Enable DNSSEC in Dnsmasq on local domains | any (dis-)advantages?

Started by flushell, June 14, 2025, 11:22:02 AM

Previous topic - Next topic
I have setup Unbound with forwarding for my local domain to Dnsmasq per the docs: https://docs.opnsense.org/manual/dnsmasq.html#dhcpv4-with-dns-registration
I have DNSSEC enabled in Unbound.

I noticed there is also a DNSSEC switch in the settings of Dnsmasq. If I switch this on, everything works the same as switched off. Is there any advantage or disadvantage switching this on in Dnsmasq? It seems useless to me, since it is for local lookups only... does it even do anything in this scenario?