On-device DNSSEC validation over an injected DohWireTransport; unsigned and invalid answers fail closed.
DnssecResolver performs validation locally and clears any resolver-provided AD
bit before evaluating an answer. Callers control the DNS-over-HTTPS transport,
including whether it connects directly or through SOCKS. The transport remains
owned by the caller and must be closed when it is no longer needed; see
example/dnssec_resolver_example.dart.
The released Hickory dependency contains the IANA KSK-2017 and KSK-2024 root anchors. KSK-2024 is required for the root signing-key rollover scheduled for October 11, 2026. IANA schedules KSK-2017 for revocation on January 11, 2027 and removal on March 22, 2027. The native test suite deliberately fails at the revocation date until the pinned trust-anchor set is reviewed and updated.