Based on pricing ($9.99/.com) and a growing irritation with GoDaddy, I finally moved my domains to Dynadot:
They have a (custom) 2FA app and 2FA SMS. BTW this friend referral https://www.dynadot.com/?s9N6j7d9G8B07i73 gives you & me $5 after purchase.
DNSSEC is an important trust root that can be used to pin certificates in addition to PKIX (CAs), or, in some practical cases (such as mailservers), instead of them.
Are you still running Telnet?
FWIW, I use the Firefox addon "DNSSEC Validator" (also does DANE) - https://www.dnssec-validator.cz/ - So if somebody managed to MITM my connection and insert a different, but still trusted, cert in the way, I'd notice.
DNSSEC/DANE would probably see a lot more adoption if one or more of the main browsers did this sort of validation by default.
(Slightly confused by this board.)
If your registrar currently accepts DS records, please
send an email with subject "DNSSEC REGISTRAR UPDATE"
and body containing company name, country location, URL,
what TLDs you accept DS records for, whether your Web
interface supports DS records, whether you provide
DNSSEC signing services to dnssec@icann.org and the
Security team will add your registrar to this DNSSEC
page.