So DNS should be open to MITM attackers?
Even with DNSSEC, it still is. Example: https://blog.cloudflare.com/de-tld-outage-dnssec/
Even with DNSSEC, it still is. Example: https://blog.cloudflare.com/de-tld-outage-dnssec/