It's not just a problem for NXDOMAIN. Their DNSKEY response is over 1250 bytes, so those who use a lower limit (e.g. 1232 recommended by dnsflagday.net/2020) will have no access to that subtree at all. --Vladimir