I came just around this thread, while following the DANE progress:
Am 08.04.2014 um 21:48 schrieb Jeremy Harris <jgh@???>:
>> address. If you really want DNSSEC, you can apply it on the forward
>> lookup, it is unlikely that in-addr.arpa will be signed any time
>> soon.
>>
>
> ip6.arpa is - and I'd never have known if exim wasn't able to
> distinguish:
in-addr.arpa has been signed too (in 2011 AFAIK):
- - -
$ dig +dnssec PTR 192.8.111.131.in-addr.arpa.
[. . .]
;; flags: qr rd ra ad; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1
[. . .]
;; ANSWER SECTION:
192.8.111.131.in-addr.arpa. 85850 IN PTR tahini.csx.cam.ac.uk.
192.8.111.131.in-addr.arpa. 85850 IN RRSIG PTR 5 6 86400 20140501052605 20140401195913 41112 111.131.in-addr.arpa. KE0p2yIWf8koUd9fGZvuLokCr+c8R/u6QREyuXHOXuUf+UlbmBgCsSbk sfhlhlNVciKg7bt3eDcI8Z5IrFrqvqzqN2JSO1wi7o014O+V8DgEtSI+ lvsOlItylBNx73vF+eWnqbuHXBsIa3hvFfS8vqZfGA==
- - -
Axel
---
PGP-Key:29E99DD6 ☀ +49 151 2300 9283 ☀ computing @ chaos claudius