DNSSEC Validation indicates that a caching DNS server will attempt to validate replies from a signed zone.

You can configure DNSSEC Validation in two ways: using a DNS Raw Option to automatically validate using the trusted root zone, or using the DNSSEC Validation and DNSSEC Trust Anchors deployment options. BlueCat suggests using this second method only if it is required to validate signed zones lower in the DNS namespace that cannot be securely delegated from the signed root zone.