All my domains are under control of stargrave.org's nameservers.

DNSSEC is global-scale PKI, with single trust anchor controlled by
USA/NATO. That is why, my nameservers use DNSCurve technology and DANE.

All X.509 certificates are also signed by my own CA.

=> https://dnscurve.io/faq/differences-between-dnscurve-and-dnssec.html
=> DNSCurve
=> ca.stargrave.org CA

Most of my domains has y. prefix, leading to Yggdrasil accessible address.
=> Yggdrasil