1. performance: since the TCP+TLS handshake is only performed once and the connection is kept open forever
2. privacy: the resolver doesn't get the requesting party's IP address
How does that work? Is it somewhat like Tor?
[Requesting Party]<--->[XMPP server]<--->[XMPP Server]<--->[Resolver]
[Requesting Party]<--->[XMPP server1]<--->[XMPP Server2]<--->[Resolver]
But do I need to trust XMPP server 1 and 2?And will XMPP server 2 have my IP address?
Also; you don't get virtual circuits, but the performance should be superior. Tor only supports A, AAAA and PTR; DoX supports every record type.
Also, XMPP has e2e extensions, at least one of which supports encrypting/verifying arbitrary XML[1], so if the resolver supported it, you could only trust the resolver. (also don't forget about DNSSEC which can be used to verify DNS responses too)
I must admit to being biased against using DNSSEC alone because a malicious XMPP server can still inspect and/or modify queries and responses. By self-hosting you mitigate, but without e2ee the server is still trusted (in the threat-model).
You trust whatever server you query. That might be server one, or it might be server one and server two. It's a federated network, so you make requests through your own server.
> And will XMPP server 2 have my IP address?
No. It's a federated network, like email, so it just gets your XMPP address (historically referred to as a "Jabber ID" or "JID").
There was an intense debate on whether it ought to be published as Standards Track or Humorous...
It's just as humorous as DoT or DoH.