I have been assigned the task of improving security of a specific service. After some analysis of the requirements we have come to the conclusion, that a certain aspect of the specified requirements can only be met through the use of DNSSEC.
I have a decent amount of experience with information security and cryptography, and I believe I understand the general principles in DNSSEC. However I have no hands on experience.
Usually such new technologies first get deployed to a subdomain of our primary domain name. But that approach doesn't seem to be possible with DNSSEC, since a proper deployment involves signing all the way from the root servers to the subdomain. Our domains currently have no DNSSEC and the hosting provider doesn't support DNSSEC.
Buying an experimental domain through a separate hosting provider might be an option, but due to lack of hands on experience with DNSSEC I have no clue what to look for in such a hosting provider.
I have also considered using one of the numerous services where one can acquire a free subdomain with dynamic DNS. However none of the providers I have looked at so far supports DNSSEC.
What would be a sensible next step to take in order to get the hands on experience I need?