Not tamper with the record directly, but MitM it on the way to a target.
That should be prevented by dnssec no?
That's what DNSSEC is for.
That should be prevented by dnssec no?