Some TLDs unfortunately still don't support DNSSEC all the way to the root. However, is it possible to add a specific DNSKEY to my resolver (currently using knot-resolver) so that a signed zone can be verified even without TLD support?


You must log in to answer this question.

Browse other questions tagged .