dnssec makes no sense if it's not supported by all of your servers. It means that an invalid DNS response would still slip through if it came from one of the DNS servers that do not support DNSSEC. Kinda like having a door lock on the front door, and an open window right next to it...