Thanks all for explains. I am new to DNSSEC, so I have questions:
1. how to check if a zone has a valid DNSSEC key? 2. how to validate if the zone has been signed with correct key? Regards. on 2020/1/8 19:00, Stephane Bortzmeyer wrote:
As explained by several experts, this domain is DNSSEC-broken. This has nothing to to with the public resolvers (on my own local resolver, it fails as well), any resolver which validates signatures (they should all do it) will have the same problem.
_______________________________________________ dns-operations mailing list dns-operations@lists.dns-oarc.net https://lists.dns-oarc.net/mailman/listinfo/dns-operations