On 2015/12/08 16:45 , Daniel Karrenberg wrote: > Real resolvers > - use caching, > - retry queries, > - can use all authoritative servers for a zone, > - perform recursion, and (again) > - use caching. > > The typical TTL for caching in the root zone is 48 hours.
I wonder if in the case of local DNSSEC validating resolvers behind DNSSEC-unware resolvers in CPEs, this model is still valid.