paste a ds or dnskey record into the field above to use. the given name servers must be authoritative for the same zone as the trust anchor - i.e., the name server must match the zone in which the trust anchor is located if it is not already published in the dns. qr = 0 tc = 1 rd = 0. opcode = noerror ;; do =