logoalt Hacker News

feryesterday at 10:27 PM1 replyview on HN

If you have systemd-resolved, it tries to validate DNSSEC by default and replies with SERVFAIL if it fails. Same happens here, I go through some privacy focused DNS servers and they sometimes remove the signature.

$ resolvectl query z.ai

z.ai: resolve call failed: DNSSEC validation failed: no-signature


Replies

bfleschtoday at 12:10 AM

That seems to be it, thanks for the explanation :)