I have made several DNS lookups using Sophos DNS Protection to assess the routing of our traffic and have observed that the resolved destinations often do not align with optimised routes. For instance, connections to Office 365 are being routed to servers in Germany (800-900 km away) instead of utilising local 'front doors' situated just 10-200 km away, as when using our ISP's DNS or services such as 1.1.1.1 or 8.8.8.8. Are there plans to introduce more local DNS resolves, for example in Stockholm, to improve routing efficiency?
Also, is DNSSEC validation on the roadmap for SFOS/XGS? DNSSEC is getting more relevant now when Microsoft is rolling out DNSSEC and DANE for the MX records in Exchange Online.