<html dir="ltr"><head></head><body style="text-align:left; direction:ltr;"><div>On Sat, 2021-02-27 at 01:33 +0000, Wessels, Duane via dns-operations wrote:</div><blockquote type="cite" style="margin:0 0 0 .8ex; border-left:2px #729fcf solid;padding-left:1ex">Additionally, we expect this may bring some new attention to the<br>
way in which authoritative name servers respond to queries of type<br>
NSEC.  Some implementations respond with referrals, while others<br>
respond with an NSEC RR in the Answer section.  Verisign will be<br>
pleased to work with the community if there are ambiguities in the<br>
relevant RFCs (e.g. 4035) that would benefit from clarification,<br>
as current behavior beyond this subset of our name servers suggests.</blockquote><div><br></div><div>Earlier, inconclusive, discussion on that: <a href="https://lists.dns-oarc.net/pipermail/dns-operations/2016-July/015114.html">https://lists.dns-oarc.net/pipermail/dns-operations/2016-July/015114.html</a> ('DS-side NSEC query')</div><div><br></div><div>Kind regards,</div><div><span><div style="width: 71ch;">-- </div><div style="width: 71ch;">Peter van Dijk</div><div style="width: 71ch;">PowerDNS.COM BV - https://www.powerdns.com/</div></span></div></body></html>