@lanodan Just for fun, try a request for a non-existant TLD¹: answer is already ≈ 1,000 bytes (there is 6 records in the NXDOMAIN answer: SOA, NSEC for the domain you queried and NSEC for root. Plus the signatures of the 3 records).
RSA 4096 would create answers > 1232 bytes in those cases, thus answers will be truncated and queries should be retried using TCP. Lots of resources (and time) wasted
¹ eg. dig +dnssec grrrr