Problem Statement
What problem does DNSSEC aim to solve?
Explanation
DNSSEC lets resolvers verify that the DNS data they received is authentic by checking digital signatures. It defends against cache poisoning and spoofed answers. It does not encrypt queries; for privacy you would add protocols like DoT or DoH.
Code Solution
SolutionRead Only
Resolver behavior: validate RRSIG with DNSKEY; if signature fails, mark response bogus
