNS
18:20 What is Protective DNS?
20:30 DNS over QUIC
21:50 DoT, DoH, DoQ - Which is best?
26:30 What's next in our DNS series?
#DNS #CyberSecurity #Wireshark #Networking #Infosec
In this interview, we sit down with Ross Gibson, an engineer at Infoblox and contributor to the latest NIST guidance on DNS security, to break down what modern DNS protection really looks like. We explore the key differences between DNSSEC, DoH (DNS over HTTPS), DoT (DNS over TLS), and DoQ (DNS over QUIC)—what they do, how they work, and when to use each. We also explore Protective DNS and how it is helping secure systems using analysis on client requests.
Whether you're a network engineer, security analyst, or just looking to deepen your understanding of DNS, this conversation offers practical insights straight from someone helping shape industry best practices.
Get the book!
The Hidden Potential of DNS in Security
amzn.to/48XpK9o
🔗 Want to go deeper? Get $50 off my Wireshark Certified Analyst course here:
packetschool.teachable.com/l/pdp/official-wireshark-certified-analyst?coupon_code=PACKETHEAD50
0:00 Intro - Who is Ross?
1:26 NIST Update!
2:29 Why is DNS still under attack?
5:30 Securing DNS today
6:15 What is DNSSEC?
9:50 Clients don't use DNSSEC
10:50 Encrypting DNS - Different methods
12:50 DoT vs DoH
16:50 Monitoring encrypted DNS
18:20 What is Protective DNS?
20:30 DNS over QUIC
21:50 DoT, DoH, DoQ - Which is best?
26:30 What's next in our DNS series?
#DNS #CyberSecurity #Wireshark #Networking #Infosec










