diff --git a/doc/man/knot.conf.5in b/doc/man/knot.conf.5in
index 4585c68538b4b03ccb00f5def126950bcf808bd4..f58de129c48b55f28075ee0a373650d0e4887976 100644
--- a/doc/man/knot.conf.5in
+++ b/doc/man/knot.conf.5in
@@ -1971,15 +1971,11 @@ Missing NS record at the zone apex
 .IP \(bu 2
 Missing glue A or AAAA record
 .IP \(bu 2
-Invalid DNSKEY, DS, or NSEC3PARAM record
+Invalid DS or NSEC3PARAM record
 .IP \(bu 2
 CDS or CDNSKEY inconsistency
 .IP \(bu 2
-Missing, invalid, or unverifiable RRSIG record
-.IP \(bu 2
-Invalid NSEC(3) record
-.IP \(bu 2
-Broken or non\-cyclic NSEC(3) chain
+All other DNSSEC checks executed during \fI\%dnssec\-validation\fP
 .UNINDENT
 .sp
 \fBNOTE:\fP
diff --git a/doc/reference.rst b/doc/reference.rst
index 32937f4cd520e9e6c0dc2b7e98cd6091fb6d85f3..8b91957f6c0af6ada4bd1f2930b6efe10735d726 100644
--- a/doc/reference.rst
+++ b/doc/reference.rst
@@ -2148,11 +2148,9 @@ Extra checks:
 
 - Missing NS record at the zone apex
 - Missing glue A or AAAA record
-- Invalid DNSKEY, DS, or NSEC3PARAM record
+- Invalid DS or NSEC3PARAM record
 - CDS or CDNSKEY inconsistency
-- Missing, invalid, or unverifiable RRSIG record
-- Invalid NSEC(3) record
-- Broken or non-cyclic NSEC(3) chain
+- All other DNSSEC checks executed during :ref:`zone_dnssec-validation`
 
 .. NOTE::
    The soft mode allows the refresh event to ignore a CNAME response to a SOA