Quote from: jostreff on June 09, 2026, 10:54:13 AMI am experiencing the exact same issue with my slave zones transferred from a PowerDNS master.
The zone transfers (AXFR) complete successfully, and the SOA serial numbers match perfectly across all nsX.he.net nodes. However, any external DNSSEC validation tool (like DNSViz) throws an ECONNREFUSED error specifically when querying the Hurricane Electric Anycast IPs (e.g., 216.66.1.2) for DNSKEY records.
My zones are signed using Algorithm 13 (ECDSA Curve P-256 with SHA-256), which is the current modern standard. It seems that the HE Anycast edge servers either drop/refuse requests for these crypto keys or fail to parse the DNSSEC records properly if the algorithm isn't explicitly supported by the underlying legacy software version running on the nodes.
It's 2026, and it's quite disappointing that we still cannot properly host a modern DNSSEC-signed slave zone on HE's Free DNS platform without down-grading to obsolete algorithms like RSASHA1. Any chance the backend software will be updated to support current PowerDNS/BIND DNSSEC deployments?
Best regards,
Jordan