It would be good to be able to have local DNSSEC validation work (especially if we want to use TLSA). I also serve authoritative DNS using NetBSD currently and for over a decade. I am fine with installing an authoritative server via a package.