Getting your dns signed with dnssec has become easier and easier with the more current versions of bind.
In fact, both bufferbloat.net (running on a x86_64 box) and http://jupiter.lab.bufferbloat.net (running on a mips based cerowrt box) are now both signed, and the overhead seems non-existent.
comcast is running a set of dnssec enabled dns servers now, as well, which work great as forwarders.
dns.comcast.net
There is a tool for firefox that can validate if your dns signed, here: