As far as I know, there's really no "out of the box" validation for end users. The web browsers will have to make the validation, or failed validation, visible for people to care enough to implement it.
Although DNSSEC is becoming more and more commonplace, it still seems that in a lot of places, you'll have to throw up your own DNS-server to be able to use it. Make it simpler to implement, and you'll probably see a lot more people starting to use it.
Also, just to clarify, DANE doesn't _solve_ the CA-problem. You're now putting all your trust into it being hard to both issue a valid certificate and compromise the DNS chain.