I received a message that the website dagjeuitactie.nl was not working.
When I do a dig for this domain the status is SERVFAIL.

dig dagjeuitactie.nl @ -p 5353

; <<>> DiG 9.10.3-P4-Ubuntu <<>> dagjeuitactie.nl @ -p 5353
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 30367
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1

; EDNS: version: 0, flags: do; udp: 1452
;dagjeuitactie.nl.              IN      A

;; Query time: 101 msec
;; WHEN: Fri Oct 26 15:50:50 CEST 2018
;; MSG SIZE  rcvd: 45

In the log file I can see the following.

dnsmasq[5172]: query[A] dagjeuitactie.nl from
dnsmasq[5172]: forwarded dagjeuitactie.nl to
dnsmasq[5172]: validation dagjeuitactie.nl is BOGUS

A query using the Cloudflare or Google DNS servers is working.
The domain name (dagjeuitactie.nl and www.dagjeactie.nl) is a CNAME for
dagjeuit-web.queueup.eu. Dagjeuitactie.nl is not DNSSEC enabled. However,
the domain dagjeuit-web.queueup.eu is DNSSEC enabled. However this record
is also a CNAME to a AWS server.

I'm not a DNSSEC expert but is this behavior correct? Is this a failure in
Dnsmasq or is the domain not configured correctly.

