Warda asks the upstream servers with the AD bit (RFC 6840): a validating
resolver says whether it checked the signatures, without sending them. The
answers validated are counted. A minute after the start, then every 6 hours
(task dnssec.check), each upstream is asked isc.org (signed: AD
expected) and dnssec-failed.org (signed wrong: SERVFAIL expected): it
validates, or not. With Only ask the upstream servers that validate
DNSSEC (PUT /api/v1/dns-services/dnssec, meta dnssec_require), only
those are asked while at least one is known to validate; the others only
when none of them answers (names never stop resolving). POST /api/v1/dns-services/dnssec/check
checks at once.