Traditionally DNSSEC how-tos start with a variation of:
Be prepared for higher resource consumption when you enable DNSSEC validation.
Is that still true in 2022? According to our measurements - not really.
In this talk, we compare answer latency, resolver CPU usage, memory consumption, and network bandwidth between validating and non-validating configurations of a busy ISP resolver running BIND.