Hacker News new | past | comments | ask | show | jobs | submit login

As others answered, something called qname minimization. Others gave detailed explanations, so I'll try to be shorter.

In DNS, the recursive resolver sends the entire FQDN each time to every step.

Now realize, like every company, DNS operators want to collect and sell your data.

So imagine a 'bigsite.com' that does a lot of things. And you like, say porn.bigsite.com. Without this minimization, everyone from the root to verisign to bigsite knows what you queried for.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: