Docs on DNSSEC signatures and more

I'm trying to do a small experiment to get all the signatures/digests/rrsig data etc for the chain of trust to a specific dns record on a domain. I've read over https://www.cloudflare.com/dns/dnssec/universal-dnssec/. But one thing I'm not finding easily is how to format the dns record to know the exact payload that is signed. Where can I find more docs on this?
Cloudflare
Cloudflare offers easy-to-use DNSSEC, and it only takes a few minutes to set up.
Was this page helpful?