8 ms·
> Too many domains which are incorrectly configured leading to non-existing domain errors. That's an interesting and somewhat surprising data point given the u
by dc396 1y ago
> Too many domains which are incorrectly configured leading to non-existing domain errors.
That's an interesting and somewhat surprising data point given the use of DNSSEC validation at public resolvers (e.g., 1.1.1.1, 8.8.8.8, etc.). Might be something that would be useful to track by those following DNSSEC deployment.
For selectively disabling DNSSEC validation, I gather PiHole+dnsmasq doesn't support Reverse Trust Anchors (RTA). Unfortunate.
- tptacek 1y agoGeoff Huston at APNIC does track this!