Check ECS response in DiG for RFC compliance
We have seen servers that return ECS responses that don't meet this requirement.
RFC 7871, 7.2.1. Authoritative Nameserver FAMILY, SOURCE PREFIX-LENGTH, and ADDRESS in the response MUST match those in the query. Echoing back these values helps to mitigate certain attack vectors, as described in Section 11.
Add a warning when the ECS response fails to meet this requirement.