> On Apr 18, 2025, at 1:24 AM, Philip Homburg <[email protected]> > wrote: > > > The current draft contains the following text: > DNSSEC validating resolvers will fail to resolve names ending in "internal". >
That sentence doesn’t sit very well with me. I configured .internal as an auth-zone in my instance of Unbound (which is an out-of-the-box DNSSEC validating resolver) and had no problems at all resolving names in my local .internal zone. The sentence might as well just say “All resolvers will fail to resolve names ending in internal” because the only way a resolver is going to resolve them is with locally configured data or forwarding. DW
smime.p7s
Description: S/MIME cryptographic signature
_______________________________________________ DNSOP mailing list -- [email protected] To unsubscribe send an email to [email protected]
