In the DNSSEC check, should there not be a test on the algorithm and digest type? Some should be seen as insecure / phased-out https://dnsthought.nlnetlabs.nl/vis/ https://www.iana.org/assignments/dns-sec-alg-numbers/dns-sec-alg-numbers.xhtml https://www.iana.org/assignments/ds-rr-types/ds-rr-types.xhtml