In addition to the root hints, you should also download the DNSSEC anchor key (available on the same site as the root hints). That will let you detect manipulations of records that are DNSSEC-signed.
Otherwise, you could spin up your recursive resolver on your cloud, VPS, or other hosting provider of choice, and then use that.