Google now fully supports DNSSEC validation on Google Public DNS resolvers. DNS cache poisoning is the most common DNS attack, which tries to pollutes cache by injecting spoofed responses to upstream DNS queries. Only 7% of queries from the client side are DNSSec-enabled. Only 1/3 of top-level domains have been signed, but most second-level sites remain unsigned. Google is serving more than 130 billion DNS queries on average (peaking at 150 billion) from more than 70 million unique IP addresses each day.”]
Source: https://security.googleblog.com/2013/03/google-public-dns-now-supports-dnssec.html

