Hello, I try to replace a validating unbound-resolver with stubby (DNS-via-TLS to this unbound-resolver) and found dnssec validation differences. how should I configure stubby to make "dig @stubby dnssec-failed.org." return SERVFAIL and "dig @stubby getdnsapi.net." return data with AD bit set? Andreas