Does the opi support DNSSEC, i.e. does it verify the dnssec records when resolving host names? I.e. if I configure my mail server smtp.example.com does it verify it using DNSSEC?
Does opi run standalone dns resolver, something like bind or unbound or what?
Also it would be nice to have the op-i.me protected with DNSSEC. It seems .me-top level domain is signed, but op-i.me is not signed. The openproducts.com seems to be partially signed. There is DNSKEY for the openproducts.com, but there is no DS records in the .com delegating the domain securely to the openproducts.com name servers.
See http://dnsviz.net/d/openproducts.com/dnssec/ for current dnssec status of the openproducts.com.