DNSSEC Disable for Forward Zone
When DNSSEC is enabled, all forward zones will request queries with DNSSEC enabled. Not all services allow DNSSEC responses, and therefore Bind will fail its lookup.
Usecase is where someone is running a Bind server with a forward zone for Emercoin TLDs. Emercoin TLDs are ofcourse not secured by DNSSEC, and therefore are unable to respond on requests where DNSSEC is enabled.
Disable DNSSEC per (forward) zone.
Links / references