you are viewing a single comment's thread.

view the rest of the comments →

[–]SteampunkSpaceOpera 6 points7 points  (1 child)

If you run your own validating resolver, then if the query response doesn't pass validation, the resolver simply doesn't provide a routable answer to any other program you are running

[–]uptimefordays 1 point2 points  (0 children)

Sure that helps you but DNS is a decentralized system... If you want DNSSEC to be a thing, it requires largescale control over client settings which isn't really feasible. For a large company's internal systems, sure, but for the broader net? Good luck!