Earlier quoted context omitted.
Who cares? If you control BGP, you control the meaning of the IP addresses DNS resolves to.
You’re also relying on the client validating DNSSec. I have no idea if/how/when this occurs, or if you can choose to ignore it.
A nit, but the resolver, not the client, validates DNSSEC. The client/stub resolver trusts its local resolver. That always struck me as weird.