Simon Kelley writes: > That's straightforward. Dnsmasq gets a query for > 62.75.115.213.in-addr.arpa, sends it upstream, gets an answer which > isn't signed, and determines that it's insecure, then returns the > answer. Right, that's what I thought. So everything is working as it should? :) -Toke