Resources
What is DNSSEC?
DNSSEC signs the records in a zone so a resolver can prove the answer it received is the one you published.
Plain DNS answers can be forged in transit. DNSSEC adds signatures over the record sets, and a chain of trust from the root down to your zone.
The chain closes at the registrar: a DS record there points at the key in your zone. Signing without publishing the DS proves nothing.
Key rollovers and signature lifetimes have to be handled, which is why DNSSEC is a service, not a checkbox.
At CTPFDNS signing is being rolled out: a domain is signed once its move to our nameservers is complete.