Earlier quoted context omitted.
Virtually everyone relies on ISP DNS servers, which can trivially bypass DNSSEC (DNSSEC collapses down to a single bit in the header on the last hop from server to stub resolver). If all you're trying to do is resist DNS censorship, you can get almost everything you need from using an out-of-country name and DoH, which is universally available, very much unlike DNSSEC.
DNS without DNSSEC is pretty much vulnerable to the kind of censorship that won't even let you know you are being censored... Any name system without something equivalent to DNSSEC is. With DNSSEC it is still vulnerable, but only to the kinds that you will know you are being censored, so you can try to get it from another country or another channel. If your ISP denies DNSSEC for you, you already know you are being at…
The only way around this is for local systems to do their own recursive resolution, which isn't the default configuration on any OS or distribution that I'm aware of.