From this posting:

http://www.internetsociety.org/deploy360/blog/2014/01/circleid-dns-security-should-be-one-of-your-priorities-including-dnssec/

I like this quote:

However, on the recursive resolver side, I am much more of a fan of having the DNS resolution occur as close to the end user as possible. This is particularly true when you enable DNSSEC validation.