As an example, if i mitm your dhcp request, i insert myself in as your dns server and gateway and i just say that DNSSEC isn't enabled for this domain. You have to trust me, and I can give you a MITM'd page.
Similarly dnssec uses a very similar model. You need somebody to sign that your record is valid which is roughly the same as somebody signing your certificate as valid. They are both a chain of trust, they just differ slightly in implementation.
I do agree with you that using dnssec makes more sense then our current system.
I don't want to give Symantec (owner of Verisign) money or trust to do something I can easily do myself.