On Mar 30, 2017, at 1:11 PM, Steve Crocker <st...@shinkuro.com> wrote: > And I remain puzzled as to why a simple NXDOMAIN response from the root isn’t > exactly the right thing and why it matters whether it’s signed or not.
Because DNSSEC. A validating stub will see a proof of nonexistence and ignore anything the local recursive resolver offers.
_______________________________________________ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop