DANE technically achieved that, I played around with OpenSSL plugin for DANE back in 2010 (when the . was signed). But yeah, I get your point.
Right now, the path ahead is stapled DANE TLS extension.
Basically, the idea is that you can use simple unauthenticated DNS to get the domain name, just like now. Then you get the complete DNSSEC-authenticated DNS chain for the DANE record as a part of the TLS handshake: https://datatracker.ietf.org/doc/rfc9102/
This seems to be the best of both worlds:
1. We keep DNS as a simple and nimble UDP-based service, without trying to cram the signature in each packet.
2. Since we HAVE to use TLS anyway to achieve any meaningful security, we can just transmit the full DNS chain (up to the root zone!) with signatures easily as a part of the TLS handshake.
3. The client then just needs to validate this chain, and it only needs to have the root zone's key as the root of trust.
4. The root zone's key changes fairly infrequently (once in a decade), so IoT devices can use it to bootstrap themselves.