diff --git a/man/resolved.conf.xml b/man/resolved.conf.xml index 213be1d7b2c..818000145b9 100644 --- a/man/resolved.conf.xml +++ b/man/resolved.conf.xml @@ -210,8 +210,9 @@ send for setting up an encrypted connection, and thus results in a small DNS look-up time penalty. - Note as the resolver is not capable of authenticating - the server, it is vulnerable for "man-in-the-middle" attacks. + Note that in opportunistic mode the + resolver is not capable of authenticating the server, so it is + vulnerable to "man-in-the-middle" attacks. In addition to this global DNSOverTLS setting systemd-networkd.service8