After reloading the server configuration file, additional DNSSEC resource records are auto-magically generated. By default, BIND will generate NSEC records. If you wish to use NSEC3 instead, please follow the additional steps described in the section called “Migrating from NSEC to NSEC3”. To learn more about the difference between NSEC and NSEC3, please see the section called “Proof of Non-Existence (NSEC and NSEC3) ”.