Unsigned zones can be spoofed between authority and resolver. Teams delay DNSSEC because they think it forbids geo, failover or low TTLs. On Cloud DNS those features still sit on a signed zone.
What validating resolvers gain
DNSSEC lets a supporting resolver check that the answer came from the zone owner. Not every resolver validates. Signing still authenticates the zone for those that do.
DS at the parent
Enabling DNSSEC on Cloud DNS is not finished until DS records are published at the parent. Test with a validating resolver before you treat production as signed.
Low TTLs and signatures
Plan record and signature lifetimes so a one-second TTL and DNSSEC remain compatible. Signing is not an excuse for 24-hour application TTLs.
Vanity nameservers
Branded NS records are supported. Include glue and DS in the plan so the branded names remain valid.
