DNSSEC validation succeeds even if the chain does not reach the trust anchor
https://www.next-gen.ro shows with green key icon. However, the .ro zone is not signed as shown here: http://dnssec-debugger.verisignlabs.com/www.next-gen.ro
https://www.next-gen.ro shows with green key icon. However, the .ro zone is not signed as shown here: http://dnssec-debugger.verisignlabs.com/www.next-gen.ro