First check that DNSSEC validation is set in your configuration file.

You should see a line in the

WATCH, etc.), and location specific servers you might prefer (Open NIC).

will automatically route to the nearest DNS server operated by Level3 Communications, the company that provides most of the ISPs in the US their access to the internet backbone.

Give the following command at a shell command line: BIND versions 9.9, 9.10, and 9.11 support DNSSEC validation using automatic RFC 5011 updating.

Another reason to change DNS servers is if you're looking for a better performing service.There is a companion document that describes how to check if you are using the latest trust anchors; you can find it here.