* Paul Vixie wrote: >> If we limit the DNS size to 512 bytes, the results are frustrating: Every >> possible response is truncated, because the RRSIG is too long. > > dnssec requires edns. There are several setups out there limiting any EDNS query to 512 bytes.