> Actually there *is* DNSSEC involved or the query would not have > failed.
Yes, sorry. I meant to imply that there is no DNSSEC involved beyond the verification of the covering NSEC that proves the lack of a DLV record. > There is a bug in the BIND 9.7.0-P1 fixes that triggers this. The > fix below is in review at the moment. Interesting - so it sounds like the problems I was seeing with 9.7.0 were probably unrelated. The patch certainly seems to fix the issue with www.bbc.net.uk. I'll run with it for a few days and see if the .org issue I was having earlier recurs. Thanks, -roy _______________________________________________ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users