--trust-anchor=<domain>,[<class>,][<key-tag>,<algorithm>,<digest-type>,<digest>]
Provide DS records to act a trust anchors for DNSSEC validation. The class defaults to IN. Typically these will be the DS record(s) for Key Signing key(s) (KSK) of the root zone, but trust anchors for limited domains are also possible. A negative trust anchor (ie. proof that a DS record doesn't exist) may be configured be specifying only the name or only the name and class. This can be useful for forcing dnsmasq to treat zones delegated using --server=/<domain>/<ip-address> as unsigned. The current root-zone trust anchors may be downloaded from https://data.iana.org/root-anchors/root-anchors.xml