Too bad DNSSEC isn't widely used; signing the records would prevent this from working. The government could still block the DNS requests, though.
I am not just a DNSSEC hater, but the level of misunderstanding on DNSSEC is quite large.
When victim issues a query for youtube.com, I can intercept that query and hand back whatever response I want. Unless the victim KNOWS IN ADVANCE (which DNSSEC doesn't offer) that the response should be DNSSEC signed, they will accept my forged response.
DNSSEC solves problems we don't really have, and ignores the ones we do.