After some searches I think I have the answer. According to the RFC 1034 (maybe in 5.3.3), nothing forces a recursive DNS resolver to behave like a `dig +trace`, end of story. Is that about right? At least I have learned how to compile unbound from source and run it in a docker. :) Bye. -- François Lafont