DNSSEC not detected
This scan did not see a validating DNSSEC chain for the name.
Why it matters
Without DNSSEC, resolvers cannot cryptographically reject a forged answer.
What to do
Sign the zone and publish a DS record at the parent if you want DNSSEC.
Reference
DNSSEC adds cryptographic authenticity to DNS responses.