I enabled trace with sudo rec_control trace-regex "app\.$" and did
lookup "dig app ns @localhost".
What I understand from the trace output is that the recursor has the
the NS records in the cache but then it gets the DNSSEC Keys from the
NS servers and validates the records.
--
Regards
Hi everyone!
We are happy to announce the first release candidate of what will become
dnsdist 1.7.0, with only one fix and one improvement since the second beta.
We fixed a crash introduced in 1.7.0-alpha1 that could occur when a DoH
query was forwarded to a backend over TCP, DoT or DoH and