the solution is for the resolver to not use DNSSEC because it is broken. I have a domain that we hit and looking at the query stats we have for it I have a strong suspicion that it is returning invalid DNSSEC signatures when it is rolling over the signatures. I suspect it is either not rolling them fast enough and serving stale signatures or rolling them too quickly and serving signatures that are not valid for the current time. we do parallel queries to public recursive nameservers and the name servers we were using we returning SERVFAIL errors. its possible when making queries to recursive name servers to disable checking DNSSEC and we have enabled that option now.