Integrity, not confidentiality
The single most common misunderstanding about DNSSEC is treating it as an encryption technology. It proves a response is authentic and unaltered; it does nothing to hide the fact that a lookup happened or what was looked up. Confidentiality is a separate problem, solved by DoH or DoT.
Adoption is still uneven
Because DNSSEC requires the domain owner and the registry to both set it up correctly, a meaningful share of domains on the internet remain unsigned. A domain being unsigned is not itself a red flag, but it does mean that domain gets no protection against cache poisoning or spoofing from this particular mechanism.
Frequently Asked Questions
Does DNSSEC also encrypt what I am looking up?
No. DNSSEC verifies that a DNS response is authentic and has not been tampered with -- it is not an encryption technology and does not hide the content of a lookup. For that, you would need DoH or DoT.
Is every domain protected by DNSSEC?
No. DNSSEC has to be explicitly configured by the domain owner and registrar, so it is an opt-in feature rather than something applied universally, and plenty of domains still are not signed.