Custom DNS resolver in private synthetic locations: no DNS-over-TLS enforcement
0 reputation · 13 Dec 2022, 18:36 UTC
Dynatrace Synthetic HTTP monitors running from private locations can be configured with a custom DNS resolver IP address. This setting applies to all monitors on that location. The configuration does not expose an option to enforce DNS-over-TLS (DoT) or DNS-over-HTTPS (DoH) for the resolver.
In environments where encrypted DNS is required for compliance or security, this leaves an unresolved gap: the resolver traffic may be sent in cleartext. It is also unclear whether the location's JSON export includes any field for encrypted DNS, or whether a granular permission exists to restrict DNS changes without granting full "Edit Synthetic Locations" rights.
The behavior may vary by Dynatrace SaaS release, so current verification is needed.
- How can encrypted DNS be enforced for a private synthetic location?
- Is there a supported configuration field for DoT or DoH?
- Does a permission boundary exist for DNS-only edits?