Isolate DS NXDOMAIN responses. This will help when zones are grafted on using forward zones but is not a real fix as validating client will not work when the "parent" zone is signed as is the case when grafting on tld's this way.