log DNSSEC validation failures on normal level

DNSSEC validation failures should not occur at all during normal operations.

Feedback from operators indicates that at least at least domain name and qtype from queries which failed DNSSEC validation should be logged by default.

To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information