Yeah, to repeat what I mentioned briefly at NZNOG for the benefit of people that didn't attend.

We turned on dnssec support on our unbound resolvers in June 2011. We've have had no known issues from doing this at all. It was a simple 5 minute change.

Also, because occasional "dns weirdness" tickets get to us from the helpdesk I'd like to think that any issues that could occur are not just getting lost in the matrix.

Cheers
Dave

On Tue, Feb 11, 2014 at 12:20 PM, Dean Pemberton <nznog@deanpemberton.com> wrote:
Dave Mill (Inspire) stood up at NZNOG and clearly said that for them
that never happened.

Just turn it on.