From 9743da7b9668ff7b8df70d30e6da7fcf5e37b27c Mon Sep 17 00:00:00 2001 From: Mark Drobnak Date: Mon, 17 Sep 2018 11:35:52 -0400 Subject: [PATCH] Add more DNSSEC warnings. Signed-off-by: Mark Drobnak --- settings.php | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/settings.php b/settings.php index ea87dc7f..248bdfc7 100644 --- a/settings.php +++ b/settings.php @@ -834,7 +834,9 @@ if (isset($_GET['tab']) && in_array($_GET['tab'], array("sysadmin", "blocklists"

Validate DNS replies and cache DNSSEC data. When forwarding DNS queries, Pi-hole requests the DNSSEC records needed to validate - the replies. Use Google, Norton, DNS.WATCH, Quad9, or another DNS + the replies. If a domain fails validation or the upstream does + support DNSSEC, this setting can cause issues resolving domains. + Use Google, Norton, DNS.WATCH, Quad9, or another DNS server which supports DNSSEC when activating DNSSEC. Note that the size of your log might increase significantly when enabling DNSSEC. A DNSSEC resolver test can be found