End of life statements
======================
-The currently supported release train of the PowerDNS Recursor is 4.x.
+The currently supported release train of the PowerDNS Recursor is 4.1.
-PowerDNS Recursor 3.7 is considered legacy and will only receive
-critical bug fixes and security fixes.
+PowerDNS Recursor 4.0 will only receive correctness, stability and security updates.
-PowerDNS Recursor 3.6 will only receive security fixes.
+PowerDNS Recursor 3.x, and 2.x are end of life.
-PowerDNS Recursor 3.5, 3.4, 3.3, 3.2, 3.1, 3.0 and 2.x are end of life.
+Note: Users with a commercial agreement with PowerDNS.COM BV or Open-Xchange
+can receive extended support for releases which are End Of Life. If you are
+such a user, these EOL statements do not apply to you.
===============================
As of 4.0.0, the PowerDNS Recursor has support for DNSSEC processing and experimental support for DNSSEC validation.
+.. warning::
+ The DNSSEC implementation in the PowerDNS Recursor 4.0.x is known to have deficiencies due to its original design.
+ When doing DNSSEC validation, ensure you are running 4.1.0 or later which has a fully reworked (and correct) DNSSEC implementation.
+
DNSSEC settings
---------------
The PowerDNS Recursor has 5 different levels of DNSSEC processing, which can be set with the :ref:`setting-dnssec` setting in the ``recursor.conf``.