Earlier quoted context omitted.
The best way to protect yourself against this kind of attack is DNSSEC. Plain and simple.
I dispute this, even though this seems like the one case where we're talking about an attack that actually lines up with what DNSSEC actually does. The reason is, what we're talking about is a massive misconfiguration. It's not an elaborate technical spoofing attack that takes advantage of the weakness of the underlying DNS. The mistake the .IO team made is just as easy to make in DNSSEC as it is with vanilla DNS.
I don't really understand your argument. I'm talking specifics and you seem to be talking about some hypothetical.