About DDNS and DNSSEC: they don't work well together because DDNS requires private (zone) keys are online to update signatures when DNSSEC works well and safer with offline keys. Regards Francis.Dupont@enst-bretagne.fr PS: I locally solved this operational issue with a dedicated DDNS sub-zone.