hickory 0.26.3 rejects two kinds of valid answers, and outbound delivery then retries those hosts until the message expires: - A zone delegated beneath an unsigned zone (l.google.com under google.com). Proving the delegation insecure needs an SOA record in the DS reply, and public resolvers often leave it out. Every Google MX host behind a signed MX record was unreachable. - A signed CNAME to a signed name that lacks the queried type. The NSEC denial is checked against the original name, not the target's. On a bogus verdict, follow a signed CNAME and repeat the lookup at its target; otherwise look up the name's zone and its parents, nearest first. A zone that validates as unsigned means nothing below it can be signed, so the plain resolver answers and the result is insecure. A zone that validates as signed first leaves the verdict standing.