.onion might be exempt but while the TLD "." is anycast worldwide for the actual DNS service, Verisign still signs the cert. Isn't that a show-stopper for dependencies on dns-over-https or https altogether or do .cn, .ru, .ir etc all add/replace with their own independent signatures ?