[public-dns-discuss] Re: DNS-over-TLS certificate domain name mismatch

Mike wrote:
Interesting and thanks.  Qualys is usually spot-on.

Qualys evaluates web servers only, so it was using port 443 (HTTPS) rather than port 853 (DNS-over-TLS). The certificate on port 443 is the one used by DNS-over-TLS (which doesn't currently operate on the et al. anycast addresses).

