On 6/2/21 11:07, Jeroen Massar via NANOG wrote:

As for solutions: better education, more improvements to the tools & making it easier. CDS records already help a lot. But we might also need to improve recovery mechanisms, as f-ups are made, and you don't want to be off this Internet thing for too long.

I think DNSSEC implementation needs to be made less scary for folk who are apprehensive, and broken down into two steps, where step 1 is most emphasized:

             dnssec-enable yes;
             dnssec-validation auto;

        Done! Two lines (BIND, in this case), and off you go.

Mark.