>> Running a DNS over TLS for a couple of users is easy, but running it
>> for millions of users is not easy.
> There are not many DNS servers with millions of users! Most DNS
> servers have much less. The behemoths with a real lot of users (such
> as Google Public DNS) are also the ones who certainly have the
> abilities to make it work large-scale.
Most ISP/Telcos and mobile networks have millions of users easily. And
there are a bunch of them in every country, and these operators are
the people I recall the IETF wants to encourage to participate, yet
we design protocols that put a lot of burden on them.

At the moment for an ISP/Telco DNS is relatively small cost compared to
other network/hosting costs even if they buy a commercial solution. DNS
over TLS will increase that cost a lot for no benefit for them (I
assume they can protect their networks from illegal spying). So I see
no incentive for them to deploy it.

So long

