Protocol Support
This guide covers the essentials. Read the full upstream guide on GitHub → For a specific release, select its tag in the repository.
BoronDNS provides secondary authoritative DNS. Its feature reference describes implemented behavior and limits; the RFC compliance register records scoped claims and evidence.
Main capabilities
| Capability | Scope |
|---|---|
| UDP and TCP DNS | Authoritative answers, EDNS handling, and TCP retry after truncation. |
| AXFR and IXFR | Transfers from primaries, incremental refresh, and AXFR fallback. |
| NOTIFY and TSIG | Authorized refresh signals and configured transfer authentication. |
| XoT | Outbound TLS 1.3 zone transfers. |
| Passive DNSSEC | Serving transferred signatures and denial records. |
| Catalog zones | Runtime member discovery with authenticated catalog transfers. |
Product boundaries
BoronDNS does not provide recursive resolution, forwarding, dynamic UPDATE, primary service, or downstream IXFR service. Passive DNSSEC does not include signing, validation, or key management. XoT does not imply client-query DoT, DoH, or DoQ support.
RFC 7314 EDNS EXPIRE is outside the current scope. Consult the upstream register for individual RFC qualifications, rather than treating this overview as a blanket conformance claim.
Detailed evidence
Use the documentation index for the requirements baseline, verification ledger, interoperability results, and release evidence. Requirements may include future acceptance targets; dated test results apply to their recorded commits and environments. Check the notes for the release you deploy.