Nice! Great progress recently, but I have a basic question:
In the medium term, how do we make this work practically? Every device (or just every router?) will have a mini DNS server, which verifies that the DNS cert for npubXYZ.npub was signed by the corresponding nsec?