Stephane Bortzmeyer via Unbound-users <unbound-users@nlnetlabs.nl> wrote: > Nick via Unbound-users <unbound-users@nlnetlabs.nl> wrote: > > > Recently I have been looking for ways to determine/differentiate > > (from the DNS client) SERVFAIL & SERVFAIL due to DNSSEC errors. > > Indeed, this is a big problem, and a serious issue for the DNS in > general, and for DNSSEC specially.
Yes. You can distinguish between something DNSSEC and something else if you re-query with CD=1 (e.g. `dig +cd`), but that still leaves a lot to be desired. Tony. -- f.anthony.n.finch <d...@dotat.at> http://dotat.at/ Dogger: Northwest 5 or 6, becoming variable 3 or 4. Rough or very rough, becoming moderate. Fair. Good.