log DNSSEC validation failures on normal level
DNSSEC validation failures should not occur at all during normal operations.
Feedback from operators indicates that at least at least domain name and qtype from queries which failed DNSSEC validation should be logged by default.