DNSSEC Validation deployment option - BlueCat Integrity - 9.3.0

Address Manager Administration Guide

Product name
BlueCat Integrity

DNSSEC validation indicates that a caching DNS server will attempt to validate replies from a signed zone.

Configure DNSSEC Validation by using the DNSSEC Validation and/or DNSSEC Trust Anchors deployment options. DNSSEC validation can be configured to use the built-in default trust anchor for the DNS root zone (automatic validation), or to use configured trust anchors (manual validation). BlueCat suggests using manual validation only if it's required to validate signed zones lower in the DNS namespace that can't be securely delegated from the signed root zone.