DNSSEC support in systemd is broken for almost 5 years now
github.com
github.com
Though to donselaar's point there will be governments and I suspect eventually fin-tech that will be regulated into signing and that's great especially for B2B/Gov2B connections that could use an extra form of verification. No harm in that. Optional for me, mandatory for more sensitive things and they are powerful enough to put pressure on DNS providers to make DNSSEC less error prone with time. Maybe once it has more adoption and is less error prone I may re-enable it.