Currently pimsync does not validate DNSSEC responses.
This is documented and users are responsible for using a validating revolver locally.
This should still be improved: we should use a validating revolver.
Consider hickory-resolver >= 0.25.0