ADD works on mechanisms to allow the client to discover resolvers and their properties. It defines the mechanisms through which DNS resolver information is communicated, allowing the client to decide which DNS server to use. Its current focus is to limit data leakage that happens during multi-hop DNS resolution between DNS resolvers. Sending DNS messages over encrypted transports to DNS resolvers can prevent malicious actors from snooping on the contents of DNS messages and modifying DNS traffic to block responses from selective queries. This can prevent internet service providers or government actors from monitoring or blocking users who attempt to access certain websites.

