This is a DNSSEC test zone signed only with ML-DSA-44 (algorithm 18, per draft-westerbaan-dnssec-mldsa).
If your resolver validates DNSSEC and supports algorithm 18, this zone is secure. A validating resolver without ML-DSA-44 support treats it as insecure (unknown algorithm).
Try: dig +dnssec only.alg18.westerbaan.name A
Related test zones: dual (signed with both alg 18 and alg 13) and downgrade (DNSKEY/DS for alg 18 and 13, but alg 18 signatures deliberately missing).