'server <prefix> { broken-nsec yes; };' can now be used to stop NSEC records from negative responses from servers in the given prefix being cached and hence available to synth-from-dnssec.