NS records in authority section for NOERROR response
Knot DNS includes NS records for NOERROR response. The NS record is useless and it's presence just triggers processing of additionals and therefore increasing the size of the packet heavily. Especially with DNSSEC.
BIND and NSD do the same. BIND has a tunable for this behavior (minimal-responses, disabled by default). NSD has a compile time option (--enable-minimal-responses, enabled by default).
I would like to make Knot DNS to send minimal responses without any configuration/compilation option.