To check the DNSSEC signatures on the client, you have to do a full recursive lookup. You've always been able to run your own DNS cache, if you want your host to operate independently of any upstream DNS server. But at that point, you're simply running your own DNS server.
jcalvinowens|1 day ago
tptacek|1 day ago
I agree with you, though. It's utterly pointless.