In deSEC's GUI, when you add a domain, you can expand an "Advanced" section and paste your zonefile.
You can do the same via the REST API using the "zonefile" parameter in your request.
> often either giving a vague error ("one or more records could not be imported"),
When there's an issue, the response will tell you which line it was. Perhaps that can be improved - we'd appreciate feature requests about that.
> just silently omitting records
We omit records that we manage ourselves, that is: SOA, NS, DNSKEY, RRSIG. Everything else is retained, and in fact deSEC has unusually broad record type support (see https://desec.readthedocs.io/en/latest/dns/rrsets.html#recor...).
(Disclosure: I'm CTO at deSEC.)