> No, I need to actually locally sign zonefiles for my own DNSSEC. Then > even `resolvectl query` (part of base!) can check their DNSSEC status. No, I don't know anything. It is not an operation that I do either, so I cannot contribute much in this case :-(