Skip to main content

in reply to Orhun Parmaksız 👾

Running a local instance of unbound (instead of dynamically changing your upstream DNS) should work too, and also validate DNSSEC signatures in responses. If you use a validating resolver, you should never get to the point where a client tries to connect to the fake server with a self-signed certificate.