OPT-IN
changes the granularity of DNSSEC security from "zone" to ”owner name”
based upon playing a trick with NXT to make it jump from one secured node to the next (ignoring unsecured stuff in between)
gives up authenticated denial of existence (for unsecured nodes)
obviously designed for the needs of delegation-heavy zones like TLDs