> So how do we implement one?  Create a separate caching server with DNSSEC
> validation turned off and forward all queries for the broken domain to it?

That won't work, because a validating server validates replies from a
forwarding server.

