Slide 11
Slide 11 text
dig
dig +dnssec and watch for AD flag indicating successful
validation
$ dig +dnssec @127.0.0.1 loadays.jpmens.org txt
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 4
;; flags: qr rd ra ad; QUERY: 1, ANSWER: 2, [...]
Invalid or bogus DNSSEC data will not be returned
$ dig +dnssec @127.0.0.1 www.dnssec-failed.org
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 3