tldr-dnssec
DNSSEC, the too-long-didn't-read version
DNSSEC documentation is measured in RFCs. Your domain needs one line. Type it, and your browser walks the real chain over DNS-over-HTTPS and answers the only question that matters. Every value below is fetched live; nothing is canned.
try
vantage: your browser → cloudflare-dns.com (1.1.1.1) over DoH, JSON API
Verify it yourself
port 53 behind an intercepting router: the router answers
this page: DoH 443
The long version
See the chain drawn: every key, DS, and signature for this domain as a live graph, values on hover. The wiki has DNSSEC, signed and validated for how the chain works and DNSSEC troubleshooting for when it does not.