Why isn't DNS-over-TLS (DoT) - RFC7858 - being dissected by Wireshark 3.0?

I see that Wireshark 3.0 now has support for DoH (DNS-over-HTTPS, RFC8484), but I can't see anyway to make it decode DNS-over-TLS on the IANA assigned port (853). I can decode the raw bytes, but they are not recognised as DNS.

Please let me know if this is supported and I am just missing something.

Otherwise please let me know if there are plans to support this in future?

Is the decryption working? The data can't be dissected as DNS unless it can be decrypted.

Are you able to share the trace, with the DoH?

OK - so this does work if you either

  1. simply configure the RSA key in the new 'RSA Keys' dialog in the preferences OR
  2. configure the key in the Protocols->TLS->RSA keys list AND then use the 'Decode as' dialog to instruct wireshark to decode port 853 as DNS

I was confused because when using the second method the default 'Decode as' protocol for port 853 seems to be TLS not DNS, but manually overriding this works.

DNS-over-TLS (DoT) is different from DNS-over-HTTPS (DoH). The former defaults to TCP port 853 where the latter runs over TCP port 443.

