Dani 5,664 The Queen of DaniWeb Administrator Featured Poster

I'm intrigued by the Cloudflare setting called DNSSEC that says: DNSSEC uses a cryptographic signature of published DNS records to protect your domain against forged DNS answers.

Additionally, the Cloudflare setting called CNAME flattening for all CNAME records. It says: Speed up DNS resolution on CNAMEs by having Cloudflare return the IP address of the final destination in the CNAME chain. Enabling this setting allows you to flatten all CNAMEs within your zone, which is daniweb.com. With this setting disabled, any CNAME at the apex is flattened by default and you may choose to individually flatten specific CNAMES.

Is there a benefit to enabling one or both of these? Speeding up DNS resolution sounds nice. What's the downside?

I'm not very experienced in networking and don't really understand much of Cloudflare's explanations. Additionally, I've found in the past that Cloudflare over-simplifies their explanations without demonstrating negative side effects or downsides.