I wonder if they're planning on implementing DNSSEC, given that this change is a prerequisite for full DNSSEC support. They would also have to be willing to use a less user-friendly method of blocking phishing domains (like return an unsigned NXDOMAIN that doesn't validate).

