drinkingbird
Part of the Furniture
Quad9 claims to do DNSSEC with remote hosts, and even validate the response (seemingly the same as enabling DNSSEC in Merlin and selecting "validate unsigned responses"). I've noticed having these enabled does cause a bit of performance hit to lookups, wondering if there is any reason to enable them, I trust Quad9 at least to the extent that I need to, so not sure I need to re-validate every response they send me? Especially since someone malicious that gets into their infra could just sign the response as valid.
Last edited: