Here are some additional preliminary results from my root response size research. These results were from a zone signed with a 2048-bit ZSK. Note that different key rollover strategies were not researched here (I have a separate set of results for that), so some DNSKEY responses would truncate under some rollover scenarios at this ZSK size. Referral sizes (Maximum truncation sizes): range [629 - 845] min: NF/NS, max: AN/NS [576 - 639] : 7 [640 - 703] : 98 [704 - 767] : 128 [768 - 831] : 45 [832 - 895] : 3 Referral sizes (Maximum overall sizes): range [661 - 1185] min: NF/NS, max: AERO/NS [640 - 703] : 16 [704 - 767] : 59 [768 - 831] : 55 [832 - 895] : 60 [896 - 959] : 26 [960 - 1023] : 42 [1024 - 1087] : 14 [1088 - 1151] : 6 [1152 - 1215] : 3 NXDOMAIN sizes (Maximum truncation sizes): range [953 - 1298] min: @_/A, max: XN--HGBK6AJ7F53BBA_/A [896 - 959] : 1 [1216 - 1279] : 270 [1280 - 1343] : 10 Other response sizes (Full response sizes): range [410 - 2418] min: NF/ANY, max: @/ANY [384 - 447] : 32 [448 - 511] : 112 [512 - 575] : 106 [576 - 639] : 122 [640 - 703] : 60 [704 - 767] : 82 [768 - 831] : 28 [832 - 895] : 15 [896 - 959] : 4 [1216 - 1279] : 282 [2048 - 2111] : 1 [2368 - 2431] : 1 Again, the two responses over 1500 are ./RRSIG and ./ANY: 2073 1669 254 @/RRSIG 2418 2014 254 @/ANY