Queries/Responses to a Signed Zone (1/2) Use +dnssec option of BIND9 dig Example response to an existing name % dig @127.0.0.1 +dnssec foo.sec.jinmei.org +norec ;; ANSWER SECTION: foo.sec.jinmei.org. 86400 IN A 10.0.2.2 foo.sec.jinmei.org. 86400 IN RRSIG A 1 4 86400 ... ;; AUTHORITY SECTION: sec.jinmei.org. 86400 IN NS ns.sec.jinmei.org. sec.jinmei.org. 86400 IN RRSIG NS 1 3 86400 ... ;; ADDITIONAL SECTION: ns.sec.jinmei.org. 86400 IN A 10.0.2.1 ns.sec.jinmei.org. 86400 IN RRSIG A 1 4 86400 ... sec.jinmei.org. 86400 IN DNSKEY 256 3 1 AQPRNw... sec.jinmei.org. 86400 IN DNSKEY 256 3 1 AQPFuO... sec.jinmei.org. 86400 IN RRSIG DNSKEY 1 3 86400 ... sec.jinmei.org. 86400 IN RRSIG DNSKEY 1 3 86400 ...