they won't work exactly as in real zones on authoritative servers.
For example, wildcards won't get expanded and DNAMEs won't cause occlusion.
+ .. _config-local-data-rpz:
Response Policy Zones (RPZ)
---------------------------
.. warning::
- Some validation steps are however dynamic (for example resolving of interface names) and can not be premodeled for validation and even completed without running the resolver.
+ Validation can't fully guarantee successful startup.
+ Some conditions are checked at runtime, such as the resolution of interface names.
.. tip::
^^^^^^^^^^^^^^^^^^^^^^^^^
Some jurisdictions mandate blocking access to certain domains.
-This can be achieved using by using :option:`rules <rules: <list>>`.
+This can be achieved e.g. by using :option:`rules <rules: <list>>`.
+(Or you might use a :ref:`RPZ file <config-local-data-rpz>`, as many resolver implementations accept that format.)
.. code-block:: yaml