> Thanks for the explanation. I don't know enough DNSSEC to know if > that's actually deployable, but okay > You can tune down TTLs before the change, etc. The TTL is already a small number of seconds so that in the standard DNS case, they can switch within five seconds. Sounds to me that, as I thought, they will have to sign a TLSA record every five seconds. No?