diff --git a/man/resolved.conf.xml b/man/resolved.conf.xml
index 213be1d7b2c..818000145b9 100644
--- a/man/resolved.conf.xml
+++ b/man/resolved.conf.xml
@@ -210,8 +210,9 @@
send for setting up an encrypted connection, and thus results
in a small DNS look-up time penalty.
- Note as the resolver is not capable of authenticating
- the server, it is vulnerable for "man-in-the-middle" attacks.
+ Note that in opportunistic mode the
+ resolver is not capable of authenticating the server, so it is
+ vulnerable to "man-in-the-middle" attacks.
In addition to this global DNSOverTLS setting
systemd-networkd.service8