On 6 mar 2012, at 15:04, Carlos Martinez-Cagnazzo wrote: > The one difference that comes to mind is that NSEC3 doesn't make a lot sense in the reverse space, as anyone can walk the zones anyway, so we (LACNIC) will be using NSEC for signed negative responses. Except perhaps for IPv6 ? jakob