Constantine Aleksandrovich Murenin wrote: > Shouldn't DNSSEC be off by default? Jan Lentfer informs me that you need to change your configuration (and of course you need to generate the keys and sign the zone yourself) for BIND to return DNSSEC RRs, so I think we're safe for now :) Aggelos