Verify DNSSEC delegation signer records.
DS (Delegation Signer) records establish the chain of trust in DNSSEC. They're published in the parent zone and contain a hash of the child zone's DNSKEY. This allows resolvers to verify the authenticity of DNSSEC-signed zones.