enables “name-based” virtual hosting for DNS authoritative server
$ dig _acme-challenge.algorithm13.net TXT @8.8.8.8 +short
"hijacked"
$ dig _esni.algorithm13.net TXT @8.8.8.8 +short
"legitimate delagation"
$ dig _acme-challenge.algorithm13.net TXT @res-eqt.hdais.net | grep status
... status: NXDOMAIN ...
$ dig _esni.algorithm13.net TXT @res-eqt.hdais.net +short
"legitimate delagation"
git clone -b edns-query-target https://github.com/hdais/unbound/
dig _acme-challenge.algorithm13.net TXT @res-eqt.hdais.net
(This is a rate-limited open-resolver, which returns TC=1 on receiving UDP queries and accepts TCP queries only)