So why are we not constantly seeing real world compromises of major sites that don't use DNSSEC?
Here's one: https://notes.valdikss.org.ru/jabber.ru-mitm/
Here's one: https://notes.valdikss.org.ru/jabber.ru-mitm/