On 2018-04-11 04:10, Paul Templeton wrote:
When I do a dig +dnssec . | grep ";; flags:" I get ;; flags: qr rd ra ad; QUERY: 1, ANSWER: 0, AUTHORITY: 4, ADDITIONAL: 1 this looks as if its working.
Just to be safe, you could also check the rest of the dig output and /etc/resolv.conf (or relevant resolver configuration on your system) to make sure your BIND is being used. The flags look fine, though.
Kind regards, Alexander