RFC 5155: Zones using Opt-Out MAY contain a mixture of Opt-Out NSEC3 RRs and non-Opt-Out NSEC3 RRs. Each owner name within the zone that owns authoritative RRSets MUST have a corresponding NSEC3 RR. Owner names that correspond to unsigned delegations MAY have a corresponding NSEC3 RR.
RFC 5155: If there are multiple NSEC3PARAM RRs present, there are multiple valid NSEC3 chains present. The server must choose one of them, but may use any criteria to do so.
Seshadri, Shyam: DNSSEC on Windows 7 DNS client. Port 53. Microsoft, 2008. november 11. [2009. november 7-i dátummal az eredetiből archiválva]. (Hozzáférés: 2011. november 26.)
Seshadri, Shyam: DNSSEC on Windows 7 DNS client. Port 53. Microsoft, 2008. november 11. [2009. november 7-i dátummal az eredetiből archiválva]. (Hozzáférés: 2011. november 26.)