kdig
- is an enhanced dig tool from BIND
Examples
kdig +tls google.com @1.1.1.1
kdig +https google.com @cloudflare-dns.com
kdig +quic google.com @dns.quad9.net
kdig +https +http3 google.com @dns.cloudflare.com
Verify it’s actually Encrypted
sudo tcpdump -i any port 53
- ❌ Plain DNS → you’ll see packets
- ✅ DoH / DoT → nothing shows up