I could verify this using data from @cloudflareradar data:
https://radar.cloudflare.com/tlds/de?dateRange=2d#certificate-issuance-volume
You can see the sharp drop in #certificate issuance during the period that #de #TLD was having #DNSSEC issues.
This is actually good news. It indicates that CAs are using DNSSEC for domain validation.





