Default Sovite.DNS.Resolver, built on OTP's :inet_res.
It sends queries to the nameservers configured for the VM (usually from
/etc/resolv.conf). It does not cache results and does not validate
DNSSEC itself.
lookup_secure/3 asks for DNSSEC data (EDNS0 with the DO bit and the
AD bit set, RFC 6840 §5.7) and reports the AD bit of the answer. That
bit is only meaningful from a validating resolver you trust, normally
one on the same host (such as Unbound on 127.0.0.1): anyone on the
path to a remote resolver can set it.
Options
:nameservers- list of{ip, port}tuples that override the system nameservers.:timeout- per-query timeout in milliseconds. Defaults to5000.:retry- number of retries per nameserver. Defaults to2.