First DNSSEC failure passed on even with allow-downgrade · Issue #10579 · systemd/systemd

Seeing this in systemd 240.95

Looks similar to issue of #9867

[b1tninja@hostname /]$ resolvectl query www.example.org

www.example.org: 93.184.216.34                 -- link: wlan0

-- Information acquired via protocol DNS in 133.9ms.
-- Data is authenticated: yes

[b1tninja@hostname /]$ resolvectl query www.archlinux.org

www.archlinux.org: resolve call failed: DNSSEC validation failed: no-signature
[b1tninja@hostname /]$ resolvectl dnssec
Global: allow-downgrade
Link 4 (wlan0): no

[b1tninja@hostname /]$ ip route

default via 192.168.0.1 dev wlan0 
192.168.0.0/24 dev wlan0 proto kernel scope link src 192.168.0.176 

[b1tninja@hostname /]$ cat /etc/systemd/resolved.conf

[Resolve]
#DNS=1.1.1.1
FallbackDNS=1.1.1.1 9.9.9.10 8.8.8.8 8.8.4.4 2606:4700:4700::1111 2620:fe::10 2001:4860:4860::8888
#Domains=
#LLMNR=yes
#MulticastDNS=yes
DNSSEC=allow-downgrade
#DNSOverTLS=opportunistic
Cache=yes
#DNSStubListener=yes
ReadEtcHosts=no