I happen to run an affordable EU supplier who does DNSSEC, and also AXFR (incoming and outgoing). I offer a free plan from time to time, but not at the moment to preserve resources for paying customer.
Looks like it's the glue records that point to the actual server?
This is fixed now, I'll look into why the monitoring tools didn't catch this one as they should have.