How to measure the impact of enabling DNSSEC?

Augie Schwer augie.schwer at
Tue Jan 22 19:40:08 UTC 2013

Would measuring the number of SERVFAIL entries in the "query-errors"
category be a good indicator of what impact enabling DNSSEC has?

I am replaying some production traffic at a test instance; once with DNSSEC
enabled and once with it disabled and then counting the number of entries
logged via the query-errors category to get an indication of what impact
enabling DNSSEC on my production hosts would be.

Is this a good way to measure? Is there a better way?

