Mark, I don't think you've actually given an answer to my question. I understood that .ALT was for alternative naming systems, not for DNS locally-served zones. We simply need to decide whether or not that's true. I think either answer is fine; we just need to pick one. If the answer is that it should support locally-served zones with no stub resolver (just to be clear, I am not talking about recursive resolvers), then as you say, there needs to be an un-signed delegation. If on the other hand it's really for alternative _naming systems_ then we want a secure denial of existence.
The last paragraph of the introduction seems to be saying that it's the latter. _______________________________________________ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop