A simple case on Disco+ that I believe is related to the DVE workaround is: resolvectl query www.engadget.com
DNSSEC doesn't appear to actually be involved on the domains. but with DNSSEC=(not yes) it works.
A simple case on Disco+ that I believe is related to the DVE workaround is:
resolvectl query www.engadget.com
DNSSEC doesn't appear to actually be involved on the domains. but with DNSSEC=(not yes) it works.