> there are ISPs who are internally capturing, and who try to
> do the same with  Which is why itâ??s so important to do
> cryptographic validation of the server and encryption of the
> transport, as well as DNSSEC validation.

And the good thing is that RFC 8310 has been published one week
ago. I'm waiting for its deployment in Quad9 :-)