The blog you quote is from 2015. Let's look at some recent numbers on DNSSEC/DANE deployment.


These graphs don't address any of the points. Even worse, those numbers don't say anything about how many DNS requests are actually verified... A good guess is that those crypto keys sit idle.

