- Verisign Labs are kindly hosting a test zone on a server (running a patched version of NSD):
The zone is named starttls.verisignlabs.com and it has A, AAAA, and TXT records for names from 'A' to 'Z'.
The IP address of the server is currently 126.96.36.199.
Server key file is available to download here: nsd.key
The zone is signed
- This server also supports TCP fast open
How to Decode TLS packets in Wireshark
If you want to decode the DNS packets in Wireshark (use 1.12.1 or later) to get support TLSv1.2