The DNS traffic doesn't need to be secret ("encrypted"), it just needs to be authenticated (i.e. the payload has not been modified and there is a chain of trust).
If a client is pre-seeded with trusted root keys, DNSSEC protected payload can be validated to the apex.