Follow up, If you have a secure mechanism that does not allow attackers to do cache poisioning on the client's stub resolver, then this solve the problem of malicious websites as well.
Best, Hosnieh
_______________________________________________ DNSOP mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsop
