So, that wasn't fun, yesterday:
https://lists.dns-oarc.net/pipermail/dns-operations/2021-September/021340.html
We were also hit, given we run DNSSEC on our resolvers.
Interesting some large open resolver operators use Negative TA's
for this sort of thing. Not sure how this helps with the DNSSEC
objective, but given the kind of pain mistakes like these can
cause, I can see why they may lean on NTA's.
Mark.