@bagder @icing how can you be sure of that without validating the DNS data you get using DNSSEC.
Again, DNS-over-HTTPS only secures the communication, not the data!
You could be speaking to malicious/spoofed end-point or poisoned caches.
Only way to validate the DNS data you get is by using DNSSEC.
Happy to explain more the differences, you coming to Netnod spring meeting?