Wrote a proof of concept DNSSEC Oracle on Algorand: proves TXT records on-chain, every signature checked from the root down, without trusted intermediaries. Same trust model as DNSSEC, relies only on the IANA root KSKs, with trustless rollover support.
You can explore it here:
dnssec-oracle-testnet.pages.…
"what does it do?"
Domain owners publish values as TXT records (e.g. "admin=ABC..") and anyone can bring them on-chain, without the sender being trusted. If it is on the Oracle, it was backed by cryptographic signatures all the way down.
Unaudited and highly experimental. Includes home-made RSA validation in Algorand TypeScript: @d13co/puya-ts-utils/rsa