Would you not be exposing those subdomains via DNS anyway?
It does not prevent people guesssing it tough.
There's a hack to prevent this that seeds the zone with false entries, but it requires the server to operate as an online signer. Since this is essentially incoherent to the design of the protocol (which makes major cryptographic and usability sacrifices to enable offline signers), there's an "NSEC4" being worked on now.
DNSSEC is silly.