What it is
Plain DNS gives a client no way to tell a genuine answer from a forged one, which is what makes cache poisoning and on-path spoofing possible. DNSSEC signs records with public-key cryptography so a resolver can verify nothing was altered along the way. DoH and DoT address a different half of the problem by encrypting the query itself.
Why it matters
Whether a zone is signed says something about how carefully its DNS is run. An unsigned zone is not a vulnerability on its own, but it removes one defence against an attacker already in a position to interfere with resolution.