How to configure DNSSEC on my private network with 1 server and 1 client ?

DNS Ubuntu 16.04

Hello Everyone. I am a student doing my Master thesis and my aim is to simply test the working of DNSSEC. I am using Oracle Vbox. I created one server VM and one Client VM. Both are on the same virtual private network. The server is configured as an authoritative server (BIND9) for my test domain: ‘’ and I have signed the zone as well.

Can someone help me how can I validate if DNSSEC is working or not on Client? Client does not know anything about Bind9. On the server, I cannot figure out how to upload my DS data to parent zone? In my case, there is no Parent zone I guess?

Please, I am stuck at this point in my thesis. So any help or clue in this regard would be highly appreciated.

Thank you very much.

