Hi,
could it be, that servers to which you forward queries are not authoritative only?
Maybe they are forwarding queries to some other servers, or there is recursion enabled on
them?
When I was migrating from kres5 to kres6 I did also run into troubles with complicated
historical DNS setup where some subzones were forwarded to other targets. I ended up with
setting authoritative: false which solved the issue for me. But not sure if you have
similar problems.
Here is the old list:
https://lists.nic.cz/hyperkitty/list/knot-resolver-users@lists.nic.cz/threa…