When a DNS resolver queries for a domain, the response contains additional records. The question is: "is the DNS resolver required to follow those instructions, or are they optional"?
When a DNS resolver queries for a domain, the response contains additional records. The question is: "is the DNS resolver required to follow those instructions, or are they optional"?
The resolver is free to discard those records and check them itself, and this is sometimes useful for security. Google do this.
Records in the Additional Section are completely optional, and these days generally ignored for the most part.
In particular, several of the weaknesses in the DNS protocol were caused by giving too much credence to those records.