If you scroll to "Security Analysis" a fair bit of ink is spilled on this issue. It's THE obvious one...
Now there are two mitigations that can help here:
1. Don't trust a record until you've seen it from multiple nodes, and you can setup whatever rules you want here
2. Make nodes sign messages so that if they ever emit a fictitious record, they have no deniability
That said, the slop machine is a little bit autistic here because the situation with certificate authorities is the same if not worse - there's so many of then any everybody trusts all of them for all domains...
