
Hello Luv members, I've recently added DNSSec signatures to my domain (jasonjgw.net), and supplied the key to my DNS registrar, gandi.net. Unfortunately, my ISP's name servers, which perform DNSSec validation, now return a SERVFAIL (indicating a validation failure) when I look up the domain. Google's public servers succeed, however, as DNSSec Analyzer appears to do: http://dnssec-debugger.verisignlabs.com/ The primary DNS server is running Bind 9 and I essentially followed the instructions here: https://nocko.se/2012/03/21/dnssec-quickly-and-correctly/ Is there anything that seems amiss? I have friends who are contemplating following in my footsteps with their own domains, thus anything we work out here should be helpful to them also.