There are many published papers about the load created by DNSSEC on authoritative name servers. And a lot of practical experience as well, some of it publically documented.
For the validating *resolvers*, I find on the Web a few tests in a lab environment (setting up BIND or Unbound with and without validation, and launching many DNS requests at them and measuring the differences) but I do not find data about *actual* deployments, for instance an ISP publishing the results of enabling validation ("We observed no difference" or "We had to triple the number of boxes used as resolvers because of the increased CPU load"). Any pointer? _______________________________________________ dns-operations mailing list dns-operations@lists.dns-oarc.net https://lists.dns-oarc.net/mailman/listinfo/dns-operations dns-jobs mailing list https://lists.dns-oarc.net/mailman/listinfo/dns-jobs