<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.ietf-dnsop-ns-revalidation" target="https://datatracker.ietf.org/doc/html/draft-ietf-dnsop-ns-revalidation-11">
   <front>
      <title>Delegation Revalidation by DNS Resolvers</title>
      <author initials="S." surname="Huque" fullname="Shumon Huque">
         <organization>Salesforce</organization>
      </author>
      <author initials="P. A." surname="Vixie" fullname="Paul A. Vixie">
         <organization>SIE Europe, U.G.</organization>
      </author>
      <author initials="W." surname="Toorop" fullname="Willem Toorop">
         <organization>NLnet Labs</organization>
      </author>
      <date month="October" day="19" year="2025" />
      <abstract>
	 <t>   This document describes an optional algorithm for the processing of
   Name Server (NS) resource record (RR) sets (RRsets) during iterative
   resolution, and describes the benefits and considerations of using
   this approach.  When following a referral response from an
   authoritative server to a child zone, DNS resolvers should explicitly
   query the authoritative NS RRset at the apex of the child zone and
   cache this in preference to the NS RRset on the parent side of the
   zone cut.  The (A and AAAA) address RRsets in the additional section
   from referral responses and authoritative NS answers for the names of
   the NS RRset, should similarly be re-queried and used to replace the
   entries with the lower trustworthiness ranking in cache.  Resolvers
   should also periodically revalidate the delegation by re-querying the
   parent zone at the expiration of the TTL of either the parent or
   child NS RRset, whichever comes first.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-ietf-dnsop-ns-revalidation-11" />
   
</reference>
