On Mon, Apr 29, 2013 at 07:30:38AM -0700, Paul Hoffman wrote: > Retrying queries without EDNS0 seems sensible before deployment of DNSSEC. Is that still the case now that DNSSEC is more widely deployed? Yes. The world still needs *a lot* of EDNS downgrading. But not once you've seen a DS as it makes zero sense. Bert