Survey says: 5.2 million DNSSEC domains, and ~12,000 with 512-bit RSA keys concentrated at just two small DNS providers. So good job knowing only the few stuck with early 90's export crypto. :-) They'll be shamed into fixing this soon enough. An even larger provider that had 512-bit RSA keys no longer does.
And even a 512-bit RSA key is slightly better than nothing. One needs to remember that DANE in SMTP is a mechanism for downgrade-resistant transition from unauthenticated opportunistic STARTTLS to authenticated required STARTTLS.
Below is the frequency table for RSA key lengths in zone signing keys (primarily 1024-bit RSA keys):
count | bits
---------+------ 8402 | 4096
1135 | 3168
17 | 2432
103 | 2304
20 | 2088
5 | 2064
55927 | 2048
15 | 2024
315 | 1536
17 | 1352
43 | 1304
185095 | 1280
63 | 1152
74 | 1048
291 | 1032
4019966 | 1024
28 | 768
12545 | 512
The KSK (key-signing keys registered in parent DS RRs) RSA key size frequencies are (mostly and increasingly 2048-bit): count | bits
---------+------ 39715 | 4096
11 | 3248
1149 | 3168
47 | 3072
267 | 2560
25 | 2304
20 | 2088
3051386 | 2048
17 | 1552
180111 | 1536
171 | 1304
1568 | 1280
34 | 1152
1118500 | 1024
11806 | 512