Similar to the 'max-zone-ttl' zone option, the 'dnssec-policy' option should reject zones with TTLs that are out of range.