Wait actually better a new record type: CODE pairs nicely with the HTTPS record type. Now we don't even need ANY server side execution the browser just looks up your service in DNS and executes it.
We can authenticate it with DKIM!
@amy I made a very critical blog post around that time period on my old blog. Got a lot of heat from "self-hosting" guys who were CloudFlare customers.
@thufie yeah that tracks.
@thufie good to have confirmation because I was pretty sure that was the case initially. Then google helpfully joined in so you can choose between two corporations built on spying to helpfully "protect" your DNS traffic.