Hello Team,

I would like to ask why my new version of Knot Resolver does many records of "DNSSEC validation failure szn-broken-dnssec.cz. DNSKEY"
I tried to compare results with my second resolver on Unbound 1.9.4 where I'm able to receive an answer by command #unbound-control lookup szn-broken-dnssec.cz
but no answer via dig command #dig szn-broken-dnssec.cz
The same result via dig is on the server with new Knot Resolver 4.2.2

As was mentioned in your documentation https://knot-resolver.readthedocs.io/en/stable/modules.html#dnssec-validation-failure-logging
I tried the https://dnsviz.net/d/szn-broken-dnssec.cz/dnssec/
and the result is BOGUS,
then should I be worried about this message in my log?

Thanks for any answer, 
best regards
--
Smil Milan Jeskyňka Kazatel