[wg chair hat off]
A different approach to solve the DNS search path issue would be for
clients to use a trusted DNS search path, i.e., one not acquired
through DHCP or other autoconfiguration mechanisms.
Good.
Since there is
no way for the DNS lookup APIs to tell whether a search path is
from
a trusted source, the entire client system would need to be
configured with this trusted DNS search path.
I'd say "No way with current DNS lookup API's to tell.." instead of
assuming that this will be true for all time..