DNSSEC, the too-long-didn't-read version
DNSSEC documentation is measured in RFCs. Your domain needs one line. Type it, and your browser walks the real chain over DNS-over-HTTPS and answers the only question that matters. Every value below is fetched live; nothing is canned.
try
vantage: your browser → cloudflare-dns.com (1.1.1.1) over DoH, JSON API
Verify it yourself
Run these from a seat you trust. An intercepting router answers port 53
itself, so dig @1.1.1.1 from behind one shows you the router, not 1.1.1.1.
This page rides DoH (port 443), which is why the two can disagree.
The long version
See the chain drawn: every key, DS, and signature for this domain as a live graph, values on hover. The wiki has DNSSEC, signed and validated for how the chain works and DNSSEC troubleshooting for when it does not.
the spec is measured in RFCs. the verdict is one line.