The whole point of CurveDNS (and now DoH) is that it works right away, and doesn't depend on the rest of the Internet cooperating with you. It's a bottom-up design, contrasted to DNSSEC's (failed) top-down model. The only problem with DNSCurve is that it's been effectively superseded by DoH. It's the Betamax of secure DNS protocols. Doesn't matter if it's better.