feel free...
don't know the current reliability of the DNSSEC evaluation by dnsmasq, have been using the unbound solution for a long time, however, I seem to remember, read here, it isn't supporting all algorithms and wasn't very reliable in the past.