- PERFORMANCE OF THIS SOFTWARE.
-->
-<!-- $Id: FAQ.xml,v 1.45 2008/09/09 05:02:38 marka Exp $ -->
+<!-- $Id: FAQ.xml,v 1.46 2008/09/09 05:42:17 marka Exp $ -->
<article class="faq">
<title>Frequently Asked Questions about BIND 9</title>
</question>
<answer>
<para>
- NSEC3 records are strictly meta data and can only be returned in
- the authority section. This simplifies processing and removes
- the paradox of a NSEC3 record proving it's own non-existance.
+ NSEC3 records are strictly meta data and can only be
+ returned in the authority section. This is done so that
+ signing the zone using NSEC3 records does not bring names
+ into existance that do not exist in the unsigned version
+ of the zone.
</para>
</answer>
</qandaentry>