Like IPv6, DNSSEC is one of those great forward-looking protocols that
unfortunately hasn't seen wide adoption yet. Before I implemented it myself, I
could see why. Although some people think BIND itself is difficult to set up, DNSSEC
adds an extra layer of keys, key management and a slew of additional DNS
records.