Configuration
The libraries work with their default settings. Two of those settings decide what your integration trusts. The first is how the library reads DNS. The second is what the secure flag means.
API reference:JavaScript
DNS resolvers: several perspectives by default
Every result depends on DNS records. A forged DNS answer could put an attacker's key into a user's records. To limit this, the library reads DNS through several independent resolvers at the same time, and it keeps only the records that all of them return.
To add a forged record, an attacker must forge the answers of every resolver at once. To remove a record, one forged answer is enough. This is safe, because a missing record can only deny a sign-in. It cannot grant one.
You can change the resolvers, for example to use resolvers that you run yourself. Keep more than one, and keep them independent.
The secure flag: DNSSEC on every record
Every result carries a secure value. It is true when the resolvers reported DNSSEC validation for every DNS record behind the result, including the domain's triauth record. It is false when at least one record was not protected. The library does not validate DNSSEC on its own. It relies on the resolvers and the cross-check between them.
Many domains have no DNSSEC. For such domains, the library returns results with secure: false, and you decide what to do with them. If you wish to accept only protected identities, set the library to require DNSSEC. Results that are not protected then fail with an error instead of a result.
A user whose results change from true to false is a warning sign. Treat it as you would treat a sign-in from a new device.