To turn on DNSSEC validation on your recusrsive resolver you only need to enable it and include the root trust anchor. For example on BIND /etc/namedb/named.conf you might look like below. Make sure to remove or comment (//) out "recursion yes" and "dnssec-validation yes" and do a "service named restart" when done with this exercize to return your nameserver to authoritative server mode.
# cat /etc/namedb/named.conf
options {
directory "/etc/namedb/working";
pid-file "/var/run/named/pid";
dump-file "/var/dump/named_dump.db";
statistics-file "/var/stats/named.stats";
recursion yes;
dnssec-validation yes;
allow-query { any; };
};
zone "." {
type hint;
file "/etc/namedb/named.root";
};
trusted-keys {
// real root
"." 257 3 8
"AwEAAagAIKlVZrpC6Ia7gEzahOR+9W29euxhJhVVLOyQ
bSEW0O8gcCjFFVQUTf6v58fLjwBd0YI0EzrAcQqBGCzh
/RStIoO8g0NfnfL2MTJRkxoXbfDaUeVPQuYEhg37NZWA
JQ9VnMVDxP/VHL496M/QZxkjf5/Efucp2gaDX6RS6CXp
oY68LsvPVjR0ZSwzz1apAzvN9dlzEheX7ICJBBtuA6G3
LQpzW5hOA2hzCTMjJPJ8LbqF6dsV6DoBQzgul0sGIcGO
Yl7OyQdXfZ57relSQageu+ipAdTTJ25AsRTAoub8ONGc
LmqrAmRLKBP1dfwhYB4N7knNnulqQxA+Uk1ihz0=";
// class root
"." 257 3 8
"AwEAAc3PS/ln9ICSWGS5E9zCZez5sH5EJsqUbbL0V8+R
ZsQbpYI1L87gKHVCZgRgCfb1R1Vu+DcbIt6In/B5nvLa
IZAe6lcx40Jt+Stm/PvES8YGVcJ9ndeCsp9xadFN5rGN
a+pm536xOSm4LizWXvi+ibfsaIGOfUDIYClyHo1xChlG
xbomw+tM1AgmKN8GketMGfGQGL03A1Vbeqe8n/cgEp5u
C7ifAunAaHzW8R41t29aHyM3LYSyhqhboRbzyeO9FBPO
y1r8oz7lJXeA9swBYiUo7p4ExdK+Ln9SUCb7UPnSqXRO
/AwmhZr21JiSDzO9ggCYrbMZ37HXguiTBRg5bMU=";
};