A problem there is needing to temporarily delete the entire domain just to update using a zone file. I don't manage the DNS for anything remotely critical, but if I did, it would be unacceptable. Either way, the workflow
feels deeply incorrect (though most users likely will use the record editor or the API instead; even I'd use the API through DNSControl, now).
Logging back into deSEC right now, it seems like the parser does work better than it used to, but TTL inheritance is still spotty. As an extreme example, the following input:
@ 7777 IN SOA x. x. 1 9999 9999 9999 9999
A 203.0.113.1
4444 AAAA 2001:db8::1
www A 203.0.113.1
... correctly gets parsed by BIND (with the addition of a dummy NS record) as:
@ 7777 IN A 203.0.113.1
@ 4444 IN AAAA 2001:db8::1
www 4444 IN A 203.0.113.1
... but deSEC parses:
@ 9999 IN A 203.0.113.1
@ 4444 IN AAAA 2001:db8::1
www 9999 IN A 203.0.113.1
... where 9999 is a $TTL value from a different zone file, from a different domain, that I'd imported in a completely different session. The value is permanently (?) stuck to the entire account. This is ultimately almost a squabble since there's simple workarounds, but it did affect me when I used deSEC, and it's the sort of problem that I constantly run into with other managed DNS services too.
Hopefully this helps in some way.