Warren Kumari <warren at kumari.net> wrote:
> ​Well, that's only true if you sign your reverse zones, ​yes? I'm part of
> the DNSSEC Brigade, but is a signed reverse necessary?

Well, people would be kind of upset if someone poisoned a cache
with NXDOMAIN for our mail server PTRs.

If you think reverse DNS is not worth DNSSEC, why are you even going to
the effort to synthesize bulshytt records? Might as well just leave it

