DNSSEC Validation deployment option - BlueCat Address Manager - 9.4.0

Address Manager Administration Guide

Product name
BlueCat Address Manager

DNSSEC validation indicates that a caching DNS server will attempt to validate replies from a signed zone.

Configure DNSSEC Validation by using the DNSSEC Validation and/or DNSSEC Trust Anchors deployment options. DNSSEC validation can be configured to use the built-in default trust anchor for the DNS root zone (automatic validation), or to use configured trust anchors (manual validation). BlueCat suggests using manual validation only if it's required to validate signed zones lower in the DNS namespace that can't be securely delegated from the signed root zone.