Intrepid
Regular Contributor
I just completed my final tests with Quad9.
1. Just DNSSEC: Business.Comcast.com FAILS to load properly
2. Just DNSSEC with Validate unsigned DNSSEC replies: Business.Comcast.com FAILS to load properly
3. DNSSEC (with and without Validation) -and- DNS-over-TLS (DoT): Business.Comcast.com FAILS to load properly.
4. Just DNS-over-TLS (DoT): Business.Comcast.com Loads Properly.
As recommended by Quad9, I will not be using DNSSEC because it's unreliable. As mentioned by other users this is not just a Quad9 issue as Comcast fails with Cloudflare and DNSSEC as well. If Comcast fails there will be others. I think Quad9's implementation of DNSSEC along with DNS-over-TLS (DoT) encryption on the Asus router provides more than enough security as well as reliability.
1. Just DNSSEC: Business.Comcast.com FAILS to load properly
2. Just DNSSEC with Validate unsigned DNSSEC replies: Business.Comcast.com FAILS to load properly
3. DNSSEC (with and without Validation) -and- DNS-over-TLS (DoT): Business.Comcast.com FAILS to load properly.
4. Just DNS-over-TLS (DoT): Business.Comcast.com Loads Properly.
As recommended by Quad9, I will not be using DNSSEC because it's unreliable. As mentioned by other users this is not just a Quad9 issue as Comcast fails with Cloudflare and DNSSEC as well. If Comcast fails there will be others. I think Quad9's implementation of DNSSEC along with DNS-over-TLS (DoT) encryption on the Asus router provides more than enough security as well as reliability.
Last edited: