If a DNS name server supports DNSSEC, does it mean that every DNS response it sends will include DNSSEC-related records, like NSEC, NSEC3, RRSIG, etc? Or does it depend on what the resolver sent?

I know that we need to set +dnssec when running dig commands to see DNSSEC-related records. Is it the same for "regular" DNS queries?

  • 1
    DNSSEC has been available for 10 years. All DNS servers support it now. DNSSEC is optional, so it does not mean that any response will include it, or that any response will be signed, or even if a zone is signed at all.
    – Greg Askew
    Nov 10 at 5:16


You must log in to answer this question.

Browse other questions tagged .