feat: DoT (DNS over TLS) client upstream

Adds tls:// upstream support for forwarding queries over DNS-over-TLS
(RFC 7858). Parses tls://IP:PORT#hostname format, with default port 853.

- New Upstream::Dot variant with TLS connector
- forward_dot: length-prefixed DNS over TLS stream
- build_dot_connector: system root CAs via webpki-roots
- parse_upstream handles tls:// prefix

Example config:
  address = ["tls://9.9.9.9#dns.quad9.net"]
This commit is contained in:
Razvan Dimescu
2026-04-12 18:35:06 +03:00
parent 7047767dc2
commit 05baad0cc0
3 changed files with 82 additions and 0 deletions

1
Cargo.lock generated
View File

@@ -1170,6 +1170,7 @@ dependencies = [
"tokio-rustls",
"toml",
"tower",
"webpki-roots",
]
[[package]]