Likely not related to your observation, but note that resolution of the same domain may produce different results if you use upstream servers that each would employ different filtering strategies (i.e for a domain that is allowed by Pi-hole and forwarded upstream, Quad9 may block a domain that digitalcourage would not).
This is happening independently from your observation, posing a separate issue.
Since switching off DNSSEC allows you to resolve, regardless of upstream servers, that would suggest an issue with the configuration of DNS servers authoritative for the domains you cannot access when DNSSEC is enabled.
Have a look whether the DNSSEC related replies from your logs would hint at resolution denials (BOGUS
) due to failed DNSSEC validation, see also Understanding DNSSEC validation using Pi-hole's Query Log).