> Perhaps we could compare it to the cost of a DNSSEC validation. Which is why DNSSEC validation is most effectively done by the resolver, not the intermediate cache, much as we might wish it to be otherwise (e.g. for cache poisoning protection).
_______________________________________________ DNSOP mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsop
