Comcast is the first ISP to join Firefox's Trusted Recursive Resolver program to deploy encrypted DNS lookups on the Firefox browser
Jon Brodkin / Ars Technica :
Context & Ripple Effects
This is a reversal eight months in the making. A leaked presentation showed Comcast lobbying US lawmakers against Google and Mozilla's plan to encrypt DNS, and Mozilla followed by urging Congress to reject the ISP lobby campaign it said was using Google as a boogeyman. In February, Firefox began its default rollout of encrypted DNS over HTTPS for US users — the exact move Comcast had fought.
With Comcast now the first ISP to join the Trusted Recursive Resolver program, the standoff ends with the ISP inside Mozilla's framework rather than against it: encrypted lookups stay in Firefox, but Comcast can run the resolver itself. Mozilla had already shown it would bend geography to ISP pressure, declining to enable DoH by default in the UK after ISP and government criticism, so a US carrier choosing cooperation is the stronger signal.
First-order effects
- Comcast's Xfinity subscribers on Firefox get encrypted DNS without traffic shifting to a third-party resolver like Cloudflare — the lookups stay with their ISP, just encrypted.
Second-order effects
- Other US ISPs face a choice between joining TRR to keep the resolver relationship or ceding DNS visibility to outside partners as Firefox's DoH-by-default rollout widens.
Third-order effects
- If the pattern holds, encrypted DNS stops being an ISP-versus-browser fight and becomes a certification market: carriers that won't meet Mozilla's resolver terms lose the last plaintext data stream they could observe by default.
The trend: Browser vendors are pulling DNS resolution away from ISPs and toward vetted trusted-resolver partners, converting ISPs from gatekeepers into optional participants in name-resolution.