Structured DNS error draft

구조화된 DNS 차단 오류 초안

An IETF draft gives filtered DNS responses machine-readable reasons.

···
html
<div class="n-demo"><div class="n-head"><strong>FILTERED DNS RESPONSE</strong><span>LIVE TRACE</span></div><div class="n-stage"><div class="sde"><div class="sde-query n-box">query + SDE option</div><div id="sde-result" class="sde-result n-box"><b id="sde-head">DNS: FILTERED</b><span id="sde-detail">no reason shown</span></div><div class="sde-footer" id="sde-footer">basic error</div></div></div><div class="n-foot">tap to step · auto replay</div></div>
css
.n-demo{width:min(94vw,760px);height:min(88vh,324px);padding:clamp(9px,2.2vmin,18px);border:1px solid var(--line);border-radius:13px;background:var(--surface);display:flex;flex-direction:column;gap:clamp(5px,1.3vmin,10px);font:600 clamp(12px,2.4vmin,16px)/1.3 "Pretendard Variable",Pretendard,-apple-system,BlinkMacSystemFont,"Apple SD Gothic Neo",sans-serif;overflow:hidden}.n-head,.n-foot{display:flex;justify-content:space-between;align-items:center;color:var(--muted)}.n-head strong{color:var(--accent)}.n-head span,.n-foot{font-size:12px}.n-stage{flex:1;min-height:0;position:relative;display:flex;align-items:center;justify-content:center;gap:clamp(4px,1vmin,10px)}.mono{font-family:ui-monospace,SFMono-Regular,Consolas,monospace}.n-box{padding:clamp(5px,1.5vmin,11px);border:1px solid var(--line);border-radius:8px;background:var(--bg);text-align:center}.n-on{border-color:var(--accent)!important;color:var(--accent)!important;background:color-mix(in srgb,var(--accent) 12%,var(--surface))!important}.n-muted{color:var(--muted)}@media(max-width:400px){.n-head span{display:none}}.sde{width:94%;display:grid;gap:6px}.sde-query{text-align:left;padding:5px}.sde-result{display:grid;gap:3px;text-align:left;padding:6px}.sde-result b{color:var(--accent-3)}.sde-result span{font:600 11px/1.3 ui-monospace,monospace}.sde-footer{font-size:12px;color:var(--muted);text-align:right}@media(min-width:500px){.sde-result span{font-size:12px}}
js
let step=0;function advance(){const structured=step===1;document.getElementById('sde-detail').textContent=structured?'reason: network policy':'no reason shown';document.getElementById('sde-result').classList.toggle('n-on',structured);document.getElementById('sde-footer').textContent=structured?'structured EDE detail':'basic error';step=(step+1)%2}
const clickTarget=document.querySelector('.n-demo');if(clickTarget&&typeof advance==='function'){advance();const timer=setInterval(advance,1050);clickTarget.addEventListener('pointerdown',()=>{clearInterval(timer);advance()})}

A 2026 IETF draft lets a client signal SDE support and a server place structured details in an Extended DNS Error for a filtered response. The aim is to make blocking reasons clearer to users.

The demo compares a bare blocked response with one that includes a structured reason. It remains a draft, and acting on the details requires encrypted DNS transport.

When to use

Review the draft and transport security when exploring client-visible explanations for DNS filtering.

Open as page ↗