Knot Resolver: Resolve DNS names like it's 2022! https://www.knot-resolver.cz/support/
Note that Quad9 have not announced a SPKI pinset.
Base 64 encoded form of SPKI pin(s) for TLS authentication (RFC7858)
https://letsencrypt.org/certs/isrgrootx1.pem.txt
is not enough
$ openssl s_client -connect dns.quad9.net:853
CONNECTED(00000003)
depth=2 O = Digital Signature Trust Co., CN = DST Root CA X3
verify return:1
depth=1 C = US, O = Let's Encrypt, CN = Let's Encrypt Authority X3
verify return:1
depth=0 CN = dns.quad9.net
verify return:1
-- BEG/END CERT --
lines).
$ nm -D path/to/kresd | grep engine_hint_root_file
000000000000a980 T engine_hint_root_file