DNSCurve + MinimaLT would completely stop these attacks. Based on public statements and hackathon reports I think MinimaLT will be released this semester (development is coordinated from rites.uic.edu).
I'd say it is not very common, but there are obviously some deployments out there.
Mandatory example: $ dig yp.to ns
I think it's sad that the trend is towards DNSSEC which provides not confidentiality, only authentication. As we've seen since last summer, the extra protection is very much needed.
Less than 1% of domains under .com are DNSSEC-signed, and many of them are long-term failing. At this point, 20 years after work began on DNSSEC, it's time to move on.
This is what the world in production looks like. Things may move at a glacial pace but that's because there is a steady stream of real world issues to iron out.
Even if you started work on a superiour alternative today, expect to keep working on it for the better part of a decade before you see any real world uptake.
Not even IP itself did conquer the world overnight.
Meanwhile, 85% of .GOV domains are DNSSEC-signed as are 34% of .NL domains and 18% of .BR. The improved security of DNS via DNSSEC is happening... it's just unevenly distributed.
Which is funny because the US Congress passed a law mandating DNSSEC for .gov domains. Not to mention the many outages, plus non-deployments, where domains CNAME to a non-DNSSEC CDN.
34% of .NL domains
That's because it's common for .nl domain owners to essentially be paid to run DNSSEC. That's how bad it is.
Actually, I do run DNSSEC on most of my domains, but for that particular one, danyork.com, I unfortunately lost DNSSEC support when I needed to switch the name servers to CloudFlare to be able to essentially have a CNAME at the apex (using what CloudFlare calls their "flattening" service).
Longer story... but the good news (for me) is that CloudFlare has publicly said they will be providing DNSSEC signing for their CDN by the end of 2014... so in theory I should be back to having that domain signed within the next few months.
FYI, CloudFlare's slides from the ICANN presentation where they talked about this are at: http://t.co/34sAH1FVLB
http://www.ethos-os.org/~solworth/minimalt-20131031.pdf