Checks

DNSSEC records are incomplete

Some DNSSEC records are present, but the chain did not validate.

Why it matters

A partial deployment can cause validating resolvers to treat the name as bogus.

What to do

Finish the chain from the zone through the parent DS, or remove the partial records.

Reference

DNSSEC adds cryptographic authenticity to DNS responses.

ICANN — DNSSEC