This seems to cause that some resolvers do not respond to queries any more until unbound falls back. To ensure better DNS performance, we disabled this. Signed-off-by: Michael Tremer --- config/unbound/unbound.conf | 1 - 1 file changed, 1 deletion(-) diff --git a/config/unbound/unbound.conf b/config/unbound/unbound.conf index c78ca1db7..3aab6ea46 100644 --- a/config/unbound/unbound.conf +++ b/config/unbound/unbound.conf @@ -42,7 +42,6 @@ server: # Hardening Options harden-large-queries: yes harden-referral-path: yes - use-caps-for-id: yes aggressive-nsec: yes # TLS -- 2.20.1