Earlier quoted context omitted.
Just guessing but it could be the lack of adoption. Despite having climbed rapidly in the last few years [0] the percentage is still very low. [1] [0] - https://www.verisign.com/en_US/company-information/verisign-... [1] - https://www.statdns.com/
The low adoption of DNSSEC might be due to posts like these: https://news.ycombinator.com/item?id=36171696 - Calling time on DNSSEC: The costs exceed the benefits (2023) And also many news regarding validation failures: https://hn.algolia.com/?q=dnssec
https://www.potaroo.net/ispcol/2023-02/dnssec.html
(Geoff Huston is an Internet infrastructure giant.)
But really it all just boils down to the fact that the DNS zones that matter --- the ones at the busy end of the fat tail of lookups --- just aren't signed, despite 25 years of work on the standard. IPv6 is gradually mainstreaming; in countries where registrars auto-sign zones, DNSSEC is growing too, but very notably in countries where people have a choice, DNSSEC deployment is stubbornly stuck in the low single digit percentages, and the zones that are getting signed are disproportionately not in the top 10,000 of the Tranco list.