The root DS exists outside of DNS hierarchy, so its NSEC proving non-existence always contains the SOA, as that's the root of DNS and there's nothing above it.
It's reproducible by asking for DS .
The root DS exists outside of DNS hierarchy, so its NSEC proving non-existence always contains the SOA, as that's the root of DNS and there's nothing above it.
It's reproducible by asking for DS .