Can DNSSEC resolvers pass through all mangling CPEs?

Tony Finch
Mon Jan 4 13:22:25 CET 2016

DNSSEC detects and blocks mangling, it does not bypass it. If your CPE or
your ISP are lying to you, and you need to access the sites they are lying
about, your only option is to use a different upstream resolver; you might
also have to use a tunnel.

