We're currently working on providing DNSSEC for our customers. The problem with only signing is that we really don't want all the keys to be physically present on our DNS servers, as many of them are hosted in other companies data centres.
Having a central online signing server is bad for availability, as DNS down time is really not acceptable.
That basically only leaves offline signing.