Yes — mandatory. Without a validated DNSSEC chain of trust from the root down to your zone, TLSA records can be spoofed by any on-path attacker, defeating the entire point. If your registrar or DNS provider doesn’t support DNSSEC, you can’t deploy DANE — use MTA-STS instead.
All questions