Some ISP redirect NXDOMAIN responses, another reason to run your own DNS resolver or use a public one.
The root server and big TLDs will not deploy DNSCurve
DNSSEC cannot be used directly to validate the DNSCurve public key, stored in the domain name of the parent NS record, as DNSSEC does not sign the domain name.