I am very disappointed that GoDaddy claims to support DNSSEC, yet they don't support any of the required DNS resource records other than the delegated Signer (DS) resource records. Without having the TLSA record to associate a digital certificate with its use any other settings, let alone other DNSSEC RRs. It is like they gave us a car without an engine. Without the TLSA record you can't protect yourself against Man-in-the-Middle (MitM) attacks. Without the other DNSSEC records (e.g., NSEC, NSEC3, …) you are very limited in what you can do with DNSSEC.