Let's get more logging. Enable more debugging in named. What made named think that name should be DNSSEC signed in the first place? Do you only have the problem resolving the single name and it doesn't happen every time? Does the problem ever happen without using your forwarders? Also do the query with delv -d99 and record that verbose output.